All authors

Claude Skills by H-mmer
github.com/H-mmer182 skills2 installs158 views
- Agent Privilege EscalationPrivilege Escalation specialist (H1 #26). Use for testing vertical and horizontal privilege escalation, role manipulation, admin endpoint access, and permission boundary violations.Votes: 0GitHub stars: 815
- Agent Quality CheckReport quality scorer. Use BEFORE submitting any report to validate completeness, clarity, title strength, CVSS accuracy, PoC quality, and overall report grade. Provide the draft report path or content.Votes: 0GitHub stars: 815
- Agent Race ConditionRace Condition specialist (H1 #29). Use for testing TOCTOU flaws, double-spend, parallel request abuse on balance operations, coupon redemption, and any non-idempotent state changes.Votes: 0GitHub stars: 815
- Agent Rce HunterRemote Code Execution specialist (H1 #70). Use for testing command injection, template injection (SSTI), deserialization, expression language injection, and any vector that achieves server-side code execution.Votes: 0GitHub stars: 815
- Agent Recon RankerAttack surface ranker. Takes recon output + brain data, produces P1/P2/Kill prioritized attack plan with concrete curl commands for each P1 target. Use after recon to decide what to test first.Votes: 0GitHub stars: 815
- Agent ReconReconnaissance agent for target enumeration. Use for subdomain discovery, port scanning, service fingerprinting, tech stack identification, and OSINT gathering. Specify scope and depth: 'passive' for DNS/cert/OSINT only, 'active' for port scans and probing, 'deep' for comprehensive enumeration.Votes: 0GitHub stars: 815
- Agent Report WriterSecurity report generation agent. Use for compiling findings into formal penetration test reports, executive summaries, technical write-ups, and bug bounty submissions. Provide the findings directory or list of vulnerabilities to document.Votes: 0GitHub stars: 815
- Agent Sast Danger MapperMaps dangerous operations in a source file: memory ops, type casts, arithmetic near trust boundaries, free/dealloc patterns. Pattern matching task — list what you see, don't speculate. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Devils AdvocateAdversarial validator for SAST findings. Your ONLY job is to DISPROVE the candidate. Find every reason it's not exploitable. If you can't disprove it, it survives. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Entry MapperMaps entry points where untrusted data enters a source file. Lists every function that receives external input with data type, size constraints, and initial validation. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Exploit BuilderBuilds working exploits from confirmed SAST findings. Takes a confirmed crash, develops it into a full exploit. Tier 1 (DoS) → Tier 5 (code execution). Use via /sast command after PoC confirmation.Votes: 0GitHub stars: 815
- Agent Sast File RankerSource file attack surface ranker. Reads a repository, scores every source file 1-5 by exploitability. Outputs ranked JSON for per-file hunting. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Flow TracerTraces data flow from entry points to dangerous operations. Cross-file reasoning to determine which entries can reach which dangers, and what validation exists in between. MUST run on Opus for reasoning depth. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Gap AnalyzerAnalyzes validation gaps in data flows. Takes traced flows and identifies where checks are missing, insufficient, or bypassable. The 'interaction reasoning' step — finds bugs that exist in the gaps between individually correct-looking code. MUST run on Opus. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast HunterFocused PoC builder for SAST candidates. Receives a SPECIFIC candidate vulnerability that survived adversarial validation. Writes a PoC, compiles, runs with ASan, confirms or rejects. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Scope CheckTarget scope validation agent. Use BEFORE any active testing to verify targets are in scope. Provide the target and the program name or scope file. Checks against .scope.txt, scope.yaml, and fetches live program scope from HackerOne/Bugcrowd/Intigriti APIs if configured.Votes: 0GitHub stars: 815
- Agent Sqli HunterSQL Injection specialist (H1 #67). Use for error-based, blind boolean, blind time-based, UNION-based, and out-of-band SQLi testing. Provide target endpoints with injectable parameters.Votes: 0GitHub stars: 815
- Agent Ssrf HunterSSRF vulnerability hunting specialist. Use for testing URL-accepting parameters, webhook endpoints, file import features, and any server-side request functionality. Provide target endpoints with URL parameters.Votes: 0GitHub stars: 815
- Agent Ssti HunterServer-Side Template Injection specialist. Covers Jinja2 (H1 #74), Twig, Velocity, FreeMarker, ERB, Handlebars, Thymeleaf. Use for any rule-engine, comment/message rendering, PR automation, admin template, or user-customizable template surface. Systematic blocklist mapper + CVE bypass runner + runtime-vs-parse distinguisher.Votes: 0GitHub stars: 815
- Agent Subdomain TakeoverSubdomain Takeover specialist (H1 #145). Use for finding dangling DNS records pointing to unclaimed cloud resources, expired services, or deprovisioned infrastructure.Votes: 0GitHub stars: 815
