Güvenlik uyarılı skill
Bu skill destructive command içerebilir. Skill detaylarını ve kaynak içeriği incelemeden kurulum yapmayın, kopyalamayın, indirmeyin veya çalıştırmayın. Bilinçli ve kontrollü şekilde kullanın.
Tarayıcı bulguları
highcredential_theft
Çoklu dosya
analysisResmi
Resmi Sağlayıcı Skill'iView repo
Use when analysing, triaging, reporting on, or writing up what a WordPress sample did after it was offered in KadathSandbox at /Users/fioa8c/WORK/KadathSandbox — reading the run's Xdebug traces, Snuffleupagus log, decrypted flows, DNS, drop log, and database changes into a report with IOCs and a draft YARA rule. Follows kadath-offer.
Dosyalar4 dosya
SKILL.md71 satır
Loading editor…
Kurulum
ÖnerilenTek komut — ajanınız otomatik olarak devreye alır.
Kurulum komutunu görmek için yukarıdan bir AI aracı seçin.
veya
Manuel Kurulum
Daha fazla adımArşivi indirin ve dosyaları projenize manuel olarak ekleyin.
Skill detayları
Versiyonv1.0.0
YazarAutomattic
Kategorianalysis
Skill IDAutomattic/KadathSandbox/.claude/skills/kadath-scry
Dosyalar4 dosya
İlgili skill'ler
Kadath GauntUse when you need OS-level evidence — syscalls, spawned processes with argv, file opens, raw connect() calls — from a WordPress sample running in KadathSandbox at /Users/fioa8c/WORK/KadathSandbox, rather than PHP-level Xdebug traces. Covers attaching strace and bpftrace to php-fpm via the tracer sidecar during a trigger.Kadath OfferUse when offering, running, executing, or "seeing what it does" for an untrusted WordPress plugin, theme, webshell, dropper, or loose PHP sample in the KadathSandbox sandbox at /Users/fioa8c/WORK/KadathSandbox — staging the sample, triggering it so its behaviour is traced, and marking the run so the artifacts can be attributed to it. Hands off to kadath-scry for the report.Kadath WardUse when operating, starting, resetting, snapshotting, self-testing, or troubleshooting the KadathSandbox WordPress malware sandbox at /Users/fioa8c/WORK/KadathSandbox — bringing the stack up, fixing a failing self-test or a container that will not come healthy, and understanding the containment model so you never weaken it to make a sample run.Dashboard Create ScreenCreate a new screen in the Multi-site Dashboard with automatic route registrationSelf Approve PrCheck whether a Pocket Casts Android pull request qualifies for self-approval and, if it does, label it "[Review] Self Approved". Use this whenever the user asks if they can self-approve, self-review, or merge their own PR without a human reviewer, or asks to "self-approve this PR". Pass a PR number as an argument, or run it from a branch with an open PR. Pass "check" to report the verdict without labelling.PrMUST be invoked before creating any PR, pushing a branch for review, or running `gh pr create`. Covers changelog entries, branch naming, PHPCS/PHPUnit checks, and reviewer assignment.