TheBotique

元测 yotta-security-testing

元测 —— 有纪律的 AI 安全测试方法论:对已授权目标(自有资产 / SRC 众测 / bug bounty / CTF / 靶场)按 侦察→发现→验证→报告 四阶段做 Web 安全测试(SQLi / XSS / SSRF / XXE / 反序列化 / 命令注入 / 文件上传 / 鉴权与访问控制 / 业务逻辑 / 信息泄露 / 不安全配置 / API 安全 + 漏洞评估与渗透报告方法论),内置 Scope Guard 五道防线(授权清单 scope.json + 目标三层判定 + 内置黑名单 + 操作留痕 + 法律红线),不输出可执行 payload。触发:用户要求对某个目标做安全测试 /

as observed 2026-09-03T07:20:35.503Z

Want to know when this changes? Sign in with an email address and we will tell you. Free, no card, watch up to 5.

Identifier
yotta-security-testing
Source
ClawHub
Version observed
0.2.5
Source repository
not published
Repository observation
No source repository listed
First observed here
2026-08-28T21:50:37.027Z
Observations recorded
3
Installs (reported upstream)
0
Weekly downloads (upstream)
158

Observation history

2026-09-03T07:20:35.503Z

Fields that differed: changelog latestVersion topics

FieldBeforeAfter
changelog "yotta-security-testing 0.2.4\n\n- Updated playbooks for command injection, file upload, business logic,信息泄露, and security misconfiguration for improved clarity and coverage.\ "- Removed the file skill-card.md from the project.\n- No changes made to core functionality or documentation in SKILL.md.\n- Version updated to 0.2.5.\n- This update is maint
latestVersion "0.2.4" "0.2.5"
topics ["security"] ["安全测试","授权测试","渗透测试","漏洞挖掘","漏洞评估"]
2026-08-31T05:56:02.339Z

Fields that differed: changelog latestVersion

FieldBeforeAfter
changelog "Initial public release of \"yotta-security-testing\":\n\n- Introduces a disciplined AI methodology for Web security testing in four phases: Reconnaissance, Discover "yotta-security-testing 0.2.4\n\n- Updated playbooks for command injection, file upload, business logic,信息泄露, and security misconfiguration for improved clarity and coverage.\
latestVersion "0.1.0" "0.2.4"

Correction

If you maintain this extension and believe anything above is inaccurate, request a correction. Corrections are published, and disputed entries are marked as disputed while under review.