- Agent ValidatorFinding validator. Runs 7-Question Gate + 4-gate checklist. Kills weak/theoretical findings FAST before any report writing. Output: PASS, KILL, DOWNGRADE, or CHAIN REQUIRED.Votes: 0GitHub stars: 815
- Agent Vuln ScannerAutomated vulnerability scanning agent. Use for running nuclei templates, nikto scans, SSL/TLS analysis, header checks, and known CVE detection against targets. Provide target URL or list and scan profile: 'quick' for top vulns, 'standard' for common checks, 'thorough' for deep scanning.Votes: 0GitHub stars: 815
- Agent Waf ProfilerWAF fingerprinting and behavior mapping specialist. Use to identify the WAF, map its blocking rules, find bypass techniques, and document WAF behavior for other agents. Always run this before xss-hunter or injection testing on WAF-protected targets.Votes: 0GitHub stars: 815
- Agent Web3 AuditorSmart contract and Web3/DeFi security auditor. Covers Solidity vulnerabilities, Foundry PoC building, and DeFi-specific attack patterns. Use for Immunefi, Code4rena, and other Web3 bug bounty programs.Votes: 0GitHub stars: 815
- Agent Xss HunterXSS specialist covering reflected (H1 #60), stored (H1 #61), and DOM (H1 #62). Dispatcher passes subtype — 'reflected', 'stored', or 'dom' — in the task; falls back to inference from target. Use for parameter reflection, persisted inputs (comments/profiles/uploads/filenames), or client-side source→sink analysis.Votes: 0GitHub stars: 815
- Agent Xxe HunterXXE specialist (H1 #63). Use for testing XML parsing endpoints, file upload processors, SOAP services, SVG handlers, and any feature accepting XML input.Votes: 0GitHub stars: 815
- Cmd AnalyzeAnalyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>Votes: 0GitHub stars: 815
- Cmd AutopilotAutonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying questions, no auxiliary-agent substitution. Usage: /autopilot target.com [--interactive|--autonomous] [--20m-off] [--resume]Votes: 0GitHub stars: 815
- Cmd BrainManage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.Votes: 0GitHub stars: 815
- Cmd ChainBuild deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)Votes: 0GitHub stars: 815
- Cmd CorrelateRun the finding correlation engine to discover attack chains from individual findings.Votes: 0GitHub stars: 815
- Cmd CostShow cost tracking and ROI for this engagement.Votes: 0GitHub stars: 815
- Cmd DupcheckCheck if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g. /dupcheck XSS in search endpointVotes: 0GitHub stars: 815
- Cmd FullscanFull security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.Votes: 0GitHub stars: 815
- Cmd HuntActive vulnerability hunting on a target. Loads scope, reads brain, detects tech stack, runs targeted tests with concrete payloads. Usage: /hunt target.com [--vuln-class idor|xss|ssrf|sqli|ssti|oauth|rce|race|graphql|upload|business-logic|llm-ai]Votes: 0GitHub stars: 815
- Cmd LearnRecord a platform response and update learning. Usage: /learn <report_id> <status> [--bounty 500] [--vuln-type XSS]Votes: 0GitHub stars: 815
- Cmd MindmapGenerate a text-based attack surface mindmap. Shows tech stack → vuln class → endpoint relationships. Usage: /mindmap <target>Votes: 0GitHub stars: 815
- Cmd MonitorMonitor targets for changes. Usage: /monitor baseline (first run), /monitor check (detect changes), /monitor scope (check platform for scope updates)Votes: 0GitHub stars: 815
- Cmd NewCreate a new engagement workspace. Usage: /new <platform> <program> [--type web-app|api|mobile|smart-contract]Votes: 0GitHub stars: 815
- Cmd PipelinePrepare the battlefield — recon, scanning, and surface ranking. Stops before hunting. Run /hunt or /autopilot after. Usage: /pipeline or /pipeline <target>Votes: 0GitHub stars: 815
- Cmd QualityScore a report draft before submission. Usage: /quality <draft-path-or-finding-description>Votes: 0GitHub stars: 815
- Cmd QuickscanRun a quick security scan on a target. Consults the Brain first, validates scope, runs passive recon + vuln scan in parallel.Votes: 0GitHub stars: 815
- Cmd RememberLog a finding or pattern to persistent brain memory. Auto-fills from session context. Usage: /rememberVotes: 0GitHub stars: 815
- Cmd ReportGenerate submission-ready reports for all confirmed findings. Runs dedup, PoC builder, quality check, and report writer. Usage: /report bounty or /report pentestVotes: 0GitHub stars: 815
- Cmd ResumeResume a previous hunt. Shows hunt history, untested endpoints, memory-informed suggestions. Usage: /resume target.comVotes: 0GitHub stars: 815
- Cmd SastSource code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: /sast <repo_path> [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30] [--skip-static] [--best-of N]Votes: 0GitHub stars: 815
- Cmd StatusShow engagement dashboard with program info, scope, brain state, findings, agent activity, and cost estimate.Votes: 0GitHub stars: 815
- Cmd SubmitDraft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review.Votes: 0GitHub stars: 815
- Cmd SurfaceShow ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.comVotes: 0GitHub stars: 815
- Cmd SyncSync program scope, policy, and hacktivity from a bug bounty platform. Usage: /sync hackerone tesla or /sync bugcrowd uberVotes: 0GitHub stars: 815