Playbooks
Browse 249 playbooks across every security domain
ad-attacks
Active Directory credential attacks. Kerberoasting, AS-REP roasting, DCSync, Pass-the-Hash, Pass-the-Ticket, Silver Ticket, Golden Ticket, NTLM relay. Via Impacket + netexec (no Windows required).
ad-netexec
NetExec (CrackMapExec) complete workflow. SMB/WinRM/LDAP/MSSQL enumeration, credential spraying, code execution, credential dumping, lateral movement.
blue-detect
Blue team detection skill. WAF detection, IDS/IPS identification, log analysis, and malware detection. Use for defensive operations and incident detection.
blue-forensics
Blue team forensics skill. Memory forensics, disk analysis, timeline reconstruction, and evidence preservation. Use for deep forensic analysis and evidence collection.
blue-ir
Blue team incident response skill. Incident triage, timeline analysis, containment, and eradication. Use for incident response operations and breach investigation.
blue-report
Blue team reporting skill. Incident response reports, IOC documentation, and executive summaries. Use for blue team reporting and documentation.
codex-qa
QA the gitest Codex Light edition (lazycodex / GiScan/codex) itself, in strict isolation so ONLY our plugin is exercised, never the user's real ~/.codex. The first-party method drives the real `codex app-server` against an isolated CODEX_HOME plus a LOCAL mock model (no real API call), and proves a
ctf-android
CTF Android challenge analysis. APK static analysis with Jadx and APKTool, smali disassembly for flag validation logic, native library JNI reverse engineering with Radare2, ADB dynamic analysis with exported activity launch and content provider query, Frida dynamic instrumentation for method hooking
ctf-crypto
CTF cryptography skill. Hash cracking, encoding/decoding, RSA/AES challenges, and crypto analysis. Use for crypto challenges and hash identification.
ctf-crypto-advanced-math
CTF advanced math crypto. LLL lattice attacks, Coppersmith method, Pohlig-Hellman on smooth curves, isogeny graph traversal, quaternion RSA factoring, LWE via CVP, Manger padding oracle, non-permutation S-box collision, polynomial CRT in GF(2).
ctf-crypto-classic
CTF classic cipher attacks. Vigenere key recovery, Kasiski examination, XOR frequency analysis, multi-byte XOR key recovery, OTP key reuse (many-time pad), cascade XOR, book cipher, homophonic substitution.
ctf-crypto-ecc
CTF ECC attacks. Smart's attack on anomalous curves, Pohlig-Hellman, ECDSA nonce reuse, invalid curve, singular curves, Ed25519 torsion side channel, clock group DLP.
ctf-crypto-exotic
CTF exotic cryptography attacks. Braid group Diffie-Hellman Alexander polynomial multiplicativity attack, tropical semiring cryptography residuation-based key recovery, Paillier homomorphic encryption oracle binary search, Hamming code linear algebra brute-force, ElGamal multiplicative re-encryption
ctf-crypto-historical
CTF historical cipher attacks. Lorenz SZ40/42 (Tunny) delta attack with known plaintext, ITA2/Baudot encoding, book cipher brute force.
ctf-crypto-modern
CTF modern cipher attacks. AES padding oracle, CBC bitflipping, ECB image oracle, AES-CFB-8 IV state forging, GCM key recovery, LFSR attacks, hash length extension, CRIME compression oracle, CBC-MAC forgery.
ctf-crypto-prng
CTF PRNG attacks. Mersenne Twister state recovery, time-seeded PRNG brute force, LCG parameter recovery, V8 Math.random XorShift128+ Z3 solver, GF(2) matrix approach.
ctf-crypto-rsa
CTF RSA cryptography attacks. Small exponent cube root, common modulus, Wiener attack, Pollard p-1, Hastad broadcast, Fermat factorization, batch GCD, Manger padding oracle, p=q bypass, gcd(e,phi)>1, signature forgery.
ctf-crypto-zkp
CTF zero-knowledge proof and advanced cryptography attacks. Groth16 broken trusted setup delta==gamma forgery, Groth16 replay with unconstrained nullifier, DV-SNARG forgery via verifier oracle, KZG pairing oracle for permutation recovery, FROST lattice threshold signature attack, MAYO post-quantum f
ctf-exploit
CTF exploitation skill. Binary exploitation, web exploitation, crypto challenges, and privilege escalation. Use for CTF pwn, web, and misc challenges.
ctf-forensics
CTF forensics skill. Memory forensics, disk analysis, steganography, and file recovery. Use for forensic challenges and incident response.
ctf-forensics-3d-printing
CTF 3D printing and G-code forensics. PrusaSlicer binary G-code (bgcode/GCDE) parsing, heatshrink decompression, G-code coordinate visualization for hidden patterns, QOIF image format extraction, uncommon file format identification.
ctf-forensics-disk
CTF disk and memory forensics. Volatility 3 memory analysis, Sleuth Kit disk imaging, deleted file recovery, VMware snapshot analysis, ZFS forensics, RAID 5 recovery, Docker layer analysis, APFS snapshots, MFT analysis.
ctf-forensics-disk-memory
CTF disk and memory forensics. Volatility 3 process/network/MFT analysis, disk imaging with Sleuth Kit icat, VM forensics OVA/VMDK via 7z, vmss2core snapshot conversion, ransomware AES key oracle, RAID 5 XOR recovery, APFS/ZFS snapshot reversion, WordPerfect macro brute, Docker layer secrets, PowerS
ctf-forensics-disk-recovery
CTF disk forensics. LUKS master key recovery from memory, PRNG timestamp seed brute force, VBA macro encoded binary extraction, FemtoZip shared dictionary, XFS inode reconstruction, tar duplicate entry extraction, nested matryoshka filesystem, anti-carving null byte interleaving.
ctf-forensics-linux
CTF Linux and application forensics. Log analysis, Docker image layer inspection, browser credential decryption (Chrome/Firefox), KeePass cracking, git reflog orphan recovery, USB audio extraction, TLS decryption via weak RSA, TFTP netascii decode.
ctf-forensics-network
CTF network forensics. Wireshark/tshark PCAP analysis, TLS decryption with SSLKEYLOGFILE/RSA key, HTTP object extraction, USB HID decode, SMB3 decryption, TCP stream reconstruction, BCD encoding.
ctf-forensics-network-advanced
CTF advanced network forensics. Timing-based packet encoding, USB HID mouse/pen drawing recovery, DNS exfiltration via query names, TCP flag base64 covert channel, ICMP steganography, Active Directory RID recycling, Timeroasting NTP hash, decompression anomaly detection.
