shell-obfuscation skillA
This file is byte-identical to the first copy the registry indexed. Same content hash, same audit grade.
shell-obfuscation is agent-read markdown (skill) from cha0upup/leoai: 理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
# Shell 生成与结构变体 Shell 是独立生成的制品,不从平台已有 Puppet 自动继承配置。只有用户明确要求“匹配/复制某个 Puppet”时,才可以查询该指定节点;不得因为平台上只有一个节点、最近操作过某个节点或当前页面选中了节点就读取它。 ## 生成模型 一次生成由五部分组成: 1. 运行时与承载方式:Java WebShell、Java 内存马或 PHP WebShell。 2. 用户本次选择的通信参数:传输协议、请求伪装器、响应伪装器。 3. 兼容与结构参数:JSP/JSPX、Java/Servlet 版本、容器、注入器、Packer、输出模式和混淆策略。 4. Java WebShell 的 Core 字节码只保存在服务端 `CoreArtifactStore`,AI 仅设计不含 Payload 的 Wrapper 模板。 5. 结果交付:生成器把完整结果写入 `ShellResultStore`,工具返回 `resultId`、元数据和取回按钮。 不要手写或转述完整生成代码,不要虚构工具未返回的结果。 ## 参数确认原则 1. 生成前调用 `getShellGeneratorMeta()` 获取协议、Java/Servlet、注入器、Packer 和混淆步骤等合法值。 2. 调用 `getDisguises()` 获取当前可选请求/响应伪装器;不得用 Puppet 查询代替该步骤。 3. 用户未给出的重要生成偏好必须通过 `request_user_input` 询问。Java WebShell 至少确认: - 传输协议:`http` 或 `httpchunk`; - 请求伪装器与响应伪装器; - 文件类型:`JSP` 或 `JSPX`; - 是否启用混淆。 4. Java WebShell 必须显式传 `obfuscate=true/false`;启用默认混淆时不传步骤,只有用户指定步骤时才从元数据中选择并保持顺序。 5. Java 版本和 Servlet 命名空间未指定时可使用 `auto`;已知 Jakarta 环境时显式使用 `jakarta`。 6. 类名未指定时留空,让生成器随机生成。不要为了填满参数而猜测用户意图。 ## Java WebShell 工作流 1. 调用 `getShellGeneratorMeta()` 和 `getDisguises()`。 2. 对尚未明确的传输协议、请求/响应伪装、JSP/JSPX 和混淆开关调用 `request_user_input`;调用后停止本轮,等待用户回答。 …
Read the whole file at its exact version.
How to install
mdr add cha0upup/leoai/shell-obfuscation@git:20260820.9149adfmdr add cha0upup/leoai/shell-obfuscation@sha256:77e5d2ed483b23e9Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_4atokc6j7g73qyoz)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260820.9149adf latest | 2026-08-20 | 9149adf | 6,015 B | A | view · diff |
| git:20260802.54e5f6a | 2026-08-02 | 54e5f6a | 5,923 B | A | view · diff |
| git:20260722.998d753 | 2026-07-22 | 998d753 | 12,887 B | A | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (6015 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
cha0upup/leoai · 307 stars · license GPL-3.0 · pushed 2026-09-19 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_4atokc6j7g73qyoz GET https://markdownregistry.com/api/v1/resolve?ref=cha0upup/leoai/shell-obfuscation GET https://markdownregistry.com/api/v1/blob/77e5d2ed483b23e9a4eb84838faedb43da782f436a525f322386f9b604ca0d44
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.