do-whilefor/Jase-SecKit
面向授权安全测试、AI 辅助渗透测试与漏洞研究的可复用 Security Skills 。
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ npx degit do-whilefor/Jase-SecKit/SKILL/Pentest-WindFtsy/.claude ./rig-jase-seckit # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit do-whilefor/Jase-SecKit/SKILL/Pentest-WindFtsy/.claude/skills/pentest-windftsy .claude/skills/pentest-windftsy $ npx degit do-whilefor/Jase-SecKit/refer/ARTEX-main/skills/api-recon .claude/skills/api-recon $ npx degit do-whilefor/Jase-SecKit/refer/ARTEX-main/skills/playwright-cli .claude/skills/playwright-cli $ npx degit do-whilefor/Jase-SecKit/refer/ARTEX-main/skills/scopesentry .claude/skills/scopesentry $ npx degit do-whilefor/Jase-SecKit/refer/Cairn-main/container/.agents/skills/tsec-actions .claude/skills/tsec-actions
$ curl -fsSL --create-dirs -o .claude/agents/pentest-bypass-miner.md https://raw.githubusercontent.com/do-whilefor/Jase-SecKit/main/SKILL/Pentest-WindFtsy/.claude/agents/pentest-bypass-miner.md $ curl -fsSL --create-dirs -o .claude/agents/pentest-vuln-miner.md https://raw.githubusercontent.com/do-whilefor/Jase-SecKit/main/SKILL/Pentest-WindFtsy/.claude/agents/pentest-vuln-miner.md
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 6,974 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(~/.aws/**)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(.env)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/.env.*)",
"Read(**/*.key)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(npm publish:*)",
"Bash(wget *)",
"Bash(git rebase *)",
"Bash(gh pr merge *)",
"Bash(git commit *)"
]
}
} Skills (5)
Subagents (2)
| pentest-bypass-miner | Introduce new variables for filtered leads to continue dynamic validation, then update the matrix, bypass ledger, and structured findings. |
| pentest-vuln-miner | Perform complete vulnerability-class coverage, dynamic validation, matrix updates, and structured finding registration for the specified endpoint IDs. |
Similar rigs
VoltAgent/voltagent
AI Agent Engineering Platform built on an Open Source TypeScript AI Agent Framework
Minimalist 522 tok ·
HatriGt/agent-sandbox
A cloud sandbox for coding agents, on your own server. Start a run from the dashboard, from any agentic IDE (Cursor, Claude Code, Codex, VS Code), or from a script — it runs in an isolated KVM microVM and streams back live.
Pragmatist 391 tok ·
Vironnimo/vbot
Your own AI agents, self-hosted: persistent agents with memory that work with you or on their own, in chat, real terminals, swarms, on schedules and by voice. Any model (subscriptions, API keys, local). Browser, desktop, CLI, Telegram, Disc
Skill Collector 4.0k tok ·
exactbee/claude-code-workflow
Structured Claude Code workspace — Opus plans, Sonnet executes. Curated MCP stack with ~98% token savings on input. Drop-in template for developers.
Skill Collector 10.0k tok ·