ctf-forensics-signals
CTF signals and hardware forensics. VGA binary signal decoding (800x525 total frame, 640x480 active, 5-byte samples), HDMI TMDS 10-bit symbol decode, DisplayPort 8b/10b LFSR descrambling, Voyager golden record audio sync pulse image extraction, side-channel power analysis DPA with variance-based lea
ctf-forensics-stego
CTF steganography forensics. LSB extraction, PNG/JPEG/BMP format tricks, PDF hidden layers, SVG animation, steghide, zsteg, stegsolve, bitplane analysis, QR codes hidden in images.
ctf-forensics-stego-advanced
CTF advanced steganography. FFT frequency domain image stego, SSTV decoding, DotCode barcode, DTMF custom frequency keypad, multi-track audio differential subtraction, cross-channel multi-bit LSB, video frame accumulation, audio waveform binary, spectrogram QR code, whitespace encoding in tar archiv
ctf-forensics-windows
CTF Windows forensics. Event log parsing (evtx), registry analysis, SAM hash extraction, MFT/USN journal analysis, wmiexec.py artifact detection, PowerShell history timeline, RDP event IDs, Windows Defender MPLog, anti-forensics detection.
ctf-heap-advanced
CTF advanced heap exploitation for modern glibc (2.27–2.35+). Tcache poisoning, tcache dup double-free, tcache key bypass, fastbin dup into stack, fastbin into __malloc_hook, unsorted bin libc leak, largebin attack arbitrary write, House of Force top-chunk overflow, House of Botcake overlapping chun
ctf-malware-analysis
CTF malware analysis. PE file analysis, .NET decompilation (dnSpy/ILSpy), C2 configuration extraction, PyInstaller unpacking, PyArmor bypass, sandbox evasion detection, LimeRAT C2 decryption.
ctf-malware-c2-protocols
CTF malware C2 traffic analysis. PCAP tshark protocol extraction, stream cipher shared keystream (ChaCha20 null-byte trick), RC4 WebSocket C2 decryption, AES-CBC key derivation from hardcoded strings, encryption algorithm identification by constants (AES S-box 0x637c777b, ChaCha20 'expand 32-byte k'
ctf-malware-pe-dotnet
CTF PE and .NET malware analysis. PE static triage with peframe/pestudio, sandbox evasion detection (VM artifacts, debugger checks, timing), .NET assembly analysis with dnSpy/ILSpy, LimeRAT C2 extraction via AES-256-ECB with MD5 key derivation, PyInstaller extraction with pyinstxtractor, PyArmor unp
ctf-malware-scripts
CTF malware script and obfuscation analysis. JavaScript eval deobfuscation, PowerShell -EncodedCommand base64 decode, junk code detection (NOP sleds, dead writes), hex-encoded payload XOR transforms, Debian package postinst analysis, dynamic behavioral analysis with strace/ltrace/tcpdump, YARA rule
ctf-misc-bashjails
CTF Bash jail escape techniques. Restricted shell bypass, character whitelist bypass, HashCashSlash trick, /proc/cmdline enumeration, /dev/tcp reverse shell, SUID escalation, glob expansion bypass.
ctf-misc-dns
CTF DNS exploitation. EDNS Client Subnet spoofing for geo-specific responses, DNSSEC NSEC zone walking, IXFR incremental zone transfer for deleted records, DNS rebinding, DNS tunneling detection in PCAP, custom DNS server with dnslib.
ctf-misc-encodings
CTF encoding challenges. Base64/32/hex decode, IEEE 754 float-as-text, UTF-16 mojibake fix, BCD decode, QR code repair, esoteric languages (Whitespace, Brainfuck, Piet), SMS PDU reassembly, Gray code, RTF hidden data, multi-layer cascade decoder.
ctf-misc-games-vms
CTF misc games and VMs. WASM game AI weakening via wasm2wat patching, Roblox version history binary format parsing, PyInstaller extraction with opcode remapping, Python marshal code analysis, Python environment RCE via PYTHONWARNINGS, Z3 constraint solving for custom VMs, YARA rules with Z3, Kuberne
ctf-misc-games-vms-2
CTF misc challenges part 2. ML model weight perturbation and LoRA adapter attacks, Flask session secret brute-force and decode, WebSocket coordinate/state manipulation, De Bruijn sequence generation for format string or offset discovery, Brainfuck/esoteric VM instrumentation and tracing, WASM linear
ctf-misc-pyjails
CTF Python jail escape techniques. Class hierarchy traversal, compile bypass, unicode bypass, decorator-based escape, walrus operator, octal escapes, oracle-based challenges, mastermind-style, restricted charset, quine+context detection, func_globals chain.
ctf-misc-rf-sdr
CTF RF/SDR signal processing. IQ file formats (cf32/cs16/cu8), spectrum analysis, QAM-16 demodulation with carrier and timing recovery, cyclostationary analysis for symbol rate, Mueller-Muller timing, GNU Radio integration.
ctf-osint-geolocation
CTF OSINT geolocation and media analysis. Reverse image search (Google Lens crop, Yandex for faces, Baidu for China), MGRS military grid coordinate conversion, Google Plus Codes (XXXX+XX format), metadata extraction with exiftool, VGA signal analysis, Google Street View panorama matching with ORB fe
ctf-osint-social
CTF OSINT social media investigation. Twitter/X persistent IDs, Tumblr header fingerprinting, BlueSky API, Unicode homoglyph steganography, Discord metadata, Strava GPS exposure, multi-platform username enumeration.
ctf-osint-web
CTF OSINT web and DNS investigation. Google dorking, DNS TXT/zone transfer, WHOIS, Wayback Machine CDX API, certificate transparency, OSINT framework.
ctf-pwn-advanced-exploits
CTF advanced exploitation. VM signed comparison bugs, BF JIT RWX shellcode, type confusion in interpreters, off-by-one index to size corruption, ASAN shadow memory exploitation, format string with encoding constraints, .fini_array hijack, VM GC-triggered UAF slab reuse, FSOP seccomp bypass, integer
ctf-pwn-advanced-exploits-2
CTF advanced exploitation part 2. io_uring UAF SQE injection, GF(2) Gaussian elimination for tcache poisoning, signed/unsigned char underflow heap overflow, TLS destructor hijack via pointer guard forgery, custom shadow stack bypass via pointer overflow, XSS-to-binary pwn bridge with newline injecti
ctf-pwn-basics
CTF binary exploitation basics. Stack buffer overflow, ret2win, stack alignment, offset calculation, cyclic pattern, struct pointer overwrite, signed integer bypass, canary brute-force on forking servers, OOB read via stride.
ctf-pwn-format-string
CTF format string exploitation. GOT overwrite via %n, canary/PIE leak, argument retargeting, blind pwn, free_hook overwrite, argv[0] stack smash info leak, format string game state manipulation.
ctf-pwn-heap
CTF heap exploitation. House of Apple 2 (FSOP), House of Einherjar, tcache poisoning, seccomp bypass, ret2dlresolve, musl libc attacks, setcontext pivot, tcache stashing unlink.
