YottaMeta

Yotta Security Testing — Security skill for Claude Code

Security community

YuanCe (元测) — disciplined authorization-first security-testing methodology for AI agents: four-stage web security testing on authorized targets (SRC bug bounty / CTF / self-owned / labs) with built-in.

How to install Yotta Security Testing

This entry records only its repository, not the path inside it, so there is no exact command to give. Open YottaMeta/yotta-security-testing and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Yotta Security Testing does

YuanCe (元测) — disciplined authorization-first security-testing methodology for AI agents: four-stage web security testing on authorized targets (SRC bug bounty / CTF / self-owned / labs) with built-in Scope Guard (allowlist, target triage, blacklist, audit trail, legal redlines); zero executable payloads. Part of YottaSkills.

Alternatives in Security

  • Mcp-scan (Invariant Labs) — MCP security scanner with proxy mode for real-time scanning without infrastructure changes 1.9k ★
  • /web3 Audit — Smart contract security audit using the 10-bug-class methodology 927 ★
  • Maestro Knowledge — Intent-driven knowledge-store and Run knowledge lifecycle management — audit/prune, stage candidates (with sig 530 ★

README

Language: English · 中文

yotta-security-testing banner

yotta-security-testing · 元测 (YuanCe)

YottaMeta's disciplined, authorization-first security-testing methodology for Agent skills: a four-stage workflow — Reconnaissance → Discovery → Verification → Reporting — for web security testing on authorized targets only (self-owned assets, SRC / bug-bounty scope, CTF and local training labs), backed by a built-in Scope Guard that turns "authorized only" into a hard mechanism instead of a disclaimer.

Triggers when the user asks for security testing / penetration testing / vulnerability assessment on an authorized target, SRC bug bounty, CTF or lab drills (DVWA / OWASP Juice Shop / HTB / VulnHub), or a vulnerability assessment / pentest report; or says 元测 / security test / pentest / bug bounty / authorized test / scope check.

Zero dependencies (Python 3.8+ standard library); Windows + Linux + macOS; methodology and education oriented — no executable payloads.

License: MIT Standard: agentskills.io npm package GitHub stars last commit

Related Skills