GitHub - strivepan-svg/hack-skills: Helping AI Agent become an awesome practical hacker! · GitHub
分类 AI智能 / AI工具 预判分类 技术开发


网站介绍
这是strivepan-svg在GitHub上fork的一个公共仓库,主题为“帮助AI Agent成为出色的实用黑客”。页面包含GitHub的标准导航和仓库信息,但具体文件内容未在摘要中显示,可能涉及AI驱动的渗透测试、漏洞利用或安全自动化等方向。
备注说明

HACK.SKILLS - Hacker Arsenal for Agents

<p align="right">English | <a href="./README_CN.md">中文</a></p> <p align="center"> <img src="./assets/readme-hero-banner.jpg" alt="HackSkills Hero Banner" width="100%" /> </p> <p align="center"> <strong>Master Entry → Category Entries → Deep Topic Skills</strong><br/> One master entry, six category entries, and <strong>101</strong> deep topic skills across <strong>14 security domains</strong>. </p> An Agent Skills knowledge base covering web security, API security, authentication & authorization, OS privilege escalation (Linux/Windows/macOS), Active Directory attacks, mobile security, binary exploitation (Pwn), reverse engineering, cryptography attacks, blockchain & smart contract security, AI/ML & LLM security, network protocols & pivoting, and digital forensics — built for bug bounty, penetration testing, CTF competitions, and authorized security research. The current branch has converged to a standard directory structure: every skill lives in its own directory, uniformly using skills/{semantic-identifier}/SKILL.md. The design goal is not to expose every minor tip as an entry point, but to compress what the loader truly needs to see into one master entry, six category entries, and deep topic skills drilled down on demand. The objective is straightforward: organize security knowledge that is genuinely useful in real engagements and easy to audit and maintain into a set of installable, searchable, and composable HackSkills.

Browse Online

This repo is published in three forms — pick whichever your workflow prefers; they are kept in sync on every push to main. | Channel | What you get | When to use | |---|---|---| | Web UI — <https://skills.hackbenchmark.com> | Fuzzy search, category sidebar, P0/P1/P2 tier filter, copy-paste install commands, encrypted ZIP download | Quick lookup, sharing links to a specific skill, demoing the catalog | | GitHub source — this repo | Plain SKILL.md per skill, full markdown rendering, pull-request review | Diff review, contributing, deep reading offline | | Encrypted ZIP — see Offline ZIP | One-shot download of all *.md for air-gapped use | No internet on target, AV strips plain markdown | The website is a static, fully client-side build of site/ — no tracking, no backend. Source: site/, workflow: .github/workflows/deploy-pages.yml. Search uses a weighted fuzzy index over name / id / category / description with field qualifiers like category:auth, tier:deep, lines:>200.
text
                        ┌─────────────────────────────────────┐
                        │   skills.hackbenchmark.com (static) │  ── search / filter / copy install cmd
                        └─────────────────────────────────────┘
                                          ▲
   github.com/yaklang/hack-skills ───────►┤  same repo, three views
                                          ▼
                        ┌─────────────────────────────────────┐
                        │   hack-skills.zip (AES-256, public  │  ── offline / behind AV
                        │   password: hack-skills, via CDN)   │
                        └─────────────────────────────────────┘

Knowledge Sources & Distillation Boundaries

This repository is not a mirror of external materials — it is a distillation layer aimed at Agents. Primary reference sources (all publicly available, used strictly for educational distillation): | Source | What It Provides | How We Use It | |---|---|---| | swisskyrepo/PayloadsAllTheThings | 64 vulnerability categories, payload families, bypass techniques, exploit chains | Distilled into scenario-based indices, method matrices, per-engine/per-database payload sections | | PentesterSpecialDict | OS-specific payload dictionaries, Java middleware path fuzzing lists, file extension databases | Distilled into parameter naming patterns, endpoint frequency tables, middleware fingerprint matrices | | Dictionary-Of-Pentesting | BugBounty bypass techniques (12 topics), cloud metadata endpoints, XXE payload collections, one-liner toolchains | Distilled into bypass pattern matrices, cloud metadata endpoint tables, WAF vendor bypass sections | | Hello-CTF | CTF web security tutorials with hands-on tricks for PHP/Python/Java challenges | Distilled into CTF-specific technique sections (handler bypass, filter chain tricks, Flask PIN) | | ctf-wiki | CTF competition knowledge base covering Pwn, Crypto, Reverse Engineering, Forensics, and Misc | Distilled into binary exploitation techniques (stack/heap/kernel), crypto attack patterns (RSA/lattice/symmetric), RE methodology, steganography, and traffic analysis skills | | hacktricks | Penetration testing encyclopedia covering web tricks, Linux/Windows/macOS privilege escalation, Active Directory, containers, mobile, and AI security | Distilled into OS-specific privilege escalation pl...
获取时间 2026-08-07T15:59:48+00:00
本网址已被浏览 38 次
关键词 AI Agent hacker hack-skills GitHub security
小标签 GitHub AI 黑客技能 安全 开源
暂无截图,待自动生成。
头像
暂无评论,快来抢沙发吧!