GitHub 解封 — 账号封禁/限制/恢复的领域操作系统。覆盖:(a) GitHub 官方政策体系 (TOS / 可接受使用政策 / Trust & Safety 执行模式 / 公开申诉路径 / 受制裁地区解读);(b) 封号原因诊断学 (spam / abuse / 制裁误标 / 2FA 丢失 / ToS 违规 / 账号劫持误判 / ban evasion 等子类型 + 症状→原因映射 + 自我分诊压测);(c) 申诉实操 craft (写一封能让 T&S 快速判误伤的英文申诉信 + 升级阶梯 + 法务介入边界 + Don'ts);(d) 制裁与合规硬边界 (OFAC SDN 名单 / 哪些国家或地区真不可达 / VPN 误判路径 / 中国大陆不是美国制裁地区的反复重申);(e) 中国大陆开发者特别处境 (sanctioned region 误标 + SMS 验证不支持 +86/+852 + Gitee/GitLab/Codeberg/JihuLab 备用迁移 + 私有自托管 Gitea/Forgejo);(f) 真实案例库 (~30+ 公开案例分类拆解:误伤 / 真违规 / 制裁误标三类各自赔率与申诉成功路径)。伦理锚绝不软化:不教 ban evasion / 不教撒谎式申诉 / 真违规承认改进 / 丢 2FA 无恢复因子则诚实告知 / 中国制裁误标靠申诉不靠换 VPN / 申诉 6 个月窗口必算清 / 约 3% (业内估) 真违规恢复 vs 约 79% (业内估) 误伤申诉成功率分层标。 (GitHub Account Reinstatement — the domain operating system for GitHub (and analogous platform) account suspension, restriction, appeal, and recovery. Covers: (a) GitHub official policy architecture (TOS / Acceptable Use Policies / Trust & Safety enforcement patterns / public appeals pathways / sanctioned-region interpretation); (b) suspension-cause diagnostics (spam / abuse / sanctions mis-flag / 2FA loss / ToS violation / account hijack false-positive / ban evasion taxonomy + symptom→cause mapping + self-triage pressure test); (c) appeal craft (writing an English appeal letter that gets T&S to fast-track a false-positive ruling + escalation ladder + legal-engagement boundary + Don'ts); (d) sanctions and compliance hard boundaries (OFAC SDN list / which countries/regions are truly unreachable / VPN false-positive paths / China is NOT a US-sanctioned region — repeated emphasis); (e) mainland China developer special circumstances (sanctioned-region mis-flag + SMS verification does not support +86/+852 + Gitee/GitLab/Codeberg/JihuLab fallback migration + self-hosted Gitea/Forgejo); (f) real-case library (~30+ public cases with categorized analysis: false-positive / genuine violation / sanctions mis-flag, each with win-rate and appeal success path). Ethical anchors absolutely not softened: do NOT teach ban evasion (creating new accounts turns a temp ban into a permanent one — the single biggest mistake); do NOT teach social engineering or lying in appeals (misuse + actually confirms violation); genuine violations: admit + improve beats denial; lost 2FA + no recovery factor → do not pretend recovery is possible; China sanctioned-region mis-flag → fix via appeal, not repeated VPN switching; appeal form 6-month window must be counted carefully; historical 约 3% (业内估) genuine-violation recovery vs 约 79% (业内估) false-positive appeal success rate stratification must be honestly labeled. Anti-samples (explicitly describe harm, never endorse): developer permabanned for ban evasion / open-source team org-banned for personal attacks in public issues / cases where repeated VPN switching escalated risk-control severity.) Master OS — automated mastery of GitHub Account Reinstatement — the domain operating system for GitHub (and analogous platform) account suspension, restriction, appeal, and recovery. Covers: (a) GitHub official policy architecture (TOS / Acceptable Use Policies / Trust & Safety enforcement patterns / public appeals pathways / sanctioned-region interpretation); (b) suspension-cause diagnostics (spam / abuse / sanctions mis-flag / 2FA loss / ToS violation / account hijack false-positive / ban evasion taxonomy + symptom→cause mapping + self-triage pressure test); (c) appeal craft (writing an English appeal letter that gets T&S to fast-track a false-positive ruling + escalation ladder + legal-engagement boundary + Don'ts); (d) sanctions and compliance hard boundaries (OFAC SDN list / which countries/regions are truly unreachable / VPN false-positive paths / China is NOT a US-sanctioned region — repeated emphasis); (e) mainland China developer special circumstances (sanctioned-region mis-flag + SMS verification does not support +86/+852 + Gitee/GitLab/Codeberg/JihuLab fallback migration + self-hosted Gitea/Forgejo); (f) real-case library (~30+ public cases with categorized analysis: fa
日本語の概要は準備中です。原文の説明を表示しています。
swaylq/master-skill☆ 1492026年9月6日 更新
Exploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely. Techniques include response manipulation, referal spoofing, token reuse, and predictable backup codes.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
在授权渗透测试中挖掘认证/授权绕过(authentication & authorization bypass)。当目标的登录、SSO/OAuth/SAML、2FA、会话、密码重置、邮箱验证等鉴权环节可能被逻辑缺陷或解析差异绕过时使用——典型场景:SAML 签名/entityId 绕过、OAuth `response_type`/`redirect_uri` 篡改窃取 token、邮箱规范化/预验证绕过、2FA 可预测/可跳过、会话类型混淆。适用目标类型 Web / REST API / SSO。触发场景包括用户说"测下认证绕过""这个 SAML/OAuth 有没有问题""能不能跳过 2FA""邮箱验证能绕吗"。输出:绕过路径 + 越权访问证据的 finding(含 killed 记录)。
日本語の概要は準備中です。原文の説明を表示しています。
galact-byte/galact-Skills☆ 72026年10月2日 更新
Check American Airlines AAdvantage balance, elite status, and loyalty points via Patchright. Handles email 2FA with 6-box code entry. Uses persistent browser profiles to skip 2FA on subsequent runs.
