All authors

Claude Skills by adriannoes
github.com/adriannoes237 skills1 installs376 views
- Skill Security AuditorSecurity audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a skill directory or git repo URL for malicious code, (3) pre-install security gate for Claude Code plugins, OpenClaw skills, or Codex skills, (4) scanning Python scripts for dangerous patterns like os.system, eval, subprocess, network exfiltration, (5) detecting prompt injection in SKILL.md files, (6) checking dependency supply chain risks,...Votes: 0GitHub stars: 61
- Analyzing Ransomware Network IndicatorsIdentify ransomware network indicators including C2 beaconing patterns,Votes: 0GitHub stars: 61
- Assessing Vector And Embedding WeaknessesTest vector stores for embedding inversion, cross-tenant leakage, and poisoning.Votes: 0GitHub stars: 61
- Auditing Mcp Servers For Tool PoisoningScan Model Context Protocol servers and tool metadata for poisoning, SSRF, and unauthenticated exposure.Votes: 0GitHub stars: 61
- Building Super Timelines With PlasoGenerate log2timeline and Plaso super-timelines and triage them in Timesketch.Votes: 0GitHub stars: 61
- Continuous Llm Red Teaming With PromptfooWire Promptfoo and DeepTeam into CI/CD for automated regression red-teaming of LLM apps against OWASP LLM Top 10 and OWASP Agentic presets, failing the build when jailbreak or injection vulnerabilities regress.Votes: 0GitHub stars: 61
- Defending Llms With GuardrailsDeploy Llama Guard, NeMo Guardrails, and LLM Guard input/output scanners as runtime defenses.Votes: 0GitHub stars: 61
- Detecting Data And Model PoisoningIdentify poisoned training data and backdoored models across the ML pipeline.Votes: 0GitHub stars: 61
- Detecting Dependency ConfusionDetect and prevent public-over-private name resolution in npm, PyPI, and Maven.Votes: 0GitHub stars: 61
- Detecting Entra Offensive Tools In Graph LogsHunt AADGraphActivityLogs and MicrosoftGraphActivityLogs in Microsoft Sentinel/Log Analytics for fingerprints of offensive Entra ID tools such as ROADtools, AADInternals, and AzureHound.Votes: 0GitHub stars: 61
- Detecting Indirect Prompt InjectionDetect and defend against prompt injection hidden in documents, web pages, and images consumed by an agent.Votes: 0GitHub stars: 61
- Detecting Malicious Npm PackagesTriage npm packages for install-script malware, exfiltration, and worming behavior.Votes: 0GitHub stars: 61
- Detecting Model Extraction AttacksDetect model stealing, model inversion, and membership inference performed through inference-API abuse by monitoring query patterns, applying output perturbation, and red-teaming your own model's extractability.Votes: 0GitHub stars: 61
- Detecting Secure Boot BypassDetect bootkits such as BlackLotus and Bootkitty and Secure Boot bypass via DBX and binary checks.Votes: 0GitHub stars: 61
- Detecting Typosquatting PackagesFlag misspelled, brandjacked, and typosquatted package names across npm, PyPI, and crates.io before installation using edit-distance, keyboard-proximity, and known-target corpus matching with typomania, OSSGadget, and pypi-scan.Votes: 0GitHub stars: 61
- Enumerating Cloud With CloudfoxMap AWS and Azure attack paths and find exploitable misconfigurations withVotes: 0GitHub stars: 61
- Extracting Iocs From Malware Samples'Extracts indicators of compromise (IOCs) from malware samples includingVotes: 0GitHub stars: 61
- Fleet Hunting With VelociraptorDeploy a Velociraptor server and agents and write VQL hunts across a fleet.Votes: 0GitHub stars: 61
- Generating And Analyzing SbomsProduce and ingest CycloneDX and SPDX SBOMs and correlate them to vulnerability intelligence.Votes: 0GitHub stars: 61
- Generating Forensic Timelines With HayabusaProduce Sigma-based EVTX timelines and summaries with Hayabusa.Votes: 0GitHub stars: 61
- Hunting Bootkits In Efi System PartitionBaseline the EFI System Partition and hunt malicious EFI binaries (ESPecter, BlackLotus, Bootkitty, Glupteba) by mounting the ESP, hashing and verifying boot loaders, scanning with YARA, and detecting anomalous non-EFI files.Votes: 0GitHub stars: 61
- Hunting Evtx With ChainsawPerform rapid Sigma and keyword hunting across Windows event logs withVotes: 0GitHub stars: 61
- Hunting Saas Sso Token AbuseDetect SSO and OAuth token replay and SaaS lateral movement.Votes: 0GitHub stars: 61
- Implementing Sigstore For Software Signing'Implements Sigstore-based software signing and verification using CosignVotes: 0GitHub stars: 61
- Investigating Ransomware Attack ArtifactsIdentify, collect, and analyze ransomware attack artifacts to determineVotes: 0GitHub stars: 61
- Managing Cloud Identity With Okta'This skill covers implementing Okta as a centralized identity providerVotes: 0GitHub stars: 61
- Orchestrating Llm Attacks With PyritBuild multi-turn, Crescendo, and Tree-of-Attacks-with-Pruning (TAP) automated attack chains against conversational LLM agents using Microsoft PyRIT, with adversarial chat and scorer feedback loops.Votes: 0GitHub stars: 61
- Parsing Artifacts With Eric Zimmerman ToolsParse registry, prefetch, shellbags, and MFT with EZ Tools and Timeline Explorer.Votes: 0GitHub stars: 61
- Red Teaming Llms With GarakRun NVIDIA garak probe suites against an LLM endpoint to test for jailbreaks, prompt injection, data leakage, and toxic generation, then interpret the hit-rate report for triage and reporting.Votes: 0GitHub stars: 61
- Securing Agentic Ai Tool InvocationApply least-privilege tool allowlisting, identity binding, and human-in-the-loop controls for agent tool calls.Votes: 0GitHub stars: 61