ctf-pwn-kernel
CTF Linux kernel exploitation. QEMU debugging setup, KASLR/FGKASLR bypass, kernel heap spray (tty_struct, poll_list), stack overflow, ret2usr, kernel ROP, prepare_kernel_cred/commit_creds, modprobe_path overwrite, iretq restoration.
ctf-pwn-kernel-bypass
CTF kernel protection bypass techniques. KASLR bypass via stack leak, FGKASLR bypass using stable .text gadgets and __ksymtab relative offset resolution, KPTI bypass via swapgs_restore trampoline (+22 offset), SIGSEGV handler, modprobe_path ROP, core_pattern overwrite, SMEP/SMAP bypass with kernel R
ctf-pwn-kernel-techniques
CTF kernel exploitation advanced techniques. tty_struct RIP hijack via fake vtable with leave gadget stack pivot, AAW via ioctl register control for modprobe_path overwrite, userfaultfd race stabilization with page split across boundary, SLUB freelist pointer hardening (middle offset kernel 5.7+), f
ctf-pwn-rop
CTF binary exploitation ROP chains and shellcode. ret2libc, ret2csu, raw syscall ROP, rdx control, stack pivot, bad character bypass via XOR, exotic gadgets (BEXTR/XLAT/STOSB), sprintf gadget chaining.
ctf-pwn-rop-advanced
CTF advanced ROP techniques. Double stack pivot via leave/ret, SROP with UTF-8 constraints, architecture switching via RETF to bypass seccomp, vDSO gadget harvesting, vsyscall fixed addresses, .fini_array hijack, seccomp alternative syscalls.
ctf-pwn-sandbox
CTF sandbox escape. Python jail escape, custom bytecode VM exploitation, FUSE/CUSE character device exploitation, busybox restricted shell, /proc/self/mem write-anywhere, shell fd redirection tricks.
ctf-recon
CTF reconnaissance skill. Fast OSINT, flag format detection, challenge identification. Use for CTF challenges, binary analysis, and crypto challenges.
ctf-reverse-anti-analysis
CTF anti-analysis bypass. Linux anti-debug (ptrace, /proc, timing, SIGILL), Windows anti-debug (PEB, NtQuery, TLS callbacks, hardware BP detection), anti-VM/sandbox detection, Frida detection bypass, code integrity bypass, anti-disassembly, MBA simplification.
ctf-reverse-dynamic
CTF dynamic analysis tools. Frida hooking, angr symbolic execution, lldb, x64dbg, Qiling cross-platform emulation, Intel Pin instruction counting side channel.
ctf-reverse-languages
CTF reverse engineering by language. Python bytecode (dis, PyInstaller, Pyarmor), Ruby/Perl polyglot, OPAL functional, UEFI VM bytecode, Unity IL2CPP, Roblox asset versioning, Godot KeyDot, HarmonyOS ABC, Electron ASAR, Rust serde_json, Node.js runtime introspection.
ctf-reverse-patterns
CTF reverse engineering patterns. Custom VM analysis, anti-debug bypass, XOR known-plaintext, control flow flattening, mixed-mode execution, signal-based obfuscation, S-box/keystream identification.
ctf-reverse-patterns-ctf
CTF-specific reverse engineering patterns. Hidden opcode crypto key capture, image XOR mask via smoothness, RC4 parameter extraction, Z3 VM constraint solving, Sprague-Grundy Nim strategy, block cipher zero diffusion, meet-in-middle hash inversion, kernel ioctl maze, recursive process counter, RWX s
ctf-reverse-patterns-ctf-2
CTF reverse engineering competition patterns part 2. Multi-layer self-decrypting binary with JIT fork execution, embedded ZIP XOR license decryption, .rodata XOR blob deobfuscation, prefix hash brute-force, CVP/LLL lattice for constrained ASCII validation, decision tree function obfuscation via Ghid
ctf-reverse-platforms
CTF reverse engineering by platform. macOS Mach-O analysis, iOS class-dump, IoT/embedded firmware (ARM/MIPS), Linux kernel modules, eBPF programs, game engines (Unreal .pak, Unity C#), automotive CAN/UDS, RISC-V custom extensions, HD44780 LCD reconstruction.
ctf-reverse-tools
CTF reverse engineering tools. GDB/pwndbg, Radare2/Cutter, Ghidra, Binary Ninja, dogbolt.org multi-decompiler, Unicorn emulation, FLIRT signatures, angr symbolic execution.
ctf-reverse-tools-advanced
CTF advanced reverse engineering tooling. VMProtect devirtualization, Themida unpacking, BinDiff/Diaphora patch analysis, D-810 deobfuscation, GOOMBA Ghidra, Miasm IR lifting, Qiling emulation, Triton symbolic execution, rr reverse debugging, pwndbg/GEF, LIEF binary patching.
ctf-wasm
CTF WebAssembly challenge analysis. Initial recon with wasm-objdump, WAT decompilation with wasm2wat, wasm-decompile pseudo-code, wasm2c native compilation for ltrace/GDB analysis, wasmtime/wasmer execution, WASM linear memory dump and string extraction, binary patching via WAT edit then wat2wasm, X
ctf-web-auth-access
CTF web auth and access control. Structured ID as password, weak MAC forgery, HAProxy URL encoding bypass, Express %2F route bypass, NoSQL boolean injection, LLM chatbot secret leak, affine cipher OTP brute, IDOR with zero UUID.
ctf-web-auth-infra
CTF web infrastructure authentication attacks. OAuth open redirect token theft, OIDC alg-none manipulation, OAuth state CSRF, CORS reflected origin exploitation, git history credential leakage, CI/CD variable credential theft, identity provider API takeover (authentik/Keycloak), SAML SSO flow automa
ctf-web-client-side
CTF client-side web attacks. XSS filter bypass, DOMPurify bypass via backend trust, DOM XSS jQuery hashchange, shadow DOM exfiltration, JPEG+HTML polyglot, image timing oracle, CSS text exfiltration without JS, Alpine.js/Hyperscript attribute execution.
ctf-web-cves
CTF web CVE exploitation. Next.js middleware bypass, PaperCut admin bypass, Ruby-SAML forgery, Uvicorn CRLF injection, ExifTool DjVu RCE, WeasyPrint SSRF, Zabbix SQL injection, React Server Components RCE, prototype pollution.
ctf-web-node-prototype
CTF Node.js prototype pollution and VM escape. flatnest CVE-2023-26135, lodash merge pollution, Pug AST injection, Happy-DOM VM escape, full pollution-to-RCE chains.
ctf-web-server-deser
CTF web server-side deserialization and execution attacks. Java deserialization with ysoserial gadget chains (CommonsCollections, Spring, URLDNS), Python pickle deserialization RCE via __reduce__, race condition TOCTOU balance bypass, VolgaCTF pickle chaining via STOP opcode stripping with os.dup2 s
ctf-web-server-exec
CTF web server code execution challenges — PHP webshell, eval bypass, command injection CTF, RCE via deserialization, sandbox escape.
