GITEST

Playbooks

Browse 249 playbooks across every security domain

Active Directory

ad-attacks

Active Directory credential attacks. Kerberoasting, AS-REP roasting, DCSync, Pass-the-Hash, Pass-the-Ticket, Silver Ticket, Golden Ticket, NTLM relay. Via Impacket + netexec (no Windows required).

Active Directory

ad-netexec

NetExec (CrackMapExec) complete workflow. SMB/WinRM/LDAP/MSSQL enumeration, credential spraying, code execution, credential dumping, lateral movement.

Blue Team

blue-detect

Blue team detection skill. WAF detection, IDS/IPS identification, log analysis, and malware detection. Use for defensive operations and incident detection.

Blue Team

blue-forensics

Blue team forensics skill. Memory forensics, disk analysis, timeline reconstruction, and evidence preservation. Use for deep forensic analysis and evidence collection.

Blue Team

blue-ir

Blue team incident response skill. Incident triage, timeline analysis, containment, and eradication. Use for incident response operations and breach investigation.

Blue Team

blue-report

Blue team reporting skill. Incident response reports, IOC documentation, and executive summaries. Use for blue team reporting and documentation.

Other

codex-qa

QA the gitest Codex Light edition (lazycodex / GiScan/codex) itself, in strict isolation so ONLY our plugin is exercised, never the user's real ~/.codex. The first-party method drives the real `codex app-server` against an isolated CODEX_HOME plus a LOCAL mock model (no real API call), and proves a

CTF

ctf-android

CTF Android challenge analysis. APK static analysis with Jadx and APKTool, smali disassembly for flag validation logic, native library JNI reverse engineering with Radare2, ADB dynamic analysis with exported activity launch and content provider query, Frida dynamic instrumentation for method hooking

CTF

ctf-crypto

CTF cryptography skill. Hash cracking, encoding/decoding, RSA/AES challenges, and crypto analysis. Use for crypto challenges and hash identification.

CTF

ctf-crypto-advanced-math

CTF advanced math crypto. LLL lattice attacks, Coppersmith method, Pohlig-Hellman on smooth curves, isogeny graph traversal, quaternion RSA factoring, LWE via CVP, Manger padding oracle, non-permutation S-box collision, polynomial CRT in GF(2).

CTF

ctf-crypto-classic

CTF classic cipher attacks. Vigenere key recovery, Kasiski examination, XOR frequency analysis, multi-byte XOR key recovery, OTP key reuse (many-time pad), cascade XOR, book cipher, homophonic substitution.

CTF

ctf-crypto-ecc

CTF ECC attacks. Smart's attack on anomalous curves, Pohlig-Hellman, ECDSA nonce reuse, invalid curve, singular curves, Ed25519 torsion side channel, clock group DLP.

CTF

ctf-crypto-exotic

CTF exotic cryptography attacks. Braid group Diffie-Hellman Alexander polynomial multiplicativity attack, tropical semiring cryptography residuation-based key recovery, Paillier homomorphic encryption oracle binary search, Hamming code linear algebra brute-force, ElGamal multiplicative re-encryption

CTF

ctf-crypto-historical

CTF historical cipher attacks. Lorenz SZ40/42 (Tunny) delta attack with known plaintext, ITA2/Baudot encoding, book cipher brute force.

CTF

ctf-crypto-modern

CTF modern cipher attacks. AES padding oracle, CBC bitflipping, ECB image oracle, AES-CFB-8 IV state forging, GCM key recovery, LFSR attacks, hash length extension, CRIME compression oracle, CBC-MAC forgery.

CTF

ctf-crypto-prng

CTF PRNG attacks. Mersenne Twister state recovery, time-seeded PRNG brute force, LCG parameter recovery, V8 Math.random XorShift128+ Z3 solver, GF(2) matrix approach.

CTF

ctf-crypto-rsa

CTF RSA cryptography attacks. Small exponent cube root, common modulus, Wiener attack, Pollard p-1, Hastad broadcast, Fermat factorization, batch GCD, Manger padding oracle, p=q bypass, gcd(e,phi)>1, signature forgery.

CTF

ctf-crypto-zkp

CTF zero-knowledge proof and advanced cryptography attacks. Groth16 broken trusted setup delta==gamma forgery, Groth16 replay with unconstrained nullifier, DV-SNARG forgery via verifier oracle, KZG pairing oracle for permutation recovery, FROST lattice threshold signature attack, MAYO post-quantum f

CTF

ctf-exploit

CTF exploitation skill. Binary exploitation, web exploitation, crypto challenges, and privilege escalation. Use for CTF pwn, web, and misc challenges.

CTF

ctf-forensics

CTF forensics skill. Memory forensics, disk analysis, steganography, and file recovery. Use for forensic challenges and incident response.

CTF

ctf-forensics-3d-printing

CTF 3D printing and G-code forensics. PrusaSlicer binary G-code (bgcode/GCDE) parsing, heatshrink decompression, G-code coordinate visualization for hidden patterns, QOIF image format extraction, uncommon file format identification.

CTF

ctf-forensics-disk

CTF disk and memory forensics. Volatility 3 memory analysis, Sleuth Kit disk imaging, deleted file recovery, VMware snapshot analysis, ZFS forensics, RAID 5 recovery, Docker layer analysis, APFS snapshots, MFT analysis.

CTF

ctf-forensics-disk-memory

CTF disk and memory forensics. Volatility 3 process/network/MFT analysis, disk imaging with Sleuth Kit icat, VM forensics OVA/VMDK via 7z, vmss2core snapshot conversion, ransomware AES key oracle, RAID 5 XOR recovery, APFS/ZFS snapshot reversion, WordPerfect macro brute, Docker layer secrets, PowerS

CTF

ctf-forensics-disk-recovery

CTF disk forensics. LUKS master key recovery from memory, PRNG timestamp seed brute force, VBA macro encoded binary extraction, FemtoZip shared dictionary, XFS inode reconstruction, tar duplicate entry extraction, nested matryoshka filesystem, anti-carving null byte interleaving.

CTF

ctf-forensics-linux

CTF Linux and application forensics. Log analysis, Docker image layer inspection, browser credential decryption (Chrome/Firefox), KeePass cracking, git reflog orphan recovery, USB audio extraction, TLS decryption via weak RSA, TFTP netascii decode.

CTF

ctf-forensics-network

CTF network forensics. Wireshark/tshark PCAP analysis, TLS decryption with SSLKEYLOGFILE/RSA key, HTTP object extraction, USB HID decode, SMB3 decryption, TCP stream reconstruction, BCD encoding.

CTF

ctf-forensics-network-advanced

CTF advanced network forensics. Timing-based packet encoding, USB HID mouse/pen drawing recovery, DNS exfiltration via query names, TCP flag base64 covert channel, ICMP steganography, Active Directory RID recycling, Timeroasting NTP hash, decompression anomaly detection.

CTF

ctf-forensics-signals

CTF signals and hardware forensics. VGA binary signal decoding (800x525 total frame, 640x480 active, 5-byte samples), HDMI TMDS 10-bit symbol decode, DisplayPort 8b/10b LFSR descrambling, Voyager golden record audio sync pulse image extraction, side-channel power analysis DPA with variance-based lea

CTF

ctf-forensics-stego

CTF steganography forensics. LSB extraction, PNG/JPEG/BMP format tricks, PDF hidden layers, SVG animation, steghide, zsteg, stegsolve, bitplane analysis, QR codes hidden in images.