- Testing For System Prompt LeakageExtract and defend system prompts plus embedded secrets and routing logic.Votes: 0GitHub stars: 61
- Testing Prompt Injection In Rag PipelinesProbe RAG applications for prompt injection via poisoned retrieved context and embedding manipulation.Votes: 0GitHub stars: 61
- Validating Tpm Measured Boot AttestationVerify TPM PCRs and measured-boot and remote-attestation integrity.Votes: 0GitHub stars: 61
- Verifying Build Provenance With Slsa SigstoreVerify signed artifacts and SLSA build provenance with Sigstore cosign and slsa-verifier, enforce keyless OIDC identity, and apply SLSA Build levels to harden the software supply chain.Votes: 0GitHub stars: 61
- Apk Redteam PipelineEnd-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external red-team engagement where 7 APKs were pulled manually, 4 download attempts truncated, and a hardcoded JWT + 30 internal API endpoints were recovered from one of the apps. Use wh...Votes: 0GitHub stars: 61
- Bb Local ToolkitComplete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security t...Votes: 0GitHub stars: 61
- Bb MethodologyUse at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other skills based on current hunting phase. Also use when asking "what should I do next" or "where am I in the process."Votes: 0GitHub stars: 61
- Bug BountyComplete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security t...Votes: 0GitHub stars: 61
- Bugcrowd ReportingBugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints, debug-info framing, user-enumeration with sensitive PII, theoretical-issue counter), chained-finding cross-reference patterns, target selection for QA-vs-prod programs, researcher-s...Votes: 0GitHub stars: 61
- Cloud Iam DeepCloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abuse, IMDSv1/v2 attacks via SSRF, K8s ServiceAccount token exfil, role-trust-policy confused-deputy, cross-account assume-role enumeration, IAM privilege escalation patterns (24+ AWS, 8+ Azure, 6+ GC...Votes: 0GitHub stars: 61
- Enterprise Vpn AttackExternal SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure, SonicWall, F5 Big-IP. Covers version fingerprinting, CVE matrix (2018-2026), AAA backend identification, default credentials, configuration-disclosure paths, pre-auth RCE/SSRF/path-traversal exploits where applicable. Built from authorized-engagement Cisco ASA testing plus 2024-2026 enterprise VPN CVE ...Votes: 0GitHub stars: 61
- Evidence HygieneEvidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools workflow), PII black-bar discipline (what to mask in other-user data — names, emails, phones, faces — vs what is safe to leave — usernames, trace IDs, request bodies), HAR file sanitization (jq filters for Cookie/Set-Cookie/Authorization headers), Burp Repeater/Intruder screenshot hygiene (hide request body, show only Resu...Votes: 0GitHub stars: 61
- Hunt Api MisconfigHunt API security misconfiguration — mass assignment, JWT attacks, prototype pollution, CORS, HTTP verb tampering. Mass assignment: send {is_admin:true, role:admin, verified:true} on profile/account/reset endpoints — server blindly applies. JWT: alg=none, weak HMAC bruteforce, kid path traversal, JWK injection, token confusion. Prototype pollution: __proto__ injection in JSON merge / Object.assign / lodash _.merge → polluted prototype reaches sink (RCE in Node, XSS in browser). CORS: wildcard...Votes: 0GitHub stars: 61
- Hunt AspnetHunt ASP.NET-specific surface — ViewState deserialization (signed-only vs encrypted), machineKey recovery, dual-parser MAC-bypass anti-pattern, request-validator bypass, trace.axd/elmah.axd disclosure, load-balanced ViewState cross-node failures, SafeControl enumeration via reflection, customErrors mode=Off stack-trace leaks, classic Webforms .aspx/.asmx/.svc surface. Built for ASP.NET Webforms + WCF + SharePoint farms.Votes: 0GitHub stars: 61
- Hunt AtoHunt account takeover taxonomy — 9 distinct paths to ATO, plus chains. Paths: (1) password reset flaws (host header injection redirects token to attacker, predictable token, token leaked in referer, race condition on reset link), (2) email change without re-auth, (3) OAuth account-link CSRF, (4) MFA bypass (per hunt-mfa-bypass), (5) session-fixation, (6) JWT manipulation, (7) password change without step-up (chain with password oracle), (8) social-recovery question abuse, (9) SSO subdomain ta...Votes: 0GitHub stars: 61
- Hunt Auth BypassHunting skill for auth bypass vulnerabilities. Built from 4 public bug bounty reports. Use when hunting auth bypass on any target.Votes: 0GitHub stars: 61
- Hunt Business LogicHunting skill for business logic vulnerabilities. Built from 7 public bug bounty reports. Use when hunting business logic on any target.Votes: 0GitHub stars: 61
- Hunt Cache PoisonHunting skill for cache poison vulnerabilities. Built from 4 public bug bounty reports. Use when hunting cache poison on any target.Votes: 0GitHub stars: 61
- Hunt Cloud MisconfigHunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessible via SSRF. GCP: public GCS buckets, exposed Cloud Run services, leaked service account JSON. Azure: public blob containers, exposed Function App. K8s: kubelet 10250 unauth, etcd 2379, dashboard public, services API ...Votes: 0GitHub stars: 61
- Hunt CsrfHunting skill for csrf vulnerabilities. Built from 10 public bug bounty reports. Use when hunting csrf on any target.Votes: 0GitHub stars: 61