日本語の概要は準備中です。原文の説明を表示しています。
borski/travel-hacking-toolkit☆ 6892026年10月5日 更新
sparkle-design(公開 npm パッケージ)の新バージョンをリリースするための手順スキル。 package.json の version bump、CHANGELOG.md の更新、リリース PR 作成、PR マージ後の npm への stage、メンテナーによる 2FA 承認(npm stage approve)、承認後の git tag・ GitHub Release 作成までを一連の手順で実行する。 CHANGELOG 更新漏れと GitHub Release 作成漏れを防ぐためのチェックリストを含む。 「sparkle-design をリリース」「sparkle-design の新バージョンを切る」「vX.Y.Z をリリース」 「sparkle-design の CHANGELOG を更新」で発動。 English: "release sparkle-design", "cut a new sparkle-design version", "publish sparkle-design", "bump sparkle-design version".
goodpatch/sparkle-design☆ 162026年10月2日 更新
Implement secure authentication and authorization systems with JWT, OAuth2, Session-based auth, and RBAC. Use when: (1) implementing user login/signup, (2) setting up JWT tokens, (3) OAuth2 integration (Google, GitHub, etc.), (4) role-based access control (RBAC), (5) password hashing and validation, (6) session management, (7) API authentication middleware, (8) 2FA/MFA setup. Triggers: "authentication", "login", "JWT", "OAuth", "session", "password hash", "RBAC", "permissions", "2FA".
日本語の概要は準備中です。原文の説明を表示しています。
aAAaqwq/openclaw-team☆ 22026年6月18日 更新
OpenClawのブラウザ操作で、ログイン状態やタブを確認しながら複数手順の作業を進めます。古くなった操作対象の参照やタイムアウトへの対処も扱います。
- 複数手順のウェブ作業を進めたいとき
- 操作前にログイン状態を確認したいとき
- タブの再利用と重複整理
openclaw/openclaw☆ 39.2万2026年10月11日 更新
Admin account register: system, main and backup admin, seats, plan, 2FA, shared logins and access-review dates, as CSV, SQL, JSON Schema or Notion on request. Use for access reviews.
日本語の概要は準備中です。原文の説明を表示しています。
sickn33/agentic-awesome-skills☆ 4.7万2026年10月10日 更新
Reference for the `dial` CLI — gives you a real phone number to send SMS, place AI voice calls, and receive inbound texts/codes via the Dial platform (getdial.ai). Use when the user mentions phones, calls, texts, SMS, voice, OTP, 2FA, or verification codes; when they ask to text, call, ring, or wait for a code from someone; before running any `dial …` command for the first time in a session; or when investigating what the Dial platform can do. Load this skill before invoking the CLI — `dial --help` alone will not surface the workflows, the `--json` conventions, or the docs-lookup pattern needed to use Dial correctly.
日本語の概要は準備中です。原文の説明を表示しています。
nanocoai/nanoclaw☆ 3.1万2026年10月10日 更新
Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA (CAPTCHA token replay / single-use / concurrency-window bypass specifics → hunt-captcha-bypass), IP-based rate-limit bypass via X-Forwarded-For and friends, ReDoS. Distinguishes hard lockout vs soft IP-throttle vs CAPTCHA-injection vs silent shadow-throttling (avoids false-negative 'no rate limit' conclusions). Medium to Critical depending on what the brute reaches (OTP→ATO = Critical).
日本語の概要は準備中です。原文の説明を表示しています。
elementalsouls/Claude-BugHunter☆ 4,9002026年10月10日 更新
Hunt MFA / 2FA bypass — 7 distinct patterns. (1) MFA not enforced on sensitive endpoints (password change, email change accept without MFA challenge), (2) MFA-step skip via direct navigation to post-login URL, (3) MFA-token replay (same code accepted twice), (4) brute-force the 6-digit OTP without rate limit (10^6 attempts at server speed), (5) race condition on OTP validation, (6) recovery-code dump via /api/me, (7) backup factor downgrade (SMS factor with no rate limit). Plus the chain: cookie theft + password oracle + no step-up = ATO without MFA challenge. Detection: trace auth flow in Burp, find every state transition, check if MFA is middleware-gated vs per-endpoint, check OTP entropy and rate limit on OTP-validate. Validate: attacker session reaching post-MFA state. Use when hunting auth bypass, MFA flows, chaining primitives toward ATO.
