
Web App Penetration Testing
usestrix/strix/skills/web-app-penetration-testing作者 usestrix469529068290Apache-2.067K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新
Pentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each one with a working proof-of-concept instead of a signature match. Runs with Strix, either the self-hosted open-source CLI or the managed app.strix.ai cloud. Use when the user asks to pentest, hack, security-test, or audit their web app, website, web application, or staging site.
僅公開檔案列表。將技能安裝到工作區後即可檢視檔案內容。
| 路徑 | 大小 | 類型 |
|---|---|---|
| SKILL.md | 4.2 KB | text/markdown |
來源與署名
來源:usestrix/strix位於skills/web-app-penetration-testing提交4695290
授權條款: Apache-2.0
內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。
更多來自 usestrix/strix 的技能

Owasp Top 10 Testing
usestrix
指導使用 Strix 代理執行 OWASP Top 10:2025 安全評估,並將已證實的漏洞對應到各類別。

Find Security Vulnerabilities In Code
usestrix
指導使用 Strix 進行白箱 AI 安全審查,在程式碼庫中找出並驗證可利用的漏洞。

Application Security Testing
usestrix
規劃整個產品的應用程式安全測試,並將結果彙整為依優先順序排列的修復計畫。

Api Security Testing
usestrix
指導使用 Strix 代理對 REST、GraphQL 或 gRPC API 進行安全測試,涵蓋 OWASP API 安全 Top 10 類別。
更多Security技能

Kyc Rules
anthropics
將公司的 KYC/AML 規則表套用於已解析的開戶紀錄,評定風險並給出處理路由。

Compliance Tracking
anthropics
追蹤合規要求、稽核準備情況,以及 SOC 2、ISO 27001、GDPR、HIPAA 和 PCI DSS 等框架的證據。

Dpop Adoption
指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Secops Triage
引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Secops Investigate
指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Secops Hunt
指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。