元测 yotta-security-testing
元测 —— 有纪律的 AI 安全测试方法论:对已授权目标(自有资产 / SRC 众测 / bug bounty / CTF / 靶场)按 侦察→发现→验证→报告 四阶段做 Web 安全测试(SQLi / XSS / SSRF / XXE / 反序列化 / 命令注入 / 文件上传 / 鉴权与访问控制 / 业务逻辑 / 信息泄露 / 不安全配置 / API 安全 + 漏洞评估与渗透报告方法论),内置 Scope Guard 五道防线(授权清单 scope.json + 目标三层判定 + 内置黑名单 + 操作留痕 + 法律红线),不输出可执行 payload。触发:用户要求对某个目标做安全测试 /
as observed 2026-09-03T07:20:35.503ZWant to know when this changes? Sign in with an email address and we will tell you. Free, no card, watch up to 5.
- Identifier
yotta-security-testing- Source
- ClawHub
- Version observed
- 0.2.5
- Source repository
- not published
- Repository observation
- No source repository listed
- First observed here
- 2026-08-28T21:50:37.027Z
- Observations recorded
- 3
- Installs (reported upstream)
- 0
- Weekly downloads (upstream)
- 158
Observation history
2026-09-03T07:20:35.503Z
Fields that differed: changelog latestVersion topics
| Field | Before | After |
|---|---|---|
changelog |
"yotta-security-testing 0.2.4\n\n- Updated playbooks for command injection, file upload, business logic,信息泄露, and security misconfiguration for improved clarity and coverage.\ | "- Removed the file skill-card.md from the project.\n- No changes made to core functionality or documentation in SKILL.md.\n- Version updated to 0.2.5.\n- This update is maint |
latestVersion |
"0.2.4" | "0.2.5" |
topics |
["security"] | ["安全测试","授权测试","渗透测试","漏洞挖掘","漏洞评估"] |
2026-08-31T05:56:02.339Z
Fields that differed: changelog latestVersion
| Field | Before | After |
|---|---|---|
changelog |
"Initial public release of \"yotta-security-testing\":\n\n- Introduces a disciplined AI methodology for Web security testing in four phases: Reconnaissance, Discover | "yotta-security-testing 0.2.4\n\n- Updated playbooks for command injection, file upload, business logic,信息泄露, and security misconfiguration for improved clarity and coverage.\ |
latestVersion |
"0.1.0" | "0.2.4" |
Correction
If you maintain this extension and believe anything above is inaccurate, request a correction. Corrections are published, and disputed entries are marked as disputed while under review.