ctf-web-server-side
CTF web server-side injection attacks. PHP type juggling, LFI/php://filter, SQL injection (backslash escape, hex, second-order, LIKE brute-force, column truncation, SQLi-to-SSTI), SSTI (Jinja2, Go, EJS, ERB, Mako, Twig), SSRF, XXE, command injection, Host Header SSRF, DNS rebinding.
ctf-web-server-side-advanced
CTF advanced server-side web exploitation. ExifTool DjVu ANTa eval injection, Go rune/byte mismatch UTF-8 length bypass, ZIP symlink traversal for file read, React Server Components Flight protocol RCE via constructor chain, Castor XML xsi:type polymorphism to JNDI/RMI, Nginx URL-encoded slash path
ctf-web-web3
CTF Web3/blockchain challenges. EIP-1967 proxy exploitation, ABI coder v1 dirty address bypass, Groth16 proof forgery, delegatecall storage abuse, Solidity transient storage bug, phantom market manipulation, Foundry/cast tools.
forensic-disk
Disk forensics skill. File carving, file system analysis, deleted file recovery, timeline reconstruction, and artifact extraction from disk images. Tools: autopsy, foremost, bulk_extractor, binwalk, exiftool.
forensic-memory
Memory forensics skill. Acquires and analyzes RAM dumps using volatility3. Extracts process lists, network connections, injected code, encryption keys, and malware artifacts.
forensic-network
Network forensics skill. PCAP analysis, traffic reconstruction, C2 detection, credential extraction, and protocol analysis using tshark, tcpdump, and wireshark.
forensic-report
Forensic report generation skill. Compiles memory, disk, and network findings into a chain-of-custody IR report. Includes IOC list, timeline, evidence inventory, and remediation roadmap.
framework-django
Django framework security testing — admin panel exposure, DEBUG mode RCE, CSRF bypass, secret key extraction, SSTI via templates, SQL via ORM raw queries.
framework-dotnet
ASP.NET/Core security testing — ViewState deserialization, TRACE method info leak, Razor SSTI, Windows auth bypass, IIS misconfiguration, web.config exposure, machineKey extraction.
framework-express
Express.js/Node.js security testing — prototype pollution, CORS misconfiguration, middleware bypass, npm dependency vulns, JWT abuse, path traversal via static serving, eval injection.
framework-fastapi
FastAPI security testing — OpenAPI schema exposure, auth dependency bypass, SSRF via request parameters, dependency injection abuse, pydantic bypass, debug endpoints.
framework-flask
Flask security testing — Werkzeug debug console RCE, secret key brute force, Jinja2 SSTI, session cookie forgery, PIN generation, unsafe redirects.
framework-laravel
Laravel security testing — .env file exposure, debug mode info leak, mass assignment via Eloquent, Laravel Telescope exposure, queue deserialization, CSRF bypass, route listing.
framework-nextjs
Next.js security testing — API route exposure, getServerSideProps SSRF, build output disclosure, middleware bypass, next.config.js misconfig, rewrites abuse, image proxy SSRF.
framework-php
PHP security testing — LFI/RFI, file upload bypass, eval injection, type juggling loose comparison, phpinfo disclosure, PHP wrappers, log poisoning, deserialization via unserialize().
framework-rails
Ruby on Rails security testing — mass assignment via strong parameters bypass, YAML deserialization, SQL injection via ActiveRecord raw queries, debug routes, Rails secrets exposure, cookie tampering.
framework-spring
Spring/Spring Boot security testing — actuator endpoint exposure (/actuator/env /actuator/heapdump), SpEL injection, Spring4Shell (CVE-2022-22965), Spring Security misconfig, H2 console, Eureka registry.
framework-wordpress
WordPress security testing — user enumeration, xmlrpc.php abuse, plugin/theme CVEs, REST API exposure, WP-JSON, admin upload RCE, credential brute force.
get-unpublished-changes
Compare HEAD with the latest published npm versions and list all unpublished changes by release layer.
github-triage
Read-only GitHub triage for issues AND PRs. . item = . background task (category: quick). Analyzes all open items and writes evidence-backed reports to /tmp/{datetime}/. Every claim requires a GitHub permalink as proof. NEVER takes any action on GitHub - no comments, no submits, no closes, no labels
hyperplan
Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `pl
iot-firmware
IoT and embedded firmware security analysis. Firmware extraction, binwalk filesystem extraction, credential discovery, binary analysis, QEMU emulation, web interface testing.
mobile-android
Android app security testing skill. APK decompilation, static analysis, sensitive data discovery, manifest analysis, and network traffic interception. Tools: apktool, jadx, adb, frida, mobsf.
mobile-dynamic
Mobile dynamic testing skill. API security testing, traffic analysis, session management, authentication bypass, and business logic testing for mobile backend APIs.
mobile-ios
iOS app security testing skill. IPA analysis, jailbreak detection bypass, SSL pinning bypass, Keychain inspection, runtime class introspection, and traffic interception using frida, objection, and MobSF.
mobile-report
Mobile pentest report generation skill. Compiles Android/iOS static and dynamic findings into a structured security report with CVSS scores, PoCs, and OWASP Mobile Top 10 mapping.
opencode-qa
QA opencode itself, per case: verify the CLI/terminal (opencode run, db, serve, export), prove a specific plugin hook/action/event fired via the SSE event stream, smoke-test the TUI under tmux, and investigate sessions in opencode's SQLite DB by id, title/name, or message text. Ships tested helper s
payload-command-injection
Command injection payload collection and exploitation — pipe/semicolon/backtick/newline injection, blind OOB exfiltration, filter bypass encodings, WAF evasion, polyglot OS command injection.
payload-csv-injection
CSV formula injection payloads. Excel/Google Sheets formula execution via exported CSV, HYPERLINK exfiltration, WEBSERVICE/IMPORTXML data exfil, bypass techniques.
payload-http-param-pollution
HTTP Parameter Pollution (HPP) testing. Duplicate parameter injection, first-wins vs last-wins precedence, query/body override, JSON body conflict, path semicolon smuggling, validation bypass via arrays.
payload-ldap-injection
LDAP injection payloads and testing. Filter breakout, authentication bypass, blind enumeration, attribute extraction.
payload-lfi
LFI/path traversal payload collection — directory traversal sequences, null byte, URL encoding, double encoding, PHP wrappers, log poisoning for RCE.
payload-redos
ReDoS (Regular Expression Denial of Service) testing. Nested quantifier detection, catastrophic backtracking payloads, email/URL/date validation bypass, input length scaling attack.
