面向黑客、渗透测试工程师和安全研究人员的各类精选清单合集A collection of various awesome lists for hackers, pentesters and security researchers
仓库/Skill 库
87 个 · 安全与风险
Daytona 是用于运行 AI 生成代码的安全、弹性基础设施。Daytona is a Secure and Elastic Infrastructure for Running AI-Generated Code
从 Anthropic 提取的系统提示词——Claude Fable 5、Opus 4.8、Claude Code、Claude Design;OpenAI——ChatGPT 5.5 Thinking、GPT 5.5 Instant、Codex;Google——Gemini 3.5 Flash、3.1 Pro、Antigravity;以及 xAI Grok、Cursor、Copilot、VS Code、Perplexity 等。定期更新Extracted system prompts from Anthropic - Claude Fable 5, Opus 5, Claude Design, Claude Code. OpenAI - ChatGPT GPT-5.6-Sol, Codex. Google - Gemini 3.5 Flash, 3.1 Pro, Antigravity. xAI - Grok, Cursor, Copilot, VS Code, Perplexity, and more. Updated regularly.
在 Windows 11 中强制移除 Copilot、Recall 等组件Force Remove Copilot, Recall and More in Windows 11
超快的 AI Gateway,集成 guardrails。通过一个快速友好的 API 路由到 1,600+ LLM 和 50+ AI Guardrails。A blazing fast AI Gateway with integrated guardrails. Route to 1,600+ LLMs, 50+ AI Guardrails with 1 fast & friendly API.
Cybersecurity AI (CAI),面向 AI 安全的框架。Cybersecurity AI (CAI), the framework for AI Security
OpenAI 的 Codex Security CLI 与 TypeScript SDK,用于发现、验证和修复安全漏洞。npm: https://www.npmjs.com/package/@openai/codex-securityOpenAI's Codex Security CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities. npm: https://www.npmjs.com/package/@openai/codex-security
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Astrid OS 的权威参考:内核、capsules、host ABI、总线与安全模型。The canonical reference for Astrid OS: kernel, capsules, host ABI, the bus, and the security model. Part of Unicity Astrid OS.
最快的 enterprise AI gateway(比 LiteLLM 快 50 倍),具备自适应负载均衡、集群模式、guardrails,支持 1000+ 模型,在 5k RPS 下额外开销 <100 µs。Fastest enterprise AI gateway (50x faster than LiteLLM) with adaptive load balancer, cluster mode, guardrails, 1000+ models support & <100 µs overhead at 5k RPS.
Codex登陆助手:安全地在本地导出您的已登录 ChatGPT 会话配置,生成符合 Codex 规范的 auth.json 本地备份文件。
A Codex jailbreak prompt and test pack for gpt-5.6-sol. 针对 gpt-5.6 系列的 Codex 破甲提示词与测试包。
用于检查磁盘上 package、extension 与开发者工具元数据暴露面的只读开发者端点扫描器,旨在排查已知的软件供应链攻击。Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
收录公开漏洞利用 PoC 与漏洞研究技术报告的单一归档库。本人在发布时这些内容尚未被披露,欢迎自行上报并领取 CVE 编号(若获分配,权当一乐)。请勿滥用。我做这件事是为了吸引更多人进入这一领域,并且一直认为这是最高效的方式。A single archive of public exploit PoCs and vulnerability research writeups. At the time I post these, none have been reported. Feel free to report them yourself and take credit for the CVE if handed out lulz. Please do not abuse these. I do this so to allure people into the field, and I've always found this is the most efficient way.
:orange_book: 面向 Offensive Security OSCP、OSWE、OSCE、OSEE、OSWP 考试报告的 Markdown 模板:orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report
Python 终端多功能工具——OSINT、Discord、Web 与网络工具集。Rich TUI,13 种主题,支持远程更新。仅供学习使用。Python terminal multitool — OSINT, Discord, web & network utilities. Rich TUI, 13 themes, remote updates. Educational use only.
独立 iOS 应用,可在无需越狱的情况下模拟 GPS 定位。包含 Shadowrocket/Surge/Loon/QX/Stash 模块。Standalone iOS app to spoof GPS location without jailbreak. Includes Shadowrocket/Surge/Loon/QX/Stash module.
claude-red 是一个面向 Claude skills 系统的进攻性安全 skill 精选库。每个 skill 都是一个结构化的 SKILL.md 文件,为 Claude 注入针对特定攻击面的专家级方法论 — 涵盖 SQLi、shellcode、EDR 规避到漏洞利用开发等。claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
100+ 可安装的 Claude skill,覆盖工程领域,包括 ISO 26262 功能安全、ISO/SAE 21434 网络安全、ISO 21448 SOTIF、AIAG-VDA 质量(APQP/PPAP/FMEA)、Automotive SPICE 及持续改进工具 — 每个构建 skill 均配有一个确认 reviewer。100+ installable Claude skills covering Engineering areas such as, ISO 26262 functional safety, ISO/SAE 21434 cybersecurity, ISO 21448 SOTIF, AIAG-VDA quality (APQP/PPAP/FMEA), Automotive SPICE, and continuous improvement tools — every builder paired with a confirmation reviewer.