CTF

ctf-forensics-stego-advanced

CTF advanced steganography. FFT frequency domain image stego, SSTV decoding, DotCode barcode, DTMF custom frequency keypad, multi-track audio differential subtraction, cross-channel multi-bit LSB, video frame accumulation, audio waveform binary, spectrogram QR code, whitespace encoding in tar archiv

CTF

ctf-forensics-windows

CTF Windows forensics. Event log parsing (evtx), registry analysis, SAM hash extraction, MFT/USN journal analysis, wmiexec.py artifact detection, PowerShell history timeline, RDP event IDs, Windows Defender MPLog, anti-forensics detection.

CTF

ctf-heap-advanced

CTF advanced heap exploitation for modern glibc (2.27–2.35+). Tcache poisoning, tcache dup double-free, tcache key bypass, fastbin dup into stack, fastbin into __malloc_hook, unsorted bin libc leak, largebin attack arbitrary write, House of Force top-chunk overflow, House of Botcake overlapping chun

CTF

ctf-malware-analysis

CTF malware analysis. PE file analysis, .NET decompilation (dnSpy/ILSpy), C2 configuration extraction, PyInstaller unpacking, PyArmor bypass, sandbox evasion detection, LimeRAT C2 decryption.

CTF

ctf-malware-c2-protocols

CTF malware C2 traffic analysis. PCAP tshark protocol extraction, stream cipher shared keystream (ChaCha20 null-byte trick), RC4 WebSocket C2 decryption, AES-CBC key derivation from hardcoded strings, encryption algorithm identification by constants (AES S-box 0x637c777b, ChaCha20 'expand 32-byte k'

CTF

ctf-malware-pe-dotnet

CTF PE and .NET malware analysis. PE static triage with peframe/pestudio, sandbox evasion detection (VM artifacts, debugger checks, timing), .NET assembly analysis with dnSpy/ILSpy, LimeRAT C2 extraction via AES-256-ECB with MD5 key derivation, PyInstaller extraction with pyinstxtractor, PyArmor unp

CTF

ctf-malware-scripts

CTF malware script and obfuscation analysis. JavaScript eval deobfuscation, PowerShell -EncodedCommand base64 decode, junk code detection (NOP sleds, dead writes), hex-encoded payload XOR transforms, Debian package postinst analysis, dynamic behavioral analysis with strace/ltrace/tcpdump, YARA rule

CTF

ctf-misc-bashjails

CTF Bash jail escape techniques. Restricted shell bypass, character whitelist bypass, HashCashSlash trick, /proc/cmdline enumeration, /dev/tcp reverse shell, SUID escalation, glob expansion bypass.

CTF

ctf-misc-dns

CTF DNS exploitation. EDNS Client Subnet spoofing for geo-specific responses, DNSSEC NSEC zone walking, IXFR incremental zone transfer for deleted records, DNS rebinding, DNS tunneling detection in PCAP, custom DNS server with dnslib.

CTF

ctf-misc-encodings

CTF encoding challenges. Base64/32/hex decode, IEEE 754 float-as-text, UTF-16 mojibake fix, BCD decode, QR code repair, esoteric languages (Whitespace, Brainfuck, Piet), SMS PDU reassembly, Gray code, RTF hidden data, multi-layer cascade decoder.

CTF

ctf-misc-games-vms

CTF misc games and VMs. WASM game AI weakening via wasm2wat patching, Roblox version history binary format parsing, PyInstaller extraction with opcode remapping, Python marshal code analysis, Python environment RCE via PYTHONWARNINGS, Z3 constraint solving for custom VMs, YARA rules with Z3, Kuberne

CTF

ctf-misc-games-vms-2

CTF misc challenges part 2. ML model weight perturbation and LoRA adapter attacks, Flask session secret brute-force and decode, WebSocket coordinate/state manipulation, De Bruijn sequence generation for format string or offset discovery, Brainfuck/esoteric VM instrumentation and tracing, WASM linear

CTF

ctf-misc-pyjails

CTF Python jail escape techniques. Class hierarchy traversal, compile bypass, unicode bypass, decorator-based escape, walrus operator, octal escapes, oracle-based challenges, mastermind-style, restricted charset, quine+context detection, func_globals chain.

CTF

ctf-misc-rf-sdr

CTF RF/SDR signal processing. IQ file formats (cf32/cs16/cu8), spectrum analysis, QAM-16 demodulation with carrier and timing recovery, cyclostationary analysis for symbol rate, Mueller-Muller timing, GNU Radio integration.

CTF

ctf-osint-geolocation

CTF OSINT geolocation and media analysis. Reverse image search (Google Lens crop, Yandex for faces, Baidu for China), MGRS military grid coordinate conversion, Google Plus Codes (XXXX+XX format), metadata extraction with exiftool, VGA signal analysis, Google Street View panorama matching with ORB fe

CTF

ctf-osint-social

CTF OSINT social media investigation. Twitter/X persistent IDs, Tumblr header fingerprinting, BlueSky API, Unicode homoglyph steganography, Discord metadata, Strava GPS exposure, multi-platform username enumeration.

CTF

ctf-osint-web

CTF OSINT web and DNS investigation. Google dorking, DNS TXT/zone transfer, WHOIS, Wayback Machine CDX API, certificate transparency, OSINT framework.

CTF

ctf-pwn-advanced-exploits

CTF advanced exploitation. VM signed comparison bugs, BF JIT RWX shellcode, type confusion in interpreters, off-by-one index to size corruption, ASAN shadow memory exploitation, format string with encoding constraints, .fini_array hijack, VM GC-triggered UAF slab reuse, FSOP seccomp bypass, integer

CTF

ctf-pwn-advanced-exploits-2

CTF advanced exploitation part 2. io_uring UAF SQE injection, GF(2) Gaussian elimination for tcache poisoning, signed/unsigned char underflow heap overflow, TLS destructor hijack via pointer guard forgery, custom shadow stack bypass via pointer overflow, XSS-to-binary pwn bridge with newline injecti

CTF

ctf-pwn-basics

CTF binary exploitation basics. Stack buffer overflow, ret2win, stack alignment, offset calculation, cyclic pattern, struct pointer overwrite, signed integer bypass, canary brute-force on forking servers, OOB read via stride.

CTF

ctf-pwn-format-string

CTF format string exploitation. GOT overwrite via %n, canary/PIE leak, argument retargeting, blind pwn, free_hook overwrite, argv[0] stack smash info leak, format string game state manipulation.

CTF

ctf-pwn-heap

CTF heap exploitation. House of Apple 2 (FSOP), House of Einherjar, tcache poisoning, seccomp bypass, ret2dlresolve, musl libc attacks, setcontext pivot, tcache stashing unlink.

CTF

ctf-pwn-kernel

CTF Linux kernel exploitation. QEMU debugging setup, KASLR/FGKASLR bypass, kernel heap spray (tty_struct, poll_list), stack overflow, ret2usr, kernel ROP, prepare_kernel_cred/commit_creds, modprobe_path overwrite, iretq restoration.

