做渗透测试,光 Web 一个方向就有 SQL 注入、XSS、SSRF 十几种攻击面。
This is a dev post classified by Jev as Security (a tool drop), kept by the Dev Radar because it carries real work, not commentary.
做渗透测试,光 Web 一个方向就有 SQL 注入、XSS、SSRF 十几种攻击面。 每种的思路、工具、容易踩的坑都得记在脑子里,换个方向又是一整套。 Claude-Red 把这些方法论整理成 78 个安全测试 Skill,装进 Claude 后在对话中按话题自动加载,说到 SQL 注入就调出对应那一个。 分成 23 类,Web 应用有 16 个覆盖 OWASP 常见问题,无线有 14 个,还有漏洞挖掘、云、移动端、逆向这些方向。 GitHub:http://github.com/SnailSploit/Claude-Red 每个 Skill 就是一个 SKILL.md,把某个领域的方法、工具链、边界情况写清楚,让 Claude 在这个方向上答得像个熟手,而不是泛泛而谈。 作者写明适用场景是授权的红队项目、漏洞赏金、安全研究和 CTF 备赛,动手前先确认自己在授权范围内。
Posted by GitHubDaily (84.5k followers) 4 days ago · 86 likes · 7.1k views · view the original post on X. Kept by the Dev Radar as Security. Tools mentioned: claude-red.
More dev work like this
- Wow, these slides are fantastic to just read through and contemplate. 😍… — @zooko
- Dostlar selamlar, globaldeki en büyük Cybersecurity SFT finetuning datasetlerinden olan… — @AlicanKiraz0
- Cloudflare 团队把其内部找漏洞的那套方法做成了一个 Skill,叫 security-audit,并开源了。 — @GitHub_Daily
- Scans emails and usernames across 715+ platforms to map digital footprints and verify… — @tom_doerr
- DeepTeam runs locally to simulate attacks and uncover vulnerabilities in LLM systems. — @tom_doerr
- Software now writes and runs software: — @jfrog
- Ok, jev is really cool. So many great use cases where a fast and accurate yes/no gate… — @andrelandgraf
- Running security telemetry across 170,000 cloud resources can overload infrastructure. — @CloudNativeFdn
Every post is read and classified by Jev (TypeSafe): what it is, which market it belongs to, and whether the link is a real tool. 12.2k posts from 4.7k X accounts over the last 21 days, 1.4k tools, 12 markets. Collected every 5 minutes, fully re-ranked every hour — last update 2026-09-19 18:06 UTC. Full method.