payload-sqli
SQL injection payload collection — auth bypass, UNION select, blind boolean, time-based, stacked queries, OOB DNS exfiltration, DBMS-specific payloads (MySQL/PostgreSQL/MSSQL/SQLite/Oracle).
payload-ssi-injection
Server-Side Include (SSI) injection payloads. Command execution via exec cmd, file inclusion, environment variable disclosure, printenv.
payload-ssrf
SSRF payload collection — cloud metadata endpoints (AWS/GCP/Azure), internal port scan, protocol abuse (gopher/dict/file/sftp), bypass techniques (127.0.0.1 variants, IPv6, DNS rebinding, open redirect chains).
payload-ssti
SSTI payload collection — Jinja2/Python, Twig/PHP, FreeMarker/Java, Velocity/Java, Smarty/PHP, Mako/Python, Handlebars/Node, ERB/Ruby template injection payloads for RCE.
payload-xpath-injection
XPath injection payloads and testing. Authentication bypass, boolean-based blind extraction, XML node enumeration.
payload-xss
XSS payload collection — reflected/stored/DOM, filter bypass, CSP bypass, polyglot, event handlers, SVG/HTML5, mXSS, blind XSS, cookie theft, keylogger payloads.
payload-xxe
XXE payload collection — classic file read, OOB via DNS/HTTP callback, blind XXE, SVG XXE, XInclude, SSRF via XXE, error-based XXE, parameter entity abuse.
pentest-enum
Pentest enumeration skill. Orchestrates nuclei, ffuf, gobuster, whatweb, and wafw00f for directory brute-forcing, vulnerability scanning, and technology fingerprinting. Use for web application enumeration and vuln discovery.
pentest-exploit
Pentest exploitation skill. Orchestrates sqlmap, commix, hydra, hashcat, and john for SQL injection, command injection, credential attacks, and password cracking. Use for vulnerability exploitation and proof-of-concept generation.
pentest-mode
Pentest mode selector skill. Selects engagement mode (Auto/CTF/Bug Bounty/Red Team/Blue Team/Offensive/Grey Hat) based on target or user preference. Configures tool priority, skill chain, loop config, and report format. Use before starting any pentest engagement.
pentest-recon
Pentest reconnaissance skill. Orchestrates subfinder, httpx, naabu, and massdns for passive and active subdomain discovery, port scanning, and HTTP probing. Use for bug bounty recon, attack surface mapping, and subdomain enumeration.
pentest-report
Pentest reporting skill. Compiles findings from all phases into a structured report with severity ratings, PoC, and remediation advice.
pentest-workflow
Full pentest workflow orchestrator. Chains mode-specific skills (CTF/Bug Bounty/Red Team/Blue Team/Offensive/Grey Hat) for end-to-end security testing. Manages engagement state, enforces scope, and generates findings. Use after selecting mode with pentest-mode skill.
post-bloodhound
BloodHound Active Directory attack path analysis. bloodhound-python collection, Neo4j Cypher queries, shortest path to DA, Kerberoastable accounts, ASREPRoastable, ACL edges, unconstrained delegation, session data.
post-container-escape
Container escape and Docker breakout techniques. Privileged containers, Docker socket exploitation, cgroup v1 release agent, nsenter, CVE-based kernel escapes, Kubernetes pod escape.
post-credential-dumping
Windows credential dumping post-exploitation. LSASS dump via procdump/nanodump/comsvcs, SAM/SYSTEM/SECURITY hive extraction, NTDS.dit dump via shadow copy, DCSync attack, LSA secrets, cached credentials, DPAPI, hash cracking, pass-the-hash.
post-lateral-movement
Lateral movement skill for post-exploitation. Credential spraying, pass-the-hash, WMI/SMB/WinRM execution, SSH key pivoting, and internal network traversal.
post-linux-privesc
Linux privilege escalation skill. Systematic enumeration and exploitation of sudo misconfigs, SUID binaries, writable cron jobs, capabilities, kernel exploits, and weak file permissions.
post-pivoting
Network pivoting skill for post-exploitation — SSH tunneling, SOCKS proxy, chisel, ligolo-ng, socat port forwarding, double pivot, rpivot.
post-windows-privesc
Windows privilege escalation skill. Token impersonation, unquoted service paths, weak service permissions, AlwaysInstallElevated, credential extraction, and scheduled task abuse.
pre-submission-review
Nuclear-grade .6-agent pre-submission submission gate. Runs /get-unpublished-changes to detect all changes since last npm release, spawns up to .0 ultrabrain agents for deep per-change analysis, invokes /review-work (5 agents) for holistic review, and . oracle for overall release synthesis. Use befo
proto-dns
DNS security testing — zone transfer, DNS cache poisoning, DNS amplification, subdomain enumeration via brute force, DNSSEC bypass, DNS rebinding.
proto-ftp
FTP security testing — anonymous login, brute force, FTP bounce, PASV/PORT exploitation, clear-text sniffing, path traversal in FTP.
proto-graphql
GraphQL security testing skill. Tests introspection, authorization bypasses, IDOR via aliases, batching abuse, path-level auth bypass, and federation exploitation.
proto-kerberos
Kerberos security testing — Kerberoasting, AS-REP roasting, Pass-the-Ticket, Golden/Silver Ticket, SPN enumeration, unconstrained delegation, constrained delegation bypass.
proto-ldap
LDAP security testing — anonymous bind, LDAP injection, user enumeration, attribute extraction, Kerberoasting prep, LDAP injection bypass.
proto-mssql
Microsoft SQL Server (MSSQL) penetration testing. Authentication, enumeration, xp_cmdshell RCE, linked server abuse, privilege escalation, database enumeration, UNC path capture, OPSEC considerations.
proto-rdp
RDP security testing — BlueKeep/DejaBlue detection, credential brute force, NLA bypass, RDP session hijacking, pass-the-hash via RDP, restricted admin mode.
proto-smb
SMB/NetBIOS security testing skill. Null session enumeration, credential spraying, pass-the-hash, relay attacks, EternalBlue, and share enumeration.
proto-smtp
SMTP/IMAP security testing — SMTP relay, user enumeration via VRFY/RCPT, email spoofing (SPF/DKIM/DMARC bypass), SMTP injection, credential brute force.
proto-snmp
SNMP security testing — community string brute force, SNMP v1/v2c info dump, OID enumeration, SNMP write abuse, MIB walking.
proto-ssh
SSH security testing — version detection, brute force, key-based auth bypass, SSH tunneling, authorized_keys misconfiguration, weak ciphers.
proto-vnc
VNC (Virtual Network Computing) enumeration and exploitation. No-auth check, VNC brute force, CVE-2006-2369 auth bypass, screenshot capture, LibVNCServer CVEs, SSH tunnel access.
publish
Publish gitest to npm via GitHub Actions workflow. Argument: <patch|minor|major>.