CTF

ctf-pwn-kernel-bypass

CTF kernel protection bypass techniques. KASLR bypass via stack leak, FGKASLR bypass using stable .text gadgets and __ksymtab relative offset resolution, KPTI bypass via swapgs_restore trampoline (+22 offset), SIGSEGV handler, modprobe_path ROP, core_pattern overwrite, SMEP/SMAP bypass with kernel R

CTF

ctf-pwn-kernel-techniques

CTF kernel exploitation advanced techniques. tty_struct RIP hijack via fake vtable with leave gadget stack pivot, AAW via ioctl register control for modprobe_path overwrite, userfaultfd race stabilization with page split across boundary, SLUB freelist pointer hardening (middle offset kernel 5.7+), f

CTF

ctf-pwn-rop

CTF binary exploitation ROP chains and shellcode. ret2libc, ret2csu, raw syscall ROP, rdx control, stack pivot, bad character bypass via XOR, exotic gadgets (BEXTR/XLAT/STOSB), sprintf gadget chaining.

CTF

ctf-pwn-rop-advanced

CTF advanced ROP techniques. Double stack pivot via leave/ret, SROP with UTF-8 constraints, architecture switching via RETF to bypass seccomp, vDSO gadget harvesting, vsyscall fixed addresses, .fini_array hijack, seccomp alternative syscalls.

CTF

ctf-pwn-sandbox

CTF sandbox escape. Python jail escape, custom bytecode VM exploitation, FUSE/CUSE character device exploitation, busybox restricted shell, /proc/self/mem write-anywhere, shell fd redirection tricks.

CTF

ctf-recon

CTF reconnaissance skill. Fast OSINT, flag format detection, challenge identification. Use for CTF challenges, binary analysis, and crypto challenges.

CTF

ctf-reverse-anti-analysis

CTF anti-analysis bypass. Linux anti-debug (ptrace, /proc, timing, SIGILL), Windows anti-debug (PEB, NtQuery, TLS callbacks, hardware BP detection), anti-VM/sandbox detection, Frida detection bypass, code integrity bypass, anti-disassembly, MBA simplification.

CTF

ctf-reverse-dynamic

CTF dynamic analysis tools. Frida hooking, angr symbolic execution, lldb, x64dbg, Qiling cross-platform emulation, Intel Pin instruction counting side channel.

CTF

ctf-reverse-languages

CTF reverse engineering by language. Python bytecode (dis, PyInstaller, Pyarmor), Ruby/Perl polyglot, OPAL functional, UEFI VM bytecode, Unity IL2CPP, Roblox asset versioning, Godot KeyDot, HarmonyOS ABC, Electron ASAR, Rust serde_json, Node.js runtime introspection.

CTF

ctf-reverse-patterns

CTF reverse engineering patterns. Custom VM analysis, anti-debug bypass, XOR known-plaintext, control flow flattening, mixed-mode execution, signal-based obfuscation, S-box/keystream identification.

CTF

ctf-reverse-patterns-ctf

CTF-specific reverse engineering patterns. Hidden opcode crypto key capture, image XOR mask via smoothness, RC4 parameter extraction, Z3 VM constraint solving, Sprague-Grundy Nim strategy, block cipher zero diffusion, meet-in-middle hash inversion, kernel ioctl maze, recursive process counter, RWX s

CTF

ctf-reverse-patterns-ctf-2

CTF reverse engineering competition patterns part 2. Multi-layer self-decrypting binary with JIT fork execution, embedded ZIP XOR license decryption, .rodata XOR blob deobfuscation, prefix hash brute-force, CVP/LLL lattice for constrained ASCII validation, decision tree function obfuscation via Ghid

CTF

ctf-reverse-platforms

CTF reverse engineering by platform. macOS Mach-O analysis, iOS class-dump, IoT/embedded firmware (ARM/MIPS), Linux kernel modules, eBPF programs, game engines (Unreal .pak, Unity C#), automotive CAN/UDS, RISC-V custom extensions, HD44780 LCD reconstruction.

CTF

ctf-reverse-tools

CTF reverse engineering tools. GDB/pwndbg, Radare2/Cutter, Ghidra, Binary Ninja, dogbolt.org multi-decompiler, Unicorn emulation, FLIRT signatures, angr symbolic execution.

CTF

ctf-reverse-tools-advanced

CTF advanced reverse engineering tooling. VMProtect devirtualization, Themida unpacking, BinDiff/Diaphora patch analysis, D-810 deobfuscation, GOOMBA Ghidra, Miasm IR lifting, Qiling emulation, Triton symbolic execution, rr reverse debugging, pwndbg/GEF, LIEF binary patching.

CTF

ctf-wasm

CTF WebAssembly challenge analysis. Initial recon with wasm-objdump, WAT decompilation with wasm2wat, wasm-decompile pseudo-code, wasm2c native compilation for ltrace/GDB analysis, wasmtime/wasmer execution, WASM linear memory dump and string extraction, binary patching via WAT edit then wat2wasm, X

CTF

ctf-web-auth-access

CTF web auth and access control. Structured ID as password, weak MAC forgery, HAProxy URL encoding bypass, Express %2F route bypass, NoSQL boolean injection, LLM chatbot secret leak, affine cipher OTP brute, IDOR with zero UUID.

CTF

ctf-web-auth-infra

CTF web infrastructure authentication attacks. OAuth open redirect token theft, OIDC alg-none manipulation, OAuth state CSRF, CORS reflected origin exploitation, git history credential leakage, CI/CD variable credential theft, identity provider API takeover (authentik/Keycloak), SAML SSO flow automa

CTF

ctf-web-client-side

CTF client-side web attacks. XSS filter bypass, DOMPurify bypass via backend trust, DOM XSS jQuery hashchange, shadow DOM exfiltration, JPEG+HTML polyglot, image timing oracle, CSS text exfiltration without JS, Alpine.js/Hyperscript attribute execution.

CTF

ctf-web-cves

CTF web CVE exploitation. Next.js middleware bypass, PaperCut admin bypass, Ruby-SAML forgery, Uvicorn CRLF injection, ExifTool DjVu RCE, WeasyPrint SSRF, Zabbix SQL injection, React Server Components RCE, prototype pollution.

CTF

ctf-web-node-prototype

CTF Node.js prototype pollution and VM escape. flatnest CVE-2023-26135, lodash merge pollution, Pug AST injection, Happy-DOM VM escape, full pollution-to-RCE chains.

CTF

ctf-web-server-deser

CTF web server-side deserialization and execution attacks. Java deserialization with ysoserial gadget chains (CommonsCollections, Spring, URLDNS), Python pickle deserialization RCE via __reduce__, race condition TOCTOU balance bypass, VolgaCTF pickle chaining via STOP opcode stripping with os.dup2 s

CTF

ctf-web-server-exec

CTF web server code execution challenges — PHP webshell, eval bypass, command injection CTF, RCE via deserialization, sandbox escape.

CTF

ctf-web-server-side

CTF web server-side injection attacks. PHP type juggling, LFI/php://filter, SQL injection (backslash escape, hex, second-order, LIKE brute-force, column truncation, SQLi-to-SSTI), SSTI (Jinja2, Go, EJS, ERB, Mako, Twig), SSRF, XXE, command injection, Host Header SSRF, DNS rebinding.

