No visual example yet
Explore the skillXAttacker
Moham3dRiahi
OPENAGENTSKILL / DIRECTORY
다음 작업에 맞는 스킬을 찾아보세요. Codex, Claude Code, Cursor 등을 지원합니다.
13 Skills
검색 결과: 13
No visual example yet
Explore the skillMoham3dRiahi
No visual example yet
Explore the skillzhaoxuya520
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for DFIR chronology, cross-artifact correlation, persistence chains, and incident timeline r…
No visual example yet
Explore the skillelementalsouls
Hunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1) password reset flaws (host-header injection redirects token, predictable/numeric token,…
No visual example yet
Explore the skillelementalsouls
Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTI…
No visual example yet
Explore the skillelementalsouls
Hunt Clickjacking — missing X-Frame-Options / CSP frame-ancestors lets an attacker embed the target page in an invisible iframe and trick victims into clicking buttons t…
No visual example yet
Explore the skillelementalsouls
Hunt HTML Injection — user-supplied input is rendered as raw HTML in the response without sanitisation, allowing an attacker to inject arbitrary HTML tags (but not neces…
No visual example yet
Explore the skilltjboudreaux
For authorized security review of code, auth, or APIs you control, model the attacker, map the attack surface, and report only findings with a reproducible exploit path…
No visual example yet
Explore the skillglebis
Residual re-identification RISK CHECK on text you have ALREADY redacted (defensive, dual-use). Use when the user asks to "check residual re-id risk", "red-team
No visual example yet
Explore the skillgaasher
Use when the user wants to adversarially stress-test a guardrail, classifier, prompt, or API they own or are authorized to test, to surface the distinct ways it fails. G…
No visual example yet
Explore the skillLiberty91LTD
Use when you need to answer "which attacker techniques do our controls actually stop, and how well?", "what controls should I have for this threat?", or "what telemetry…
No visual example yet
Explore the skillNoorQureshi
Abuse an LLM agent's tools/functions — coerce it to call tools with attacker-chosen args for SSRF, RCE, data exfil, or privilege abuse. Load when the target is an agent…
No visual example yet
Explore the skillNoorQureshi
Poison a RAG/knowledge-base pipeline so retrieved content hijacks the model (indirect prompt injection at scale) or exfiltrates data. Load when the app does retrieval ov…
No visual example yet
Explore the skillforefy
AI Agent Skills for Security Auditing to generate triaged, industry grade report findings, code locations, pocs, attacker story flow graphs and more