这是一个黑客技能知识库,包含一个主入口、六个分类入口和101个深度主题技能,覆盖14个安全领域。具体包括Web安全、API安全、认证授权、Linux/Windows/macOS提权、Active Directory攻击、移动安全、二进制利用、逆向工程、密码学攻击、区块链智能合约安全、AI/ML与LLM安全、网络协议和数字取证。每个技能都放在独立目录里用SKILL.md标准格式组织,设计思路不是把所有小技巧都暴露成入口,而是分层引导。适合做漏洞赏金、渗透测试、CTF比赛和授权安全研究的人用。
查看英文原文
HACK.SKILLS Hacker Arsenal for Agents English 中文 Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 101 deep topic skills across 14 security domains . An Agent Skills knowledge base covering web security, API security, authentication & authorization, OS privilege escalation (Linux/Windows/macOS), Active Directory attacks, mobile security, binary exploitation (Pwn), reverse engineering, cryptography attacks, blockchain & smart contract security, AI/ML & LLM security, network protocols & pivoting, and digital forensics — built for bug bounty, penetration testing, CTF competitions, and authorized security research. The current branch has converged to a standard directory structure: every skill lives in its own directory, uniformly using skills/{semantic identifier}/SKILL.md . The design goal is not to expose every minor tip as an entry point, but to compress what the loader truly needs to see into one master entry, six category entries, and deep topic skills drilled down on demand. The objective is straightforward: organize security knowledge that is genuinely useful in real engagements and easy to audit and maintain into a set of installable, searchable, and composable HackSkills. Browse Online This repo is published in three forms — pick whichever your workflow prefers; they are kept in sync on every push to main . Channel What you get When to use Web UI — Fuzzy search, category sidebar, P0/P1/P2 tier filter, copy paste install commands, encrypted ZIP download Quick lookup, sharing links to a specific skill, demoing the catalog GitHub source — this repo Plain SKILL.md per skill, full markdown rendering, pull request review Diff review, contributing, deep reading offline Encrypted ZIP — see Offline ZIP One shot download of all .md for air gapped use No internet on target, AV strips plain markdown The website is a static, fully client side build of site/ — no tracking, no backend. Source: site/ , workflow: .github/workflows/