CTF

ctf-web-server-side-advanced

CTF advanced server-side web exploitation. ExifTool DjVu ANTa eval injection, Go rune/byte mismatch UTF-8 length bypass, ZIP symlink traversal for file read, React Server Components Flight protocol RCE via constructor chain, Castor XML xsi:type polymorphism to JNDI/RMI, Nginx URL-encoded slash path

CTF

ctf-web-web3

CTF Web3/blockchain challenges. EIP-1967 proxy exploitation, ABI coder v1 dirty address bypass, Groth16 proof forgery, delegatecall storage abuse, Solidity transient storage bug, phantom market manipulation, Foundry/cast tools.

Forensics

forensic-disk

Disk forensics skill. File carving, file system analysis, deleted file recovery, timeline reconstruction, and artifact extraction from disk images. Tools: autopsy, foremost, bulk_extractor, binwalk, exiftool.

Forensics

forensic-memory

Memory forensics skill. Acquires and analyzes RAM dumps using volatility3. Extracts process lists, network connections, injected code, encryption keys, and malware artifacts.

Forensics

forensic-network

Network forensics skill. PCAP analysis, traffic reconstruction, C2 detection, credential extraction, and protocol analysis using tshark, tcpdump, and wireshark.

Forensics

forensic-report

Forensic report generation skill. Compiles memory, disk, and network findings into a chain-of-custody IR report. Includes IOC list, timeline, evidence inventory, and remediation roadmap.

Frameworks

framework-django

Django framework security testing — admin panel exposure, DEBUG mode RCE, CSRF bypass, secret key extraction, SSTI via templates, SQL via ORM raw queries.

Frameworks

framework-dotnet

ASP.NET/Core security testing — ViewState deserialization, TRACE method info leak, Razor SSTI, Windows auth bypass, IIS misconfiguration, web.config exposure, machineKey extraction.

Frameworks

framework-express

Express.js/Node.js security testing — prototype pollution, CORS misconfiguration, middleware bypass, npm dependency vulns, JWT abuse, path traversal via static serving, eval injection.

Frameworks

framework-fastapi

FastAPI security testing — OpenAPI schema exposure, auth dependency bypass, SSRF via request parameters, dependency injection abuse, pydantic bypass, debug endpoints.

Frameworks

framework-flask

Flask security testing — Werkzeug debug console RCE, secret key brute force, Jinja2 SSTI, session cookie forgery, PIN generation, unsafe redirects.

Frameworks

framework-laravel

Laravel security testing — .env file exposure, debug mode info leak, mass assignment via Eloquent, Laravel Telescope exposure, queue deserialization, CSRF bypass, route listing.

Frameworks

framework-nextjs

Next.js security testing — API route exposure, getServerSideProps SSRF, build output disclosure, middleware bypass, next.config.js misconfig, rewrites abuse, image proxy SSRF.

Frameworks

framework-php

PHP security testing — LFI/RFI, file upload bypass, eval injection, type juggling loose comparison, phpinfo disclosure, PHP wrappers, log poisoning, deserialization via unserialize().

Frameworks

framework-rails

Ruby on Rails security testing — mass assignment via strong parameters bypass, YAML deserialization, SQL injection via ActiveRecord raw queries, debug routes, Rails secrets exposure, cookie tampering.

Frameworks

framework-spring

Spring/Spring Boot security testing — actuator endpoint exposure (/actuator/env /actuator/heapdump), SpEL injection, Spring4Shell (CVE-2022-22965), Spring Security misconfig, H2 console, Eureka registry.

Frameworks

framework-wordpress

WordPress security testing — user enumeration, xmlrpc.php abuse, plugin/theme CVEs, REST API exposure, WP-JSON, admin upload RCE, credential brute force.

Other

get-unpublished-changes

Compare HEAD with the latest published npm versions and list all unpublished changes by release layer.

Other

github-triage

Read-only GitHub triage for issues AND PRs. . item = . background task (category: quick). Analyzes all open items and writes evidence-backed reports to /tmp/{datetime}/. Every claim requires a GitHub permalink as proof. NEVER takes any action on GitHub - no comments, no submits, no closes, no labels

Other

hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `pl

IoT

iot-firmware

IoT and embedded firmware security analysis. Firmware extraction, binwalk filesystem extraction, credential discovery, binary analysis, QEMU emulation, web interface testing.

Mobile

mobile-android

Android app security testing skill. APK decompilation, static analysis, sensitive data discovery, manifest analysis, and network traffic interception. Tools: apktool, jadx, adb, frida, mobsf.

Mobile

mobile-dynamic

Mobile dynamic testing skill. API security testing, traffic analysis, session management, authentication bypass, and business logic testing for mobile backend APIs.

Mobile

mobile-ios

iOS app security testing skill. IPA analysis, jailbreak detection bypass, SSL pinning bypass, Keychain inspection, runtime class introspection, and traffic interception using frida, objection, and MobSF.

Mobile

mobile-report

Mobile pentest report generation skill. Compiles Android/iOS static and dynamic findings into a structured security report with CVSS scores, PoCs, and OWASP Mobile Top 10 mapping.

Other

opencode-qa

QA opencode itself, per case: verify the CLI/terminal (opencode run, db, serve, export), prove a specific plugin hook/action/event fired via the SSE event stream, smoke-test the TUI under tmux, and investigate sessions in opencode's SQLite DB by id, title/name, or message text. Ships tested helper s

Payloads

payload-command-injection

Command injection payload collection and exploitation — pipe/semicolon/backtick/newline injection, blind OOB exfiltration, filter bypass encodings, WAF evasion, polyglot OS command injection.

Payloads

payload-csv-injection

CSV formula injection payloads. Excel/Google Sheets formula execution via exported CSV, HYPERLINK exfiltration, WEBSERVICE/IMPORTXML data exfil, bypass techniques.

Payloads

payload-http-param-pollution

HTTP Parameter Pollution (HPP) testing. Duplicate parameter injection, first-wins vs last-wins precedence, query/body override, JSON body conflict, path semicolon smuggling, validation bypass via arrays.

Payloads

payload-ldap-injection

LDAP injection payloads and testing. Filter breakout, authentication bypass, blind enumeration, attribute extraction.

Payloads

payload-lfi

LFI/path traversal payload collection — directory traversal sequences, null byte, URL encoding, double encoding, PHP wrappers, log poisoning for RCE.

Payloads

payload-redos

ReDoS (Regular Expression Denial of Service) testing. Nested quantifier detection, catastrophic backtracking payloads, email/URL/date validation bypass, input length scaling attack.

Payloads

payload-sqli

SQL injection payload collection — auth bypass, UNION select, blind boolean, time-based, stacked queries, OOB DNS exfiltration, DBMS-specific payloads (MySQL/PostgreSQL/MSSQL/SQLite/Oracle).

Payloads

payload-ssi-injection

Server-Side Include (SSI) injection payloads. Command execution via exec cmd, file inclusion, environment variable disclosure, printenv.

Payloads

payload-ssrf

SSRF payload collection — cloud metadata endpoints (AWS/GCP/Azure), internal port scan, protocol abuse (gopher/dict/file/sftp), bypass techniques (127.0.0.1 variants, IPv6, DNS rebinding, open redirect chains).