re-dynamic
Dynamic binary analysis skill. Runtime debugging, system call tracing, library call tracing, memory inspection, and exploit development using gdb, pwndbg, strace, ltrace, and angr.
re-static
Static reverse engineering skill. Disassembly, decompilation, string extraction, and binary analysis without execution. Tools: ghidra, radare2, cutter, strings, binwalk, objdump.
recon-asn-whois
ASN, WHOIS, and OSINT reconnaissance — IP range discovery via ASN, WHOIS pivoting, BGP intelligence, CIDR block enumeration, IP history, corporate netblock mapping.
recon-cloud-assets
Cloud asset discovery reconnaissance. S3 bucket enumeration, Azure Blob storage, GCP Cloud Storage, cloud subdomain identification, misconfigured storage exposure, cloud infrastructure mapping.
recon-devtools
Exposed developer tools and debug interfaces detection — Webpack DevServer, React DevTools, Vue DevTools, exposed metrics endpoints, debug ports, GraphiQL, Jupyter notebooks, Kibana.
recon-dorking
Google/Bing/DuckDuckGo dorking skill for passive OSINT reconnaissance. Discovers exposed credentials, sensitive files, admin panels, git repos, and attack surface via search engine operators.
recon-favicon
Favicon hash fingerprinting for asset discovery. MurmurHash3 (mmh3) computation of favicon.ico from target URLs, Shodan http.favicon.hash search, FOFA icon_hash search, Censys favicon hash search, httpx live verification of discovered assets.
recon-full
Comprehensive full reconnaissance methodology — passive intel, subdomain enumeration, live host detection, port scanning, tech stack fingerprinting, JS analysis, secret hunting.
recon-internal
Internal network penetration test reconnaissance — network discovery, service enumeration, LDAP/AD enumeration, SMB shares, internal web apps, printer discovery.
recon-js-analysis
JavaScript analysis skill for SPA reconnaissance. Extracts API endpoints, hardcoded secrets, internal hostnames, and authentication tokens from client-side JavaScript bundles.
recon-js-hostname
JavaScript internal hostname intelligence — extract internal hostnames, API endpoints, microservice URLs, cloud metadata endpoints, internal IP addresses from client-side JavaScript.
recon-secrets
Secrets and credential exposure scanning — gitleaks, trufflehog, JS secret scanning, S3 bucket secrets, environment variables, hardcoded credentials in source code.
recon-shodan
Shodan, Censys, FOFA passive reconnaissance. ASN enumeration, IP range discovery, favicon hashing, internet-wide scanning, exposed service discovery.
recon-subdomain
Subdomain enumeration. subfinder, assetfinder, amass passive, dnsx resolution, httpx live service detection, permutation/brute-force, high-value subdomain prioritization.
red-exploit
Red team exploitation skill. Stealth exploitation, persistence, and privilege escalation. Use for red team engagements requiring stealth and persistence.
red-lateral
Red team lateral movement skill. Active Directory attacks, SMB/WinRM pivoting, and credential relay. Use for red team lateral movement and domain dominance.
red-persistence
Red team persistence skill. Backdoor mechanisms, scheduled tasks, registry persistence, and covert channels. Use for establishing long-term access during red team engagements.
red-recon
Red team reconnaissance skill. Stealth OSINT, passive enumeration, and social engineering preparation. Use for red team engagements requiring stealth.
remove-deadcode
Remove unvalidated findings from this project with fullscan mode, scope-verified safety, atomic evidence records.
security-research
Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release
tech-apache-misconfig
Apache httpd misconfiguration testing — .htaccess bypass, mod_status, directory listing, server-info, TRACE method, Optionsbleed, path traversal via Alias.
tech-cicd
CI/CD pipeline security attacks. GitHub Actions pull_request_target exploitation, GitLab CI variable injection, Jenkins RCE via Groovy console, secret scanning, OIDC token hijacking, dependency confusion.
tech-cloud-security
Cloud security assessment skill for AWS, GCP, and Azure. Tests IMDS abuse, IAM privilege escalation, misconfigured storage, exposed credentials, serverless security, and container escapes.
tech-config-hardening
Web application and server configuration hardening review. Security header audit (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy), TLS/SSL configuration check, debug endpoint enumeration (actuator, metrics, env, debug, swagger), verbose error message detection, backup and config
tech-debt-audit
Thorough, file-cited technical debt audit across 9 dimensions using AST-grep (tree-sitter), grep, language-native tooling, and optionally CodeGraph knowledge graph. Produces ATTACK_SURFACE_AUDIT.md with severity, effort estimates, and prioritized fixes. Use when asked for target coverage check, atta
tech-docker
Docker and container security testing — privileged container escape, docker socket abuse, container breakout, image secret scanning, registry credentials, Kubernetes misconfiguration.
tech-elasticsearch
Elasticsearch and Kibana security testing — unauthenticated data exposure, index enumeration, PII data extraction, Kibana console RCE, snapshot abuse, CVE exploitation.
tech-enterprise-web
Enterprise web penetration testing workflow. Scope definition, httpx fingerprinting, katana crawling, nuclei scanning, authentication testing, JWT analysis, business logic review, IDOR, dependency SCA, manual verification.
tech-firebase
Firebase security testing — Firestore/RTDB unauthenticated read/write, Firebase Auth bypass, Storage bucket enumeration, API key exposure, Cloud Functions SSRF.
tech-frida-hooking
Frida dynamic instrumentation and hooking. Android/iOS SSL pinning bypass, method interception, memory patching, native hook, Java method override, argument/return value modification, runtime analysis.
tech-git-platforms
Git platform security testing — GitLab/GitHub/Gitea misconfigs, exposed .git repos, API token abuse, CI/CD pipeline injection, secret scanning in public repos.
tech-jenkins
Jenkins security testing — unauthenticated RCE via Groovy console, credential exposure, Jenkinsfile injection, CSRF bypass, build artifact secrets, pipeline abuse.
tech-kubernetes
Kubernetes cluster security assessment. API server enumeration, kubelet exploitation, etcd access, RBAC misconfigurations, pod escape, privilege escalation, service account abuse.
tech-memcached
Memcached security testing — unauthenticated access, cache poisoning, session hijacking, data extraction, DDoS amplification, memcached stats enumeration.
tech-mongodb
MongoDB security testing — unauthenticated access, collection enumeration, NoSQL injection, data exfiltration, MongoDB bind IP misconfiguration.
tech-nginx-apache
Nginx and Apache security testing — path traversal via alias misconfiguration, .htaccess bypass, Apache mod_status, nginx off-by-slash, server-side includes, HTTP methods abuse, server info disclosure.
tech-observability
Observability platform security testing — Grafana default credentials, Prometheus metrics exposure, Jaeger unauth access, Zipkin, alertmanager webhook abuse, metric exfiltration.
