~ / rigs / do-whilefor / Jase-SecKit

do-whilefor/Jase-SecKit

面向授权安全测试、AI 辅助渗透测试与漏洞研究的可复用 Security Skills 。

↗ GitHub ★ 7 mit updated 26d ago project Claude CodeCodex
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~206 tokens
Featherweight · median rig: 2.3k · breakdown
GUARDRAILS
0/5
No committed guardrails · details

Copy this rig

# review before running: this installs third-party code
$ npx degit do-whilefor/Jase-SecKit/SKILL/Pentest-WindFtsy/.claude ./rig-jase-seckit  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ npx degit do-whilefor/Jase-SecKit/SKILL/Pentest-WindFtsy/.claude/skills/pentest-windftsy .claude/skills/pentest-windftsy
$ npx degit do-whilefor/Jase-SecKit/refer/ARTEX-main/skills/api-recon .claude/skills/api-recon
$ npx degit do-whilefor/Jase-SecKit/refer/ARTEX-main/skills/playwright-cli .claude/skills/playwright-cli
$ npx degit do-whilefor/Jase-SecKit/refer/ARTEX-main/skills/scopesentry .claude/skills/scopesentry
$ npx degit do-whilefor/Jase-SecKit/refer/Cairn-main/container/.agents/skills/tsec-actions .claude/skills/tsec-actions
$ curl -fsSL --create-dirs -o .claude/agents/pentest-bypass-miner.md https://raw.githubusercontent.com/do-whilefor/Jase-SecKit/main/SKILL/Pentest-WindFtsy/.claude/agents/pentest-bypass-miner.md
$ curl -fsSL --create-dirs -o .claude/agents/pentest-vuln-miner.md https://raw.githubusercontent.com/do-whilefor/Jase-SecKit/main/SKILL/Pentest-WindFtsy/.claude/agents/pentest-vuln-miner.md

This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,974 rigs:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(~/.aws/**)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(.env)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/.env.*)",
      "Read(**/*.key)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(npm publish:*)",
      "Bash(wget *)",
      "Bash(git rebase *)",
      "Bash(gh pr merge *)",
      "Bash(git commit *)"
    ]
  }
}

Skills (5)

Subagents (2)

pentest-bypass-minerIntroduce new variables for filtered leads to continue dynamic validation, then update the matrix, bypass ledger, and structured findings.
pentest-vuln-minerPerform complete vulnerability-class coverage, dynamic validation, matrix updates, and structured finding registration for the specified endpoint IDs.

Similar rigs

copied ✓