Payloads

payload-ssti

SSTI payload collection — Jinja2/Python, Twig/PHP, FreeMarker/Java, Velocity/Java, Smarty/PHP, Mako/Python, Handlebars/Node, ERB/Ruby template injection payloads for RCE.

Payloads

payload-xpath-injection

XPath injection payloads and testing. Authentication bypass, boolean-based blind extraction, XML node enumeration.

Payloads

payload-xss

XSS payload collection — reflected/stored/DOM, filter bypass, CSP bypass, polyglot, event handlers, SVG/HTML5, mXSS, blind XSS, cookie theft, keylogger payloads.

Payloads

payload-xxe

XXE payload collection — classic file read, OOB via DNS/HTTP callback, blind XXE, SVG XXE, XInclude, SSRF via XXE, error-based XXE, parameter entity abuse.

Pen Testing

pentest-enum

Pentest enumeration skill. Orchestrates nuclei, ffuf, gobuster, whatweb, and wafw00f for directory brute-forcing, vulnerability scanning, and technology fingerprinting. Use for web application enumeration and vuln discovery.

Pen Testing

pentest-exploit

Pentest exploitation skill. Orchestrates sqlmap, commix, hydra, hashcat, and john for SQL injection, command injection, credential attacks, and password cracking. Use for vulnerability exploitation and proof-of-concept generation.

Pen Testing

pentest-mode

Pentest mode selector skill. Selects engagement mode (Auto/CTF/Bug Bounty/Red Team/Blue Team/Offensive/Grey Hat) based on target or user preference. Configures tool priority, skill chain, loop config, and report format. Use before starting any pentest engagement.

Pen Testing

pentest-recon

Pentest reconnaissance skill. Orchestrates subfinder, httpx, naabu, and massdns for passive and active subdomain discovery, port scanning, and HTTP probing. Use for bug bounty recon, attack surface mapping, and subdomain enumeration.

Pen Testing

pentest-report

Pentest reporting skill. Compiles findings from all phases into a structured report with severity ratings, PoC, and remediation advice.

Pen Testing

pentest-workflow

Full pentest workflow orchestrator. Chains mode-specific skills (CTF/Bug Bounty/Red Team/Blue Team/Offensive/Grey Hat) for end-to-end security testing. Manages engagement state, enforces scope, and generates findings. Use after selecting mode with pentest-mode skill.

Post-Exploitation

post-bloodhound

BloodHound Active Directory attack path analysis. bloodhound-python collection, Neo4j Cypher queries, shortest path to DA, Kerberoastable accounts, ASREPRoastable, ACL edges, unconstrained delegation, session data.

Post-Exploitation

post-container-escape

Container escape and Docker breakout techniques. Privileged containers, Docker socket exploitation, cgroup v1 release agent, nsenter, CVE-based kernel escapes, Kubernetes pod escape.

Post-Exploitation

post-credential-dumping

Windows credential dumping post-exploitation. LSASS dump via procdump/nanodump/comsvcs, SAM/SYSTEM/SECURITY hive extraction, NTDS.dit dump via shadow copy, DCSync attack, LSA secrets, cached credentials, DPAPI, hash cracking, pass-the-hash.

Post-Exploitation

post-lateral-movement

Lateral movement skill for post-exploitation. Credential spraying, pass-the-hash, WMI/SMB/WinRM execution, SSH key pivoting, and internal network traversal.

Post-Exploitation

post-linux-privesc

Linux privilege escalation skill. Systematic enumeration and exploitation of sudo misconfigs, SUID binaries, writable cron jobs, capabilities, kernel exploits, and weak file permissions.

Post-Exploitation

post-pivoting

Network pivoting skill for post-exploitation — SSH tunneling, SOCKS proxy, chisel, ligolo-ng, socat port forwarding, double pivot, rpivot.

Post-Exploitation

post-windows-privesc

Windows privilege escalation skill. Token impersonation, unquoted service paths, weak service permissions, AlwaysInstallElevated, credential extraction, and scheduled task abuse.

Other

pre-submission-review

Nuclear-grade .6-agent pre-submission submission gate. Runs /get-unpublished-changes to detect all changes since last npm release, spawns up to .0 ultrabrain agents for deep per-change analysis, invokes /review-work (5 agents) for holistic review, and . oracle for overall release synthesis. Use befo

Protocols

proto-dns

DNS security testing — zone transfer, DNS cache poisoning, DNS amplification, subdomain enumeration via brute force, DNSSEC bypass, DNS rebinding.

Protocols

proto-ftp

FTP security testing — anonymous login, brute force, FTP bounce, PASV/PORT exploitation, clear-text sniffing, path traversal in FTP.

Protocols

proto-graphql

GraphQL security testing skill. Tests introspection, authorization bypasses, IDOR via aliases, batching abuse, path-level auth bypass, and federation exploitation.

Protocols

proto-kerberos

Kerberos security testing — Kerberoasting, AS-REP roasting, Pass-the-Ticket, Golden/Silver Ticket, SPN enumeration, unconstrained delegation, constrained delegation bypass.

Protocols

proto-ldap

LDAP security testing — anonymous bind, LDAP injection, user enumeration, attribute extraction, Kerberoasting prep, LDAP injection bypass.

Protocols

proto-mssql

Microsoft SQL Server (MSSQL) penetration testing. Authentication, enumeration, xp_cmdshell RCE, linked server abuse, privilege escalation, database enumeration, UNC path capture, OPSEC considerations.

Protocols

proto-rdp

RDP security testing — BlueKeep/DejaBlue detection, credential brute force, NLA bypass, RDP session hijacking, pass-the-hash via RDP, restricted admin mode.

Protocols

proto-smb

SMB/NetBIOS security testing skill. Null session enumeration, credential spraying, pass-the-hash, relay attacks, EternalBlue, and share enumeration.

Protocols

proto-smtp

SMTP/IMAP security testing — SMTP relay, user enumeration via VRFY/RCPT, email spoofing (SPF/DKIM/DMARC bypass), SMTP injection, credential brute force.

Protocols

proto-snmp

SNMP security testing — community string brute force, SNMP v1/v2c info dump, OID enumeration, SNMP write abuse, MIB walking.

Protocols

proto-ssh

SSH security testing — version detection, brute force, key-based auth bypass, SSH tunneling, authorized_keys misconfiguration, weak ciphers.

Protocols

proto-vnc

VNC (Virtual Network Computing) enumeration and exploitation. No-auth check, VNC brute force, CVE-2006-2369 auth bypass, screenshot capture, LibVNCServer CVEs, SSH tunnel access.

Other

publish

Publish gitest to npm via GitHub Actions workflow. Argument: <patch|minor|major>.

Reverse Engineering

re-dynamic

Dynamic binary analysis skill. Runtime debugging, system call tracing, library call tracing, memory inspection, and exploit development using gdb, pwndbg, strace, ltrace, and angr.

Reverse Engineering

re-static

Static reverse engineering skill. Disassembly, decompilation, string extraction, and binary analysis without execution. Tools: ghidra, radare2, cutter, strings, binwalk, objdump.

