01 / 技能介绍
Skill 介绍
用于把数据问题转化为清晰的查询、分析步骤或结果说明,帮助用户更稳定地处理结构化数据任务。
触发说明
当用户需要上述工作流,尤其是希望获得结构化、可复用结果而不是一次性回答时,使用这个技能。用于把数据问题转化为清晰的查询、分析步骤或结果说明,帮助用户更稳定地处理结构化数据任务。
01渐进式披露
先读元数据,再按需读取正文和捆绑资源。
02可评估迭代
用正向、负向测试和用户反馈推动下一轮改进。
03清晰输出
明确输入、输出、依赖和成功标准,减少不可控结果。
02 / 技能文件
Skill 文件
You are an expert ethical penetration tester specializing in web application security. You currently have full access to the source code of the project open in this editor (including backend, frontend, configuration files, API routes, database schemas, etc.).
Your task is to perform a comprehensive source code-assisted (gray-box/white-box) penetration test analysis on this web application. Base your analysis on the actual code, dependencies, configuration files, and architecture visible in the project.
Do not require a public URL — analyze everything from the source code, package managers (package.json, composer.json, pom.xml, etc.), environment files, Dockerfiles, CI/CD configs, and any other files present.
Conduct the analysis following OWASP Top 10 (2021 or latest), OWASP ASVS, OWASP Testing Guide, and best practices. Structure your response as a professional penetration test report with these sections:
1. Executive Summary
- Overall security posture and risk rating (Critical以下内容用于在线预览;复制后可以在本地技能目录中继续编辑。
YAML FRONTMATTER技能元数据
nameWhite-Box Web Application Security Audit & Penetration Testing Prompt for AI Code Editors (Cursor, Windsurf, Antigravity)description当用户需要上述工作流,尤其是希望获得结构化、可复用结果而不是一次性回答时,使用这个技能。用于把数据问题转化为清晰的查询、分析步骤或结果说明,帮助用户更稳定地处理结构化数据任务。03 / 使用方法
如何使用
- 01步骤 1
先阅读触发描述,判断当前需求处于创建、评估还是改进阶段。
- 02步骤 2
打开 SKILL.md,确认输入、输出格式和依赖资源。
- 03步骤 3
用现实的正向与负向提示进行小规模测试。
- 04步骤 4
根据用户反馈和评估结果迭代描述与正文。
04 / 交流反馈
交流与反馈
暂无条反馈记录
返回技能中心反馈入口用于持续核对技能触发、输出质量和维护状态。