tech-qemu-emulation
QEMU cross-architecture emulation for firmware analysis and exploit testing. ARM/MIPS/RISC-V binary execution, GDB debugging cross-arch, firmware extraction with binwalk, chroot emulation, IoT service testing, cross-compile exploitation.
tech-redis
Redis security testing — unauthenticated access, AUTH brute force, config write for cron/SSH injection, Lua RCE, Redis module exploitation.
tech-stack-fingerprint
Technology stack fingerprinting for security assessment. httpx-based technology detection with status codes and server banners, HTTP response header analysis (Server, X-Powered-By, Set-Cookie tech reveals), WhatWeb aggressive detection, Nuclei tech-detect templates, WordPress/Drupal/Joomla/framework
tech-supabase
Supabase security testing — anon key abuse, Row Level Security bypass, PostgREST direct access, service_role key exposure, real-time subscription abuse.
tech-tomcat
Apache Tomcat security testing — manager app default creds, WAR deployment RCE, CVE exploitation (Ghostcat, CVE-2019-0232), AJP connector abuse, session fixation.
tool-advanced-fuzzing
Advanced web fuzzing techniques — ffuf, feroxbuster, custom wordlists, virtual host fuzzing, API endpoint fuzzing, parameter fuzzing, HTTP method fuzzing, header fuzzing.
tool-browser-automation
Browser automation for pentesting — Playwright/Puppeteer for authenticated crawling, form submission, SPA spider, JavaScript rendering, DOM XSS detection, screenshot proof collection.
tool-caido
Caido web security proxy — intercepting proxy, replay, automate, workflow rules, filter, match/replace, HTTPQL querying, Caido Automate for fuzzing.
tool-dalfox
Dalfox XSS scanner — parameter discovery, DOM XSS, blind XSS, WAF bypass, pipe mode, custom payloads, Burp integration.
tool-hashcat-john
Password cracking with Hashcat and John the Ripper — hash identification, wordlist attacks, rule-based attacks, hybrid attacks, rainbow tables, mask attacks.
tool-impacket
Impacket toolkit — psexec, wmiexec, smbexec, secretsdump, GetUserSPNs, GetNPUsers, NTLM relay, SMB client, DCSync, pass-the-hash, Kerberos ticket.
tool-metasploit
Metasploit Framework usage — module search, exploit execution, payload generation, post-exploitation, meterpreter, auxiliary modules, MSFvenom.
tool-nmap
Nmap comprehensive usage — SYN scan, service detection, script scanning, OS fingerprinting, aggressive scan, CVE detection, UDP scan, output formats.
tool-nuclei
Nuclei template-based vulnerability scanner — community templates, custom templates, CVE scanning, severity filtering, bulk scanning, rate limiting, report output.
tool-scripting
Pentest scripting techniques — bash one-liners, Python exploit scripts, curl chaining, Burp Extender automation, jq parsing, grep pattern extraction for pentest workflows.
tool-semgrep
Semgrep static analysis for security — SAST rules, custom rules, secret detection, code pattern matching, OWASP Top 10 detection, CI/CD integration.
tool-source-audit
Manual source code security audit — PHP/Python/Node/Java code review, dangerous function patterns, file inclusion vulnerabilities, SQL injection in ORM, authentication logic flaws.
tool-sqlmap
SQLMap usage guide — detection mode, database enumeration, data extraction, file read/write, OS shell, WAF bypass, tamper scripts, custom payloads.
tool-wapiti
Wapiti web vulnerability scanner — SQL injection, XSS, SSRF, file disclosure, command injection, CRLF, open redirect scanning with HTML report.
vuln-2fa-bypass
Two-factor authentication bypass testing — OTP brute force, response manipulation, backup code abuse, step skip, CSRF on 2FA disable, SIM swap indicators, OAuth to bypass 2FA, cookie theft to bypass 2FA.
vuln-account-takeover
Account takeover (ATO) testing — password reset flaws, OAuth misconfig, session fixation, CSRF chain to ATO, XSS cookie theft, IDOR-based ATO, credential stuffing, email change without verification.
vuln-api-schema-exposure
API schema exposure testing — OpenAPI/Swagger discovery, GraphQL introspection, WSDL exposure, gRPC reflection, API documentation endpoints.
vuln-api-testing
REST API security testing — endpoint discovery, authentication testing, rate limiting bypass, versioning attacks, excessive data exposure, API security top 10.
vuln-auth-workflow
Authentication workflow testing — login bypass, session management flaws, insecure remember-me, concurrent session handling, account lockout bypass, credential stuffing.
vuln-bfla
Broken Function Level Authorization (BFLA) testing — accessing admin functions as regular user, HTTP method override, hidden admin endpoints, privilege escalation via API versioning.
vuln-blind-xss
Blind XSS (out-of-band XSS) testing. Stored XSS in admin panels, log viewers, moderation queues. interactsh callback setup, injection point mapping, payload delivery via forms/headers/file metadata.
vuln-business-logic
Business logic vulnerability testing. Tests workflow bypass, price manipulation, refund abuse, quota bypass, and state machine attacks.
vuln-cache-deception
Web cache deception testing. CDN caching of authenticated content via extension tricks, path manipulation, URL encoding. Cache behavior analysis, sensitive endpoint discovery.
vuln-clickjacking
Clickjacking (UI redressing) vulnerability testing. X-Frame-Options check, CSP frame-ancestors bypass, PoC iframe creation, drag-and-drop variant, multi-step clickjacking.
vuln-cors
CORS misconfiguration testing skill. Tests origin reflection, null origin, subdomain trust chains, and credential-bearing cross-origin requests.
vuln-crlf
CRLF injection testing — HTTP header injection, response splitting, cookie injection, XSS via CRLF, log injection, redirect via CRLF.
vuln-csrf
CSRF (Cross-Site Request Forgery) testing — token bypass, SameSite bypass, Referer-only validation bypass, JSON CSRF, multipart CSRF, cross-origin state change.
vuln-csrf-advanced
Advanced CSRF bypass — SameSite cookie bypass via navigation, click-jacking chain, CSRF via Flash redirect, subdomain CSRF bypass, sibling domain CSRF, browser-based CSRF bypass via service worker.
vuln-deserialization
Insecure deserialization testing — Java (ysoserial gadget chains), PHP object injection, Python pickle RCE, Ruby Marshal injection, .NET BinaryFormatter, Jackson/XStream, node-serialize.
vuln-dom-xss
DOM-based XSS and client-side vulnerabilities. Source-to-sink analysis, postMessage origin bypass, open redirect via DOM, eval/innerHTML sinks, DOM clobbering.
vuln-exploit-validation
Exploit and vulnerability validation methodology. Safe reproduction with minimal payload, baseline request capture, controlled impact demonstration without destructive actions, fix verification after remediation, evidence collection for report. Triage preconditions, auth requirements, input vectors.