Reconnaissance

recon-asn-whois

ASN, WHOIS, and OSINT reconnaissance — IP range discovery via ASN, WHOIS pivoting, BGP intelligence, CIDR block enumeration, IP history, corporate netblock mapping.

Reconnaissance

recon-cloud-assets

Cloud asset discovery reconnaissance. S3 bucket enumeration, Azure Blob storage, GCP Cloud Storage, cloud subdomain identification, misconfigured storage exposure, cloud infrastructure mapping.

Reconnaissance

recon-devtools

Exposed developer tools and debug interfaces detection — Webpack DevServer, React DevTools, Vue DevTools, exposed metrics endpoints, debug ports, GraphiQL, Jupyter notebooks, Kibana.

Reconnaissance

recon-dorking

Google/Bing/DuckDuckGo dorking skill for passive OSINT reconnaissance. Discovers exposed credentials, sensitive files, admin panels, git repos, and attack surface via search engine operators.

Reconnaissance

recon-favicon

Favicon hash fingerprinting for asset discovery. MurmurHash3 (mmh3) computation of favicon.ico from target URLs, Shodan http.favicon.hash search, FOFA icon_hash search, Censys favicon hash search, httpx live verification of discovered assets.

Reconnaissance

recon-full

Comprehensive full reconnaissance methodology — passive intel, subdomain enumeration, live host detection, port scanning, tech stack fingerprinting, JS analysis, secret hunting.

Reconnaissance

recon-internal

Internal network penetration test reconnaissance — network discovery, service enumeration, LDAP/AD enumeration, SMB shares, internal web apps, printer discovery.

Reconnaissance

recon-js-analysis

JavaScript analysis skill for SPA reconnaissance. Extracts API endpoints, hardcoded secrets, internal hostnames, and authentication tokens from client-side JavaScript bundles.

Reconnaissance

recon-js-hostname

JavaScript internal hostname intelligence — extract internal hostnames, API endpoints, microservice URLs, cloud metadata endpoints, internal IP addresses from client-side JavaScript.

Reconnaissance

recon-secrets

Secrets and credential exposure scanning — gitleaks, trufflehog, JS secret scanning, S3 bucket secrets, environment variables, hardcoded credentials in source code.

Reconnaissance

recon-shodan

Shodan, Censys, FOFA passive reconnaissance. ASN enumeration, IP range discovery, favicon hashing, internet-wide scanning, exposed service discovery.

Reconnaissance

recon-subdomain

Subdomain enumeration. subfinder, assetfinder, amass passive, dnsx resolution, httpx live service detection, permutation/brute-force, high-value subdomain prioritization.

Red Team

red-exploit

Red team exploitation skill. Stealth exploitation, persistence, and privilege escalation. Use for red team engagements requiring stealth and persistence.

Red Team

red-lateral

Red team lateral movement skill. Active Directory attacks, SMB/WinRM pivoting, and credential relay. Use for red team lateral movement and domain dominance.

Red Team

red-persistence

Red team persistence skill. Backdoor mechanisms, scheduled tasks, registry persistence, and covert channels. Use for establishing long-term access during red team engagements.

Red Team

red-recon

Red team reconnaissance skill. Stealth OSINT, passive enumeration, and social engineering preparation. Use for red team engagements requiring stealth.

Other

remove-deadcode

Remove unvalidated findings from this project with fullscan mode, scope-verified safety, atomic evidence records.

Other

security-research

Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release

Techniques

tech-apache-misconfig

Apache httpd misconfiguration testing — .htaccess bypass, mod_status, directory listing, server-info, TRACE method, Optionsbleed, path traversal via Alias.

Techniques

tech-cicd

CI/CD pipeline security attacks. GitHub Actions pull_request_target exploitation, GitLab CI variable injection, Jenkins RCE via Groovy console, secret scanning, OIDC token hijacking, dependency confusion.

Techniques

tech-cloud-security

Cloud security assessment skill for AWS, GCP, and Azure. Tests IMDS abuse, IAM privilege escalation, misconfigured storage, exposed credentials, serverless security, and container escapes.

Techniques

tech-config-hardening

Web application and server configuration hardening review. Security header audit (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy), TLS/SSL configuration check, debug endpoint enumeration (actuator, metrics, env, debug, swagger), verbose error message detection, backup and config

Techniques

tech-debt-audit

Thorough, file-cited technical debt audit across 9 dimensions using AST-grep (tree-sitter), grep, language-native tooling, and optionally CodeGraph knowledge graph. Produces ATTACK_SURFACE_AUDIT.md with severity, effort estimates, and prioritized fixes. Use when asked for target coverage check, atta

Techniques

tech-docker

Docker and container security testing — privileged container escape, docker socket abuse, container breakout, image secret scanning, registry credentials, Kubernetes misconfiguration.

Techniques

tech-elasticsearch

Elasticsearch and Kibana security testing — unauthenticated data exposure, index enumeration, PII data extraction, Kibana console RCE, snapshot abuse, CVE exploitation.

Techniques

tech-enterprise-web

Enterprise web penetration testing workflow. Scope definition, httpx fingerprinting, katana crawling, nuclei scanning, authentication testing, JWT analysis, business logic review, IDOR, dependency SCA, manual verification.

Techniques

tech-firebase

Firebase security testing — Firestore/RTDB unauthenticated read/write, Firebase Auth bypass, Storage bucket enumeration, API key exposure, Cloud Functions SSRF.

Techniques

tech-frida-hooking

Frida dynamic instrumentation and hooking. Android/iOS SSL pinning bypass, method interception, memory patching, native hook, Java method override, argument/return value modification, runtime analysis.

Techniques

tech-git-platforms

Git platform security testing — GitLab/GitHub/Gitea misconfigs, exposed .git repos, API token abuse, CI/CD pipeline injection, secret scanning in public repos.

Techniques

tech-jenkins

Jenkins security testing — unauthenticated RCE via Groovy console, credential exposure, Jenkinsfile injection, CSRF bypass, build artifact secrets, pipeline abuse.

Techniques

tech-kubernetes

Kubernetes cluster security assessment. API server enumeration, kubelet exploitation, etcd access, RBAC misconfigurations, pod escape, privilege escalation, service account abuse.

Techniques

tech-memcached

Memcached security testing — unauthenticated access, cache poisoning, session hijacking, data extraction, DDoS amplification, memcached stats enumeration.

Techniques

tech-mongodb

MongoDB security testing — unauthenticated access, collection enumeration, NoSQL injection, data exfiltration, MongoDB bind IP misconfiguration.

Techniques

tech-nginx-apache

Nginx and Apache security testing — path traversal via alias misconfiguration, .htaccess bypass, Apache mod_status, nginx off-by-slash, server-side includes, HTTP methods abuse, server info disclosure.

Techniques

tech-observability

Observability platform security testing — Grafana default credentials, Prometheus metrics exposure, Jaeger unauth access, Zipkin, alertmanager webhook abuse, metric exfiltration.

Techniques

tech-qemu-emulation

QEMU cross-architecture emulation for firmware analysis and exploit testing. ARM/MIPS/RISC-V binary execution, GDB debugging cross-arch, firmware extraction with binwalk, chroot emulation, IoT service testing, cross-compile exploitation.