8 个 Claude Skill · 100+ 侦察能力 · 80 条 secret-regex 模式 · 80+ dorks · 9 个只读凭据验证器 · 27 个攻击路径模板 · 约 10,000 行结构化技术内容。开箱即用的 SKILL.md 文件,可将 Claude 改造为面向授权红队与漏洞赏金项目的顶级外部侦察操作员。8 Claude skills · 100+ recon capabilities · 80 secret-regex patterns · 80+ dorks · 9 read-only credential validators · 27 attack-path templates · ~10,000 lines of structured tradecraft. Drop-in SKILL.md files that turn Claude into a god-mode external recon operator for authorized red-team and bug-bounty engagements.
反检测与人性化工具及浏览器列表,含验证码识别与短信激活。List of anti-detect and humanizing tools and browsers, including captcha solvers and sms-activation.
剥离多厂商 AI 来源标记:Unicode 文本卫生、统计改写钩子,以及 PNG/JPEG/SVG/PDF/DOCX/HTML/MD 中的 C2PA 与元数据。Strip multi-vendor AI provenance marks: Unicode text hygiene, statistical rewrite hooks, and C2PA/metadata from PNG/JPEG/SVG/PDF/DOCX/HTML/MD
Revolt 是排名第一的 Edgenuity 自动化工具,提供自动答题、自动写作文、自动跳课、humanization 驱动的 AI 写作、自动词汇、自动日志等功能。这是一款半挂机脚本,可轻松应对测验、考试、测试、项目和作文。支持桌面端和移动端。访问 https://revolt.ly 即可开始使用。Revolt is the #1 Edgenuity automation tool featuring Auto Quiz, Auto Essay, Auto Advance, AI-powered writing with humanization, Auto Vocabulary, Auto Journal, and more. A semi-AFK script that handles quizzes, tests, exams, projects, and essays with ease. Compatible with desktop and mobile. Visit https://revolt.ly to get started.
IoT HackBot:用于混合 IoT 渗透测试的 Claude Skills 和自定义工具集合。IoT HackBot: A collection of Claude Skills and custom tooling for hybrid IoT pentesting
text-humanizer 是一个开源项目,旨在将 AI 生成的文本转换为"humanized"版本。可绕过大多数 AI 检测器,如 Turnitin 或 GPTZero。text-humanizer is an open-source project designed to convert text generated by AI to its "humanized" version. Bypasses the most of AI detectors such as Turnitin or GPTZero
面向机器操作的 consequence firewall。EMILIA Gate 在资金、代码、权限、基础设施或受监管状态变更前校验确切授权;其开放协议使证据可独立验证。Consequence firewall for machine actions. EMILIA Gate verifies exact authority before money, code, permissions, infrastructure, or regulated state changes; the open protocol makes the evidence independently verifiable.
claude-red 是一个面向 Claude skills 系统策划的攻击性安全 skills 库。每个 skill 是一个结构化的 SKILL.md 文件,为 Claude 提供针对特定攻击面的专家级方法论,涵盖从 SQLi 到 shellcode、EDR 规避到漏洞利用开发。claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
降低学术论文 AIGC 查重率的 Claude Code Skill | A Claude Code skill for reducing AIGC detection rates in academic papers
将 AI 生成的文本轻松转换为正式、类人、学术化的写作风格,规避 AI 检测器!Transform AI-generated text into formal, human-like, and academic writing with ease, avoids AI detector!
差分隐私联邦学习系统综述(ACM Survey);Adap dp-fl:自适应噪声的差分隐私联邦学习(TrustCom'2022)Differentially private federated learning: A systematic review (ACM Survey); Adap dp-fl: Differentially private federated learning with adaptive noise (TrustCom'2022)
最佳的静态 AI 文本 humanizer。两个基于研究的、与 LLM 无关的 Skill,让 AI 写作听起来自然且具亲和力。九大杠杆,50+ 同行评审来源,覆盖 2024-2026 年检测文献。Best static AI text humanizer. Two research-grounded LLM-agnostic skills that make AI writing sound human and relatable. Nine levers, 50+ peer-reviewed sources, 2024-2026 detection literature.
全面解析 2026 年 8 月 GTA 6 玩法泄露事件:技术核查、暗网溯源、地图细节与诈骗警示Full breakdown of the August 2026 GTA 6 gameplay leaks, technical checks, dark web trail, map details, and scam warning.