vuln-file-upload
File upload vulnerability testing — extension bypass, MIME type bypass, magic bytes bypass, double extension, null byte, polyglot files, webshell upload, path traversal via filename.
vuln-grpc
gRPC security testing — service enumeration via reflection, proto file analysis, injection via gRPC methods, authentication bypass, plaintext gRPC interception.
vuln-host-header
Host header injection testing — password reset poisoning, cache poisoning via Host, SSRF via Host header, routing bypass, virtual host confusion, port-based bypass.
vuln-http-smuggling
HTTP request smuggling testing skill. Tests CL.TE, TE.CL, TE.TE, H2.CL, H2.TE desync vulnerabilities.
vuln-idor
IDOR/BOLA (Insecure Direct Object Reference / Broken Object Level Authorization) testing skill. Tests horizontal/vertical access control across REST, GraphQL, WebSocket, and gRPC.
vuln-info-disclosure
Information disclosure testing — error message leakage, debug endpoints, stack traces, API schema exposure, backup files, git repositories, environment variables exposure, directory listing.
vuln-interactsh-oob
Out-of-band vulnerability detection with Interactsh. Blind SSRF via URL/header injection, blind XXE with external entity and parameter entity OOB data exfiltration, blind SQL injection via MySQL/MSSQL/PostgreSQL/Oracle OOB channels, blind SSTI via Jinja2/Twig/FreeMarker with curl callback, blind com
vuln-jwt
JWT vulnerability exploitation. Algorithm confusion (alg:none, RS256→HS256), weak secret cracking, kid injection, JWK header injection, claim manipulation.
vuln-llm-attacks
LLM application security testing. Direct prompt injection, indirect RAG injection, tool abuse, output injection (XSS via markdown), pipeline mapping, system prompt extraction.
vuln-log4shell
Log4Shell (CVE-2021-44228) detection and exploitation. JNDI injection, WAF bypass obfuscation, interactsh OOB detection, marshalsec LDAP exploit server, ysoserial gadget chains.
vuln-mass-assignment
Mass assignment vulnerability testing — injecting extra parameters to elevate privileges, bypass access control, assign roles/admin flags via API body.
vuln-nosql
NoSQL injection testing — MongoDB operator injection ($ne/$gt/$where), authentication bypass, blind NoSQL injection, MongoDB aggregation abuse, Redis command injection.
vuln-oauth
OAuth 2.0 and OpenID Connect misconfiguration testing. Open redirect ATO, state CSRF bypass, authorization code leakage and reuse, token audience confusion, PKCE bypass, scope escalation, implicit flow abuse.
vuln-open-redirect
Open redirect testing — parameter-based redirect bypass, host header redirect, subdomain bypass, URL scheme bypass, phishing chain, OAuth redirect_uri abuse.
vuln-password-reset-poisoning
Password reset poisoning via Host header injection and redirect parameter manipulation. Causes reset emails with attacker-controlled URLs.
vuln-path-traversal
Path traversal / directory traversal / LFI testing — ../../../etc/passwd, URL encoding bypass, null byte bypass, filter bypass with encoding, absolute path injection, path normalization bypass.
vuln-privesc-web
Web application privilege escalation testing — horizontal to vertical escalation, parameter tampering for role bypass, JWT privilege escalation, cookie manipulation, admin panel access via role confusion.
vuln-prototype-pollution
Prototype pollution testing skill. Tests client-side (DOM XSS gadgets) and server-side (Node.js RCE, auth bypass) via Object.prototype injection.
vuln-race-conditions
Race condition testing skill for concurrent request vulnerabilities. Tests TOCTOU, double-spend, coupon abuse, quota bypass using HTTP/2 tight synchronization.
vuln-rce
Remote Code Execution testing skill. Tests command injection, template injection RCE, deserialization RCE, SSRF-to-RCE chains, and container escape vectors.
vuln-sensitive-exposure
Sensitive data and PII exposure testing — credentials in responses, API key leakage, PII in logs/responses, unencrypted sensitive data, EXIF data, S3 bucket exposure, cloud storage misconfig.
vuln-spring4shell
Spring4Shell (CVE-2022-22965) detection and exploitation. JSP webshell via classloader pattern, nuclei detection, Spring/Tomcat fingerprinting, WAR deployment RCE.
vuln-sqli
SQL injection testing skill. Comprehensive SQLi methodology: parameter discovery, manual probing, error/boolean/time-based/union/OOB techniques, DBMS-specific payloads, and WAF bypass.
vuln-ssrf
Server-Side Request Forgery (SSRF) testing — cloud metadata exfiltration, internal service pivoting, blind SSRF via OOB callbacks, protocol abuse (Gopher/dict/file), DNS rebinding, SSRF filter bypass.
vuln-ssti
Server-Side Template Injection (SSTI) testing — Jinja2/Twig/Freemarker/Velocity/Pebble/Smarty/ERB/Mako detection, template expression probing, RCE via SSTI, sandbox escape.
vuln-subdomain-takeover
Subdomain takeover testing — dangling CNAME detection, cloud service fingerprinting, GitHub Pages takeover, S3 bucket takeover, Heroku/Netlify/Vercel claim, NS takeover.
vuln-supply-chain
Supply chain security testing — dependency confusion, typosquatting, npm/PyPI package hijacking, malicious dependency injection, CI/CD pipeline attacks, GitHub Actions poisoning.
vuln-waf-bypass
WAF detection and bypass techniques — WAF fingerprinting, encoding bypass, case manipulation, header smuggling past WAF, chunked encoding, parameter pollution, Unicode normalization bypass.
vuln-websocket
WebSocket security testing — cross-site WebSocket hijacking (CSWSH), message injection, authentication bypass, SQL/NoSQL/command injection via WebSocket messages, privilege escalation via WebSocket.
vuln-xs-leaks
XS-Leaks (cross-site leak) vulnerability testing. Timing attacks, resource event inference, redirect chain leaks, browser side channels, history.length leaks, frame counting.
vuln-xss
Reflected and Stored XSS testing — injection point discovery, context-aware payload crafting, WAF bypass, stored XSS via API, CSP bypass, cookie theft, keylogging, BeEF hooking.
vuln-xxe
XML External Entity (XXE) injection testing — local file read, SSRF via XXE, blind OOB XXE via DNS/HTTP callbacks, parameter entity XXE, DTD-based exfiltration, XXE via SVG/DOCX/XLSX.
work-with-pr
Full pentest finding submission lifecycle in an isolated engagement workspace: implement via the pentest-loop skill with mandatory evidence-bound manual QA → detailed English PR → verification loop (validation + review-work reviewers + Cubic, where Cubic is skipped only when its quota is exhausted)
work-with-pr-workspace
Git workflow skill for working with pull requests in isolated worktrees — branch creation, implementation, QA evidence, PR creation via gh CLI.