日本語の概要は準備中です。原文の説明を表示しています。
elementalsouls/Claude-BugHunter☆ 4,9002026年10月10日 更新
Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
日本語の概要は準備中です。原文の説明を表示しています。
mrgoonie/claudekit-skills☆ 2,2272026年4月3日 更新
Operates GitHub via gh CLI and REST/GraphQL — PRs, issues, Actions, repos, collaborators, org permissions, 2FA — with explicit target, authorization, and independent readback. Use when a write reports success but state didn't change, or choosing gh/REST/GraphQL/UI-only. Not for local Git recovery (use git-safety-net), maintainer PR review (use github-review-pr), or upstream contribution (use github-contributor).
日本語の概要は準備中です。原文の説明を表示しています。
daymade/claude-code-skills☆ 1,4512026年10月11日 更新
Get back into a locked or hacked account the right way — the official recovery routes, what proof you'll need, and how to re-secure it so it doesn't happen again. Use when asked I'm locked out of my account, my account got hacked, help me recover my [email/social/bank] account, or I lost access to 2FA. Produces the official recovery path for the account type, the identity proof to prepare, a re-securing checklist for after you're back in, and warnings about fake 'recovery' services and support scams.
日本語の概要は準備中です。原文の説明を表示しています。
mohitagw15856/pm-claude-skills☆ 1,4362026年10月10日 更新
Verify phone numbers using SMS one-time codes via the Didit API. Use when you need to confirm a user owns a phone number, implement SMS-based 2FA, or validate phone during signup/onboarding flows.
日本語の概要は準備中です。原文の説明を表示しています。
gooseworks-ai/goose-skills☆ 1,2422026年10月10日 更新
Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
日本語の概要は準備中です。原文の説明を表示しています。
Microck/ordinary-claude-skills☆ 4052026年9月7日 更新
Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL. Use when setting up Better Auth with NestJS backend, integrating Next.js App Router frontend, configuring Drizzle ORM schema, implementing social login (GitHub, Google), adding plugins (2FA, Organization, SSO, Magic Link, Passkey), implementing email/password authentication with session management, or creating protected routes and middleware.
日本語の概要は準備中です。原文の説明を表示しています。
giuseppe-trisciuoglio/developer-kit☆ 3572026年9月10日 更新
Bring up a REAL, visible, interactive chromium on the Kali VM that the operator logs into (Smart-ID / Mobile-ID / any manual auth or MFA/CAPTCHA), while the agent drives and observes it live through the chrome-devtools MCP (navigate, DOM snapshot, network capture, screenshots, console, evaluate). Use whenever a target needs a MANUAL login the agent cannot complete headlessly, when you need to capture an authenticated session / the real API calls a page makes, or to confirm/screenshot a DOM-XSS. Triggers - "open a browser", "log in manually", "smart-id / mobile-id / national id login", "mfa / 2fa login", "solve the captcha", "drive the browser", "capture the authenticated session / network".
日本語の概要は準備中です。原文の説明を表示しています。
Encod3d-Sec/TORCH☆ 3302026年9月1日 更新
Admin account register: system, main and backup admin, seats, plan, 2FA, shared logins and access-review dates, as CSV, SQL, JSON Schema or Notion on request. Use for access reviews.
日本語の概要は準備中です。原文の説明を表示しています。
lingxling/awesome-skills-cn☆ 3062026年10月7日 更新
Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks. Use when adding auth, encountering D1 adapter errors, or implementing OAuth/2FA/RBAC features.
日本語の概要は準備中です。原文の説明を表示しています。
secondsky/claude-skills☆ 2272026年9月28日 更新
Configure TOTP authenticator apps, send OTP codes via email/SMS, manage backup codes, handle trusted devices, and implement 2FA sign-in flows using Better Auth's twoFactor plugin. Use when users need MFA, multi-factor authentication, authenticator setup, or login security with Better Auth.
日本語の概要は準備中です。原文の説明を表示しています。
better-auth/skills☆ 2212026年9月1日 更新
Connect every external account NowStack Mobile needs (Convex, Expo/EAS, Apple Developer, Vercel, Stripe, Google Play) by acquiring PROGRAMMATIC API ACCESS for each, then doing everything automatically through that access. Use for "setup accounts", "connect my accounts", first-run onboarding, or when check-setup reports CLI/auth gaps. The skill obtains a token/key per service, stores it in the right place, and only asks the user for the irreducible manual steps (browser signup, 2FA, one-time key download). Every account is skippable.
日本語の概要は準備中です。原文の説明を表示しています。
Melvynx/saveit.now☆ 322026年10月10日 更新
Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
日本語の概要は準備中です。原文の説明を表示しています。
VoDaiLocz/kilo-kit-mcp☆ 272026年9月13日 更新
Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.
日本語の概要は準備中です。原文の説明を表示しています。
lilinji/GeneTind-Life-Skills☆ 142026年8月21日 更新