
Web App Penetration Testing
usestrix/strix/skills/web-app-penetration-testing作者 usestrix469529068290Apache-2.067K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新
Pentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each one with a working proof-of-concept instead of a signature match. Runs with Strix, either the self-hosted open-source CLI or the managed app.strix.ai cloud. Use when the user asks to pentest, hack, security-test, or audit their web app, website, web application, or staging site.
仅公开文件列表。将技能安装到工作区后即可查看文件内容。
| 路径 | 大小 | 类型 |
|---|---|---|
| SKILL.md | 4.2 KB | text/markdown |
来源与署名
来源:usestrix/strix位于skills/web-app-penetration-testing提交4695290
许可证: Apache-2.0
内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。
更多来自 usestrix/strix 的技能

Owasp Top 10 Testing
usestrix
指导使用 Strix 代理执行 OWASP Top 10:2025 安全评估,并将已证实的漏洞映射到对应类别。

Find Security Vulnerabilities In Code
usestrix
指导使用 Strix 进行白盒 AI 安全审查,在代码库中发现并验证可利用的漏洞。

Application Security Testing
usestrix
规划整个产品的应用安全测试,并将结果整合为按优先级排序的修复计划。

Api Security Testing
usestrix
指导使用 Strix 代理对 REST、GraphQL 或 gRPC API 进行安全测试,覆盖 OWASP API 安全 Top 10 类别。
更多Security技能

Kyc Rules
anthropics
将公司的 KYC/AML 规则表应用于已解析的开户记录,评定风险并给出处理路由。

Kyc Rules
anthropics
将公司的 KYC/AML 规则表应用于已解析的开户记录,评定风险并给出处理路由。

Compliance Tracking
anthropics
跟踪合规要求、审计准备情况以及 SOC 2、ISO 27001、GDPR、HIPAA 和 PCI DSS 等框架的证据。

Dpop Adoption
指导为 Google OAuth 平台实现 OAuth 2.0 DPoP(RFC 9449)发送方约束刷新令牌。

Secops Triage
指导 SOC 分析师对 Google SecOps 安全告警进行分诊,从调查到关闭或升级。

Secops Investigate
指导 SOC 分析师在 Google SecOps 中使用 UDM 查询和时间线进行深入的安全事件与实体调查。