web-exploit-prover by 1ikeadragon/awesome-offsec-claude
npx skills add https://github.com/1ikeadragon/awesome-offsec-claude --skill web-exploit-prover将初步的 Web 漏洞线索转化为高置信度的可利用成果。
initial_findingstarget_contextauth_and_role_dataenvironment_constraintsL1: 仅观察到可疑行为L2: 观察到可利用原语L3: 代码路径以攻击者可控的方式执行L4: 证明了业务影响广告位招租
在这里展示您的产品或服务
触达数万 AI 开发者,精准高效
confirmed: 当 L3+ 可复现时。plausible: 当原语存在但影响被阻断时。disputed: 当缓解措施被证实时。inconclusive: 当存在环境性阻碍时。{
"confirmed_exploits": [],
"plausible_findings": [],
"disputed_findings": [],
"inconclusive_findings": [],
"impact_evidence": []
}
| 条件 | 行动 | 证据要求 |
|---|---|---|
| 发现信号不稳定 | 降低置信度并添加重试计划 | 重复运行方差日志 |
| 链式环节缺少先决条件 | 拆分链并标记依赖阻碍 | 先决条件图 |
| 孤立看影响似乎较低 | 评估链式放大路径 | 链级影响叙述 |
| 缓解措施声称不完整 | 验证替代路径和状态变体 | 缓解措施绕过检查 |
| 环境阻碍占主导 | 归类为未定,并附解除阻碍请求 | 阻碍证据 |
每周安装数
1
仓库
GitHub 星标数
4
首次出现
1 天前
安全审计
安装于
zencoder1
amp1
cline1
openclaw1
opencode1
cursor1
Convert initial web vulnerability leads into high-confidence exploit outcomes.
initial_findingstarget_contextauth_and_role_dataenvironment_constraintsL1: suspicious behavior onlyL2: exploit primitive observedL3: code path executed in attacker-controlled wayL4: business impact demonstratedconfirmed when L3+ is reproducible.plausible when primitive exists but impact blocked.disputed when mitigation is proven.inconclusive when environmental blockers remain.{
"confirmed_exploits": [],
"plausible_findings": [],
"disputed_findings": [],
"inconclusive_findings": [],
"impact_evidence": []
}
| Condition | Action | Evidence Requirement |
|---|---|---|
| Finding signal unstable | downgrade confidence and add retest plan | repeated run variance log |
| Chain link missing prerequisite | split chain and mark dependency blocker | prerequisite graph |
| Impact appears low in isolation | evaluate chain amplification paths | chain-level impact narrative |
| Mitigation claim is partial | verify alternate path and state variants | mitigation bypass check |
| Environment blocker dominates | classify inconclusive with unblock requests | blocker evidence |
Weekly Installs
1
Repository
GitHub Stars
4
First Seen
1 day ago
Security Audits
Gen Agent Trust HubPassSocketFailSnykPass
Installed on
zencoder1
amp1
cline1
openclaw1
opencode1
cursor1
Skills CLI 使用指南:AI Agent 技能包管理器安装与管理教程
29,800 周安装