# Encod3d-Sec

> Open-source publisher. Listings imported from github.com/Encod3d-Sec — credited to the original author with their license.

- **Listings:** 49
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/encod3d-sec
- **Website:** https://github.com/Encod3d-Sec

## Published listings

- [Hunt Bizlogic](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-bizlogic) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-bizlogic`
  Business-logic flaw hunting - workflow/state bypass, price/quantity tampering, negative/overflow values, coupon/refund abuse, mass assignment, and logic races. The top-paying bug class with no scanner coverage. Wiki-first, FIND schema output.
- [Hunt Idor](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-idor) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-idor`
  >
- [Hunt Cloud](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-cloud) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-cloud`
  Cloud attack hunting for AWS / Azure / GCP - credential discovery, metadata SSRF, IAM privesc, service enumeration, persistence. Scope + billing aware. Wiki-first, FIND schema output.
- [Hunt Vpn](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-vpn) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-vpn`
  Enterprise SSL VPN attack - vendor fingerprinting, CVE matrix (Cisco, Fortinet, Citrix, Palo Alto, Pulse/Ivanti), default credentials, pre-auth exploit commands. Wiki-first, FIND schema output.
- [Hunt Cicd](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-cicd) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-cicd`
  CI/CD pipeline attack hunting (GitHub Actions focus) - pwn requests (pull_request_target), script injection, self-hosted runner takeover, cache poisoning, OIDC-to-cloud token theft, poisoned pipeline execution. Wiki-first, FIND schema output.
- [Hunt Injection](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-injection) — Skill · Free — `agentstack add skill-encod3d-sec-torch-hunt-injection`
  GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE. OOB-mandatory for blind XXE. Wiki-first, FIND schema output.
- [Hunt Mcp](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-mcp) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-mcp`
  MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. Wiki-first, FIND schema output.
- [Hunt Sqli](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-sqli) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-sqli`
  SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection. sqlmap automation after manual confirmation. Wiki-first, FIND schema output.
- [Hunt Federation](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-federation) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-federation`
  OAuth and SAML attack hunting - redirect_uri bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. Wiki-first, FIND schema output.
- [Hunt Upload](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-upload) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-upload`
  File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS. Wiki-first, FIND schema output.
- [Hunt M365](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-m365) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-m365`
  Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC validation, Conditional Access mapping. Wiki-first, FIND schema output.
- [Hunt Ad](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-ad) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-ad`
  Active Directory attack hunting - enumeration to domain dominance. Spray-safe (lockout gate), AS-REP/Kerberoast, ACL + ADCS (ESC1-16), delegation, DCSync, lateral movement. Wiki-first, FIND schema output.
- [Wiki](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-wiki) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-wiki`
  Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status.
- [Ctf Category](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-ctf-category) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-ctf-category`
  CTF challenge router - fingerprint a challenge (file type / prompt / artifacts) into its category (pwn, rev, crypto, forensics, stego, web, osint, hash) and route to the matching wiki page, tools, and first moves. Wiki-first.
- [Hunt Xss](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-xss) — Skill · Free — `agentstack add skill-encod3d-sec-torch-hunt-xss`
  XSS hunting - reflected, stored, DOM-based. Marker discipline to avoid false positives. Blind-XSS beacons for stored contexts. SVG/markdown/redirect vectors. Wiki-first, FIND schema output.
- [Hunt Auth](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-auth) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-auth`
  Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /_vti_bin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation. Wiki-first, FIND schema output.
- [Coverage](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-coverage) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-coverage`
  Show per-asset vuln-class coverage gaps for the active engagement so nothing in scope is skipped. Use when asked "coverage", "what haven't we tested", "test gaps", "are we thorough", or before calling an engagement done.
- [Hunt Macos](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-macos) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-macos`
  macOS attack hunting - foothold to root/persistence on a macOS host. TCC/Gatekeeper/SIP bypass, keychain + credential loot, code-signing/entitlements abuse, XPC/dylib/library injection, launch-constraint evasion, MDM/installer abuse. Wiki-first, FIND schema output.
- [Hunt Api](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-api) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-api`
  API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. OWASP API Top 10. Wiki-first, FIND schema output.
- [Pt Workflow](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-pt-workflow) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-pt-workflow`
  Autonomous pentest campaign driver. Runs a scoped engagement end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (Skill + tool) every turn. Use when starting or resuming a pentest, "run the pt workflow", "work this CIDR/domain", or when handed a client SoW/scope to reach…
- [Evidence](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-evidence) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-evidence`
  Evidence hygiene before any FIND moves to Completed or enters a report. Cookie redaction, PII black-bar, HAR sanitization, screenshot metadata strip. Run after /triage passes and before final report assembly.
