面向黑客、渗透测试工程师和安全研究人员的各类精选清单合集A collection of various awesome lists for hackers, pentesters and security researchers
仓库/Skill 库
23 个 · 安全与风险 · 快速增长
OpenAI 的 Codex Security CLI 与 TypeScript SDK,用于发现、验证和修复安全漏洞。npm: https://www.npmjs.com/package/@openai/codex-securityOpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Astrid OS 的权威参考:内核、capsules、host ABI、总线与安全模型。The canonical reference for Astrid OS: kernel, capsules, host ABI, the bus, and the security model. Part of Unicity Astrid OS.
Codex登陆助手:安全地在本地导出您的已登录 ChatGPT 会话配置,生成符合 Codex 规范的 auth.json 本地备份文件。
A Codex jailbreak prompt and test pack for gpt-5.6-sol. 针对 gpt-5.6 系列的 Codex 破甲提示词与测试包。
用于检查磁盘上 package、extension 与开发者工具元数据暴露面的只读开发者端点扫描器,旨在排查已知的软件供应链攻击。Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
收录公开漏洞利用 PoC 与漏洞研究技术报告的单一归档库。本人在发布时这些内容尚未被披露,欢迎自行上报并领取 CVE 编号(若获分配,权当一乐)。请勿滥用。我做这件事是为了吸引更多人进入这一领域,并且一直认为这是最高效的方式。A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
Python 终端多功能工具——OSINT、Discord、Web 与网络工具集。Rich TUI,13 种主题,支持远程更新。仅供学习使用。Python terminal multitool — OSINT, Discord, web & network utilities. Rich TUI, 13 themes, remote updates. Educational use only.
独立 iOS 应用,可在无需越狱的情况下模拟 GPS 定位。包含 Shadowrocket/Surge/Loon/QX/Stash 模块。Standalone iOS app to spoof GPS location without jailbreak. Includes Shadowrocket/Surge/Loon/QX/Stash module.
剥离多厂商 AI 来源标记:Unicode 文本卫生、统计改写钩子,以及 PNG/JPEG/SVG/PDF/DOCX/HTML/MD 中的 C2PA 与元数据。Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD
text-humanizer 是一个开源项目,旨在将 AI 生成的文本转换为"humanized"版本。可绕过大多数 AI 检测器,如 Turnitin 或 GPTZero。text-humanizer is an open-source project designed to convert text generated by AI to its "humanized" version. Bypasses the most of AI detectors such as Turnitin or GPTZero
claude-red 是一个面向 Claude skills 系统策划的攻击性安全 skills 库。每个 skill 是一个结构化的 SKILL.md 文件,为 Claude 提供针对特定攻击面的专家级方法论,涵盖从 SQLi 到 shellcode、EDR 规避到漏洞利用开发。claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
全面解析 2026 年 8 月 GTA 6 玩法泄露事件:技术核查、暗网溯源、地图细节与诈骗警示Full breakdown of the August 2026 GTA 6 gameplay leaks, technical checks, dark web trail, map details, and scam warning.
XCutors——面向 Windows 桌面的综合性 Roblox 执行器与脚本加载器合集XCutors – A comprehensive Roblox executor and script loader collection for Windows desktops.
还原你已拥有工作中被改写的原始标题。剥离 Anthropic 分配给你的 Outputs 中附加的供应商标识。Restore clean title in work you already own. Strip vendor marks from Outputs Anthropic assigned to you.
GoLiveBypass — Equicord/Vencord 插件,通过在非巴西代理(Tor 或经过测试的免费代理)后启动会话来恢复巴西 Discord 用户的 Go Live 与摄像头功能。隐私与反审查工具。GoLiveBypass — Equicord/Vencord plugin that restores Go Live & camera for Brazilian Discord users by booting the session behind a non-BR proxy (Tor or tested free proxy). Privacy and anti-censorship tool.
免费 Warhounds Trainer,支持大量 cfg 文件。自动更新,无需密钥系统。2026 年可用。Free Warhounds Trainer with support for many cfg files. Auto-updates, no key system. Works in 2026.
XCutors – 一套完整的 Windows 桌面工具集合,配合我们的通用加载器运行自定义 Roblox 脚本。XCutors – A complete Windows desktop collection for running custom Roblox scripts with our universal loader.
Tonkeeper Fake Balance —— TON 钱包余额伪造工具,支持 Tonkeeper 移动端与桌面端的实时浮层覆盖、自定义 TON 与 Jetton 余额注入、交易记录伪造以及截图安全的持久化显示。Tonkeeper Fake Balance — TON wallet balance spoofing tool with real-time overlay for Tonkeeper mobile & desktop, custom TON & Jetton balance injection, transaction history forging, and screenshot-safe persistent display
那条 API 背后究竟是谁?在浏览器中对任何 OpenAI 兼容端点进行指纹识别:9 项基础设施探针、并列对比、社区可扩展。Who is really behind that API? Fingerprint any OpenAI-compatible endpoint in the browser: 9 infrastructure probes, side-by-side comparison, community-extensible.
Electrum Fake —— 针对 Electrum 桌面客户端的比特币钱包余额伪造工具,具备实时叠加层、自定义 BTC 余额注入、交易历史伪造以及截图安全的持久化显示渲染。Electrum Fake — Bitcoin wallet balance spoofing tool with real-time overlay for Electrum desktop client, custom BTC balance injection, transaction history forging, and screenshot-safe persistent display rendering