authorized-attack-scope

SkillSearch

Authorized scope, no limits on technique: within scope, search/validate/chain/document all available means; if blocked, reroute and persist until achieved. Clues outside scope are only recorded, not attacked. Use when deciding how far an attack technique may go within authorized SRC scope.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the authorized-attack-scope skill

What this skill tells your AI

The instructions your AI receives, as published by langbyyi/cyberstrikeai-src in skills/authorized-attack-scope/SKILL.md and read by ahel’s review.

授权范围 · 技法不设限

OODA/项目黑板Fact/验证铁律/组合拳适用于授权范围内的所有攻击面。skill是框架不是牢笼:
  搜索一切(多渠道) · 验证一切(搜索≠漏洞) · 串联一切(小漏洞拼大突破) · 记录一切(负结果也是Fact)
  技法不设限(Web/APK/EXE/云/固件/区块链/AI/无线/硬件均可) · 被拦换路 · 不达不休
  边界只有一条:授权资产与SRC收录范围。范围外的内网横移、社工钓鱼、破坏性手段——
  不做;把线索写成Fact留待授权扩展。
> 给定一组能力和一个目标,像解谜一样推导出独属于这个目标的攻击链——
> 这条链可能全世界只有你这一个目标适用,网上永远搜不到,因为它是你现场推导出来的。
> 范围纪律不是缩手缩脚:授权范围内的每一步都大胆推进(见系统提示「默认放手做」)。
  • 证据与落库仍走 pentest-verification 证据阶梯与 record_vulnerability 可复现门;搜索命中永远只是线索。
  • 敏感接口与破坏性操作仍受敏感接口硬门约束,与本 skill 的进攻性不冲突。

Signals

GitHub stars
115
Forks
4
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
authorized-attack-scope
Source
github.com/langbyyi/cyberstrikeai-src