Techniques

tech-redis

Redis security testing — unauthenticated access, AUTH brute force, config write for cron/SSH injection, Lua RCE, Redis module exploitation.

Techniques

tech-stack-fingerprint

Technology stack fingerprinting for security assessment. httpx-based technology detection with status codes and server banners, HTTP response header analysis (Server, X-Powered-By, Set-Cookie tech reveals), WhatWeb aggressive detection, Nuclei tech-detect templates, WordPress/Drupal/Joomla/framework

Techniques

tech-supabase

Supabase security testing — anon key abuse, Row Level Security bypass, PostgREST direct access, service_role key exposure, real-time subscription abuse.

Techniques

tech-tomcat

Apache Tomcat security testing — manager app default creds, WAR deployment RCE, CVE exploitation (Ghostcat, CVE-2019-0232), AJP connector abuse, session fixation.

Tooling

tool-advanced-fuzzing

Advanced web fuzzing techniques — ffuf, feroxbuster, custom wordlists, virtual host fuzzing, API endpoint fuzzing, parameter fuzzing, HTTP method fuzzing, header fuzzing.

Tooling

tool-browser-automation

Browser automation for pentesting — Playwright/Puppeteer for authenticated crawling, form submission, SPA spider, JavaScript rendering, DOM XSS detection, screenshot proof collection.

Tooling

tool-caido

Caido web security proxy — intercepting proxy, replay, automate, workflow rules, filter, match/replace, HTTPQL querying, Caido Automate for fuzzing.

Tooling

tool-dalfox

Dalfox XSS scanner — parameter discovery, DOM XSS, blind XSS, WAF bypass, pipe mode, custom payloads, Burp integration.

Tooling

tool-hashcat-john

Password cracking with Hashcat and John the Ripper — hash identification, wordlist attacks, rule-based attacks, hybrid attacks, rainbow tables, mask attacks.

Tooling

tool-impacket

Impacket toolkit — psexec, wmiexec, smbexec, secretsdump, GetUserSPNs, GetNPUsers, NTLM relay, SMB client, DCSync, pass-the-hash, Kerberos ticket.

Tooling

tool-metasploit

Metasploit Framework usage — module search, exploit execution, payload generation, post-exploitation, meterpreter, auxiliary modules, MSFvenom.

Tooling

tool-nmap

Nmap comprehensive usage — SYN scan, service detection, script scanning, OS fingerprinting, aggressive scan, CVE detection, UDP scan, output formats.

Tooling

tool-nuclei

Nuclei template-based vulnerability scanner — community templates, custom templates, CVE scanning, severity filtering, bulk scanning, rate limiting, report output.

Tooling

tool-scripting

Pentest scripting techniques — bash one-liners, Python exploit scripts, curl chaining, Burp Extender automation, jq parsing, grep pattern extraction for pentest workflows.

Tooling

tool-semgrep

Semgrep static analysis for security — SAST rules, custom rules, secret detection, code pattern matching, OWASP Top 10 detection, CI/CD integration.

Tooling

tool-source-audit

Manual source code security audit — PHP/Python/Node/Java code review, dangerous function patterns, file inclusion vulnerabilities, SQL injection in ORM, authentication logic flaws.

Tooling

tool-sqlmap

SQLMap usage guide — detection mode, database enumeration, data extraction, file read/write, OS shell, WAF bypass, tamper scripts, custom payloads.

Tooling

tool-wapiti

Wapiti web vulnerability scanner — SQL injection, XSS, SSRF, file disclosure, command injection, CRLF, open redirect scanning with HTML report.

Vulnerability

vuln-2fa-bypass

Two-factor authentication bypass testing — OTP brute force, response manipulation, backup code abuse, step skip, CSRF on 2FA disable, SIM swap indicators, OAuth to bypass 2FA, cookie theft to bypass 2FA.

Vulnerability

vuln-account-takeover

Account takeover (ATO) testing — password reset flaws, OAuth misconfig, session fixation, CSRF chain to ATO, XSS cookie theft, IDOR-based ATO, credential stuffing, email change without verification.

Vulnerability

vuln-api-schema-exposure

API schema exposure testing — OpenAPI/Swagger discovery, GraphQL introspection, WSDL exposure, gRPC reflection, API documentation endpoints.

Vulnerability

vuln-api-testing

REST API security testing — endpoint discovery, authentication testing, rate limiting bypass, versioning attacks, excessive data exposure, API security top 10.

Vulnerability

vuln-auth-workflow

Authentication workflow testing — login bypass, session management flaws, insecure remember-me, concurrent session handling, account lockout bypass, credential stuffing.

Vulnerability

vuln-bfla

Broken Function Level Authorization (BFLA) testing — accessing admin functions as regular user, HTTP method override, hidden admin endpoints, privilege escalation via API versioning.

Vulnerability

vuln-blind-xss

Blind XSS (out-of-band XSS) testing. Stored XSS in admin panels, log viewers, moderation queues. interactsh callback setup, injection point mapping, payload delivery via forms/headers/file metadata.

Vulnerability

vuln-business-logic

Business logic vulnerability testing. Tests workflow bypass, price manipulation, refund abuse, quota bypass, and state machine attacks.

Vulnerability

vuln-cache-deception

Web cache deception testing. CDN caching of authenticated content via extension tricks, path manipulation, URL encoding. Cache behavior analysis, sensitive endpoint discovery.

Vulnerability

vuln-clickjacking

Clickjacking (UI redressing) vulnerability testing. X-Frame-Options check, CSP frame-ancestors bypass, PoC iframe creation, drag-and-drop variant, multi-step clickjacking.

Vulnerability

vuln-cors

CORS misconfiguration testing skill. Tests origin reflection, null origin, subdomain trust chains, and credential-bearing cross-origin requests.

Vulnerability

vuln-crlf

CRLF injection testing — HTTP header injection, response splitting, cookie injection, XSS via CRLF, log injection, redirect via CRLF.

Vulnerability

vuln-csrf

CSRF (Cross-Site Request Forgery) testing — token bypass, SameSite bypass, Referer-only validation bypass, JSON CSRF, multipart CSRF, cross-origin state change.

Vulnerability

vuln-csrf-advanced

Advanced CSRF bypass — SameSite cookie bypass via navigation, click-jacking chain, CSRF via Flash redirect, subdomain CSRF bypass, sibling domain CSRF, browser-based CSRF bypass via service worker.

Vulnerability

vuln-deserialization

Insecure deserialization testing — Java (ysoserial gadget chains), PHP object injection, Python pickle RCE, Ruby Marshal injection, .NET BinaryFormatter, Jackson/XStream, node-serialize.

Vulnerability

vuln-dom-xss

DOM-based XSS and client-side vulnerabilities. Source-to-sink analysis, postMessage origin bypass, open redirect via DOM, eval/innerHTML sinks, DOM clobbering.

Vulnerability

vuln-exploit-validation

Exploit and vulnerability validation methodology. Safe reproduction with minimal payload, baseline request capture, controlled impact demonstration without destructive actions, fix verification after remediation, evidence collection for report. Triage preconditions, auth requirements, input vectors.

Vulnerability

vuln-file-upload

File upload vulnerability testing — extension bypass, MIME type bypass, magic bytes bypass, double extension, null byte, polyglot files, webshell upload, path traversal via filename.