- [Hunt Rce](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-rce) — Skill · Free — `agentstack add skill-encod3d-sec-torch-hunt-rce`
  RCE hunting - template injection, YAML/XML deserialization, dependency confusion, Kubernetes surfaces, CVE-specific exploits (Apache CVE-2021-41773, Spring CVE-2022-22963). OOB-mandatory for blind cases. Wiki-first, FIND schema output.
- [Hunt Ssrf](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-ssrf) — Skill · Free — `agentstack add skill-encod3d-sec-torch-hunt-ssrf`
  SSRF hunting - OOB-mandatory methodology. Cloud metadata, blind SSRF via Collaborator/interactsh, redirect-based bypass, headless browser chains. Wiki-first, FIND schema output.
- [Bb Workflow](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-bb-workflow) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-bb-workflow`
  Autonomous bug-bounty campaign driver. Runs a full programme end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (including which Skill and tool to run) every turn. Use when starting or resuming a bug-bounty engagement, "run the bb workflow", "hunt this program", "9-pass…
- [Delegate](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-delegate) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-delegate`
  Autonomous sub-agent hand-off for a fiddly, fully-specified exploit-compile / escalation RUN - the main agent stays on strategy and the board while a cheap sub-agent runs an exact copy-paste checklist behind a false-root/hostname guardrail. Use for "delegate", "offload", "hand this to a sub-agent", "spin a haiku", or the moment a foothold plus a working escalation vector is identified. Main agent…
- [Nday](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-nday) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-nday`
  N-day / patch-diff workflow - given a CVE/advisory or a suspicious patch, diff pre- vs post-patch to locate the fixed bug, build a PoC for the unpatched version, and run variant analysis for a fresh bug. Triggers - "n-day", "patch diff", "diff the patch", "bindiff".
- [Redteamlead](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-redteamlead) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-redteamlead`
  On-demand senior red-team lead advisor. Call at a decision point or obstacle to get wiki-grounded direction instead of hammering blindly. Dispatches a fresh RTL subagent that reads the engagement state + evidence + wiki and returns ranked directions with an explicit STOP. Use for "redteamlead", "RTL", "I'm stuck", "where do I go", "what next", "which vector", "should I keep hammering this".
- [Hunt Llm](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-llm) — Skill · Free — `agentstack add skill-encod3d-sec-torch-hunt-llm`
  LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage. OWASP LLM Top 10. Wiki-first, FIND schema output.
- [Hunt Core](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-core) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-core`
  >
- [Disclosure](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-disclosure) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-disclosure`
  Drive responsible disclosure of a proven finding to a CVE. Package the report, find the vendor contact, report privately, coordinate a timeline, request the CVE (vendor CNA / GitHub / MITRE), and publish an advisory. Closes the research loop. Triggers - "disclose", "request a cve", "report this to the vendor".
- [Hunt Deserialization](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-deserialization) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-deserialization`
  Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node. Gadget-chain RCE, OOB-gated blind detection, magic-byte fingerprinting. Wiki-first, FIND schema output.
- [Arsenal](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-arsenal) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-arsenal`
  Wiki-first "what do I use" lookup - pick the automated TOOL (wiki/tools/), then the PAYLOAD/technique (wiki/payloads/ + wiki/cheatsheets/), for a surface/service/vuln-class BEFORE hand-rolling or working from memory. Use for "tool for <service>", "automated tools for web/<service>", "what should I run on <surface>", "which tool for <X>", "payloads for <X>", "payload arsenal", "cheatsheet for <X>"…
- [Hunt Ics](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-ics) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-ics`
  ICS/SCADA/OT exploitation - Modbus (502), S7comm (102), EtherNet/IP (44818), DNP3, OpenPLC, Node-RED SCADA, PLC/HMI/coil/holding-register attacks. Use when a target exposes industrial protocols or the goal is to drive a plant to a dangerous state (over-pressure/over-speed/disable interlock) and read the flag the HMI/CCTV reveals.
- [Learn](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-learn) — Skill · Free — `agentstack add skill-encod3d-sec-torch-learn`
  Post-engagement knowledge harvest AND harness retrospective - after a box/bugbounty/pentest/CTF is completed, first diff how the engagement was EXECUTED against the skills/hooks that governed it (what discipline was skipped) and improve the harness, then sweep the whole engagement for GENERIC reusable knowledge NOT already in wiki/ and land it via the leak-gated stage->promote pipeline. Use at cl…
- [Hunt Burp](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-burp) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-burp`
  Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe), then hand off to the matching vuln-class hunt. Wiki-first, FIND schema output.