Vulnerability

vuln-grpc

gRPC security testing — service enumeration via reflection, proto file analysis, injection via gRPC methods, authentication bypass, plaintext gRPC interception.

Vulnerability

vuln-host-header

Host header injection testing — password reset poisoning, cache poisoning via Host, SSRF via Host header, routing bypass, virtual host confusion, port-based bypass.

Vulnerability

vuln-http-smuggling

HTTP request smuggling testing skill. Tests CL.TE, TE.CL, TE.TE, H2.CL, H2.TE desync vulnerabilities.

Vulnerability

vuln-idor

IDOR/BOLA (Insecure Direct Object Reference / Broken Object Level Authorization) testing skill. Tests horizontal/vertical access control across REST, GraphQL, WebSocket, and gRPC.

Vulnerability

vuln-info-disclosure

Information disclosure testing — error message leakage, debug endpoints, stack traces, API schema exposure, backup files, git repositories, environment variables exposure, directory listing.

Vulnerability

vuln-interactsh-oob

Out-of-band vulnerability detection with Interactsh. Blind SSRF via URL/header injection, blind XXE with external entity and parameter entity OOB data exfiltration, blind SQL injection via MySQL/MSSQL/PostgreSQL/Oracle OOB channels, blind SSTI via Jinja2/Twig/FreeMarker with curl callback, blind com

Vulnerability

vuln-jwt

JWT vulnerability exploitation. Algorithm confusion (alg:none, RS256→HS256), weak secret cracking, kid injection, JWK header injection, claim manipulation.

Vulnerability

vuln-llm-attacks

LLM application security testing. Direct prompt injection, indirect RAG injection, tool abuse, output injection (XSS via markdown), pipeline mapping, system prompt extraction.

Vulnerability

vuln-log4shell

Log4Shell (CVE-2021-44228) detection and exploitation. JNDI injection, WAF bypass obfuscation, interactsh OOB detection, marshalsec LDAP exploit server, ysoserial gadget chains.

Vulnerability

vuln-mass-assignment

Mass assignment vulnerability testing — injecting extra parameters to elevate privileges, bypass access control, assign roles/admin flags via API body.

Vulnerability

vuln-nosql

NoSQL injection testing — MongoDB operator injection ($ne/$gt/$where), authentication bypass, blind NoSQL injection, MongoDB aggregation abuse, Redis command injection.

Vulnerability

vuln-oauth

OAuth 2.0 and OpenID Connect misconfiguration testing. Open redirect ATO, state CSRF bypass, authorization code leakage and reuse, token audience confusion, PKCE bypass, scope escalation, implicit flow abuse.

Vulnerability

vuln-open-redirect

Open redirect testing — parameter-based redirect bypass, host header redirect, subdomain bypass, URL scheme bypass, phishing chain, OAuth redirect_uri abuse.

Vulnerability

vuln-password-reset-poisoning

Password reset poisoning via Host header injection and redirect parameter manipulation. Causes reset emails with attacker-controlled URLs.

Vulnerability

vuln-path-traversal

Path traversal / directory traversal / LFI testing — ../../../etc/passwd, URL encoding bypass, null byte bypass, filter bypass with encoding, absolute path injection, path normalization bypass.

Vulnerability

vuln-privesc-web

Web application privilege escalation testing — horizontal to vertical escalation, parameter tampering for role bypass, JWT privilege escalation, cookie manipulation, admin panel access via role confusion.

Vulnerability

vuln-prototype-pollution

Prototype pollution testing skill. Tests client-side (DOM XSS gadgets) and server-side (Node.js RCE, auth bypass) via Object.prototype injection.

Vulnerability

vuln-race-conditions

Race condition testing skill for concurrent request vulnerabilities. Tests TOCTOU, double-spend, coupon abuse, quota bypass using HTTP/2 tight synchronization.

Vulnerability

vuln-rce

Remote Code Execution testing skill. Tests command injection, template injection RCE, deserialization RCE, SSRF-to-RCE chains, and container escape vectors.

Vulnerability

vuln-sensitive-exposure

Sensitive data and PII exposure testing — credentials in responses, API key leakage, PII in logs/responses, unencrypted sensitive data, EXIF data, S3 bucket exposure, cloud storage misconfig.

Vulnerability

vuln-spring4shell

Spring4Shell (CVE-2022-22965) detection and exploitation. JSP webshell via classloader pattern, nuclei detection, Spring/Tomcat fingerprinting, WAR deployment RCE.

Vulnerability

vuln-sqli

SQL injection testing skill. Comprehensive SQLi methodology: parameter discovery, manual probing, error/boolean/time-based/union/OOB techniques, DBMS-specific payloads, and WAF bypass.

Vulnerability

vuln-ssrf

Server-Side Request Forgery (SSRF) testing — cloud metadata exfiltration, internal service pivoting, blind SSRF via OOB callbacks, protocol abuse (Gopher/dict/file), DNS rebinding, SSRF filter bypass.

Vulnerability

vuln-ssti

Server-Side Template Injection (SSTI) testing — Jinja2/Twig/Freemarker/Velocity/Pebble/Smarty/ERB/Mako detection, template expression probing, RCE via SSTI, sandbox escape.

Vulnerability

vuln-subdomain-takeover

Subdomain takeover testing — dangling CNAME detection, cloud service fingerprinting, GitHub Pages takeover, S3 bucket takeover, Heroku/Netlify/Vercel claim, NS takeover.

Vulnerability

vuln-supply-chain

Supply chain security testing — dependency confusion, typosquatting, npm/PyPI package hijacking, malicious dependency injection, CI/CD pipeline attacks, GitHub Actions poisoning.

Vulnerability

vuln-waf-bypass

WAF detection and bypass techniques — WAF fingerprinting, encoding bypass, case manipulation, header smuggling past WAF, chunked encoding, parameter pollution, Unicode normalization bypass.

Vulnerability

vuln-websocket

WebSocket security testing — cross-site WebSocket hijacking (CSWSH), message injection, authentication bypass, SQL/NoSQL/command injection via WebSocket messages, privilege escalation via WebSocket.

Vulnerability

vuln-xs-leaks

XS-Leaks (cross-site leak) vulnerability testing. Timing attacks, resource event inference, redirect chain leaks, browser side channels, history.length leaks, frame counting.

Vulnerability

vuln-xss

Reflected and Stored XSS testing — injection point discovery, context-aware payload crafting, WAF bypass, stored XSS via API, CSP bypass, cookie theft, keylogging, BeEF hooking.

Vulnerability

vuln-xxe

XML External Entity (XXE) injection testing — local file read, SSRF via XXE, blind OOB XXE via DNS/HTTP callbacks, parameter entity XXE, DTD-based exfiltration, XXE via SVG/DOCX/XLSX.

Workflow

work-with-pr

Full pentest finding submission lifecycle in an isolated engagement workspace: implement via the pentest-loop skill with mandatory evidence-bound manual QA → detailed English PR → verification loop (validation + review-work reviewers + Cubic, where Cubic is skipped only when its quota is exhausted)

Workflow

work-with-pr-workspace

Git workflow skill for working with pull requests in isolated worktrees — branch creation, implementation, QA evidence, PR creation via gh CLI.