- [Hunt Windows](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-windows) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-windows`
  Local Windows privilege escalation on a STANDALONE / workgroup host, or a local shell on a domain member - foothold to SYSTEM. Token privileges (SeImpersonate/Potato), service misconfig (weak perms / unquoted path / writable binary), registry autologon creds, scheduled-task + writable-script abuse, DLL hijack, AlwaysInstallElevated, UAC bypass, credential loot. For DOMAIN escalation (kerberoast/D…
- [Fuzz](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-fuzz) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-fuzz`
  Adaptive, targeted web fuzzing - deterministic wordlist selection (wl-pick.sh) plus judgment. Picks the right SecLists list per surface (content/vhost/api/params/artifacts) smallest-first, calibrates filters against soft-404s, recurses, escalates T0 harness -> T1 seclists -> T2 cewl -> T3 app-specific on signal, pivots to hidden-param fuzzing, and detects/handles WAF/Cloudflare/throttle (backoff,…
- [Ctf Workflow](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-ctf-workflow) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-ctf-workflow`
  Autonomous CTF / boot-to-root campaign driver. Runs a box end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (Skill + tool) every turn. Use when handed a box/IP to own end to end, "run the ctf workflow", "root this box", "foothold to root". Single agent, wiki-first, tool…
- [Metasploit](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-metasploit) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-metasploit`
  Drive msfconsole across the workflow - DB-backed recon (db_nmap, auxiliary scanners), version->exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shell_reverse_tcp backup for Windows/EDR), sessions + local_exploit_suggester + post modules, and autoroute/portfwd/socks pivoting. Points to the metasploit cheatsheet for syntax. Use for "metasploit", "msfconsole", "msfven…
- [Hunt Cache](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-cache) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-cache`
  Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking. Wiki-first, FIND schema output.
- [Next Move](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-next-move) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-next-move`
  Ranked next offensive moves from engagement state. Reads state/loot/Killchain, runs the deterministic analyzer, elaborates the top move. Use when asked "what next", "where to focus", "prioritize", or at the start of an engagement session.
- [Ingest](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-ingest) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-ingest`
  Synthesize raw recon/test output into engagement state. Reads everything dropped in targets/<active>/ingest/, extracts hosts/assets/creds/paths, merges into state.md/loot.md/Killchain.md, logs it, archives the raw files. Works for pentest, bugbounty, and ctf. Use when asked to "ingest", "synthesize findings", "process recon", or after dropping tool output in the ingest folder.
- [Hunt Smuggling](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-smuggling) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-smuggling`
  HTTP request smuggling / desync hunting - CL.TE, TE.CL, TE.TE, CL.0, and HTTP/2 downgrade. Timing-based detection, differential confirmation, no-blind-claims. Wiki-first, FIND schema output.
- [Ctf Box](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-ctf-box) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-ctf-box`
  Boot-to-root methodology for a full machine (THM/HTB/PG/CTF box, "get user.txt+root.txt", "root the box", "foothold to root"). Enforces basic-tool recon (nmap, nc, ffuf, nuclei, dig) before anything custom, wiki-first lookups, and ALWAYS pspy + linpeas/winpeas for privesc. Use when handed a box/IP to own end-to-end.
- [Campaign Health](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-campaign-health) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-campaign-health`
  Health check for the bb/pt/ctf workflow driver subsystem - verifies everything is in place so every machine runs the same. Checks vault-content consistency (scripts present, JSON valid, routing wired, all 69 tool pages carry phase:, the tool index resolves, the hook edits are in place) AND per-machine wiring (the three workflow skills symlinked, hooks registered, imports work), then runs a live i…
- [Chrome Devtools Browser](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-chrome-devtools-browser) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-chrome-devtools-browser`
  Bring up a REAL, visible, interactive chromium on the Kali VM that the operator logs into (Smart-ID / Mobile-ID / any manual auth or MFA/CAPTCHA), while the agent drives and observes it live through the chrome-devtools MCP (navigate, DOM snapshot, network capture, screenshots, console, evaluate). Use whenever a target needs a MANUAL login the agent cannot complete headlessly, when you need to cap…
- [Research](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-research) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-research`
  Vulnerability-research loop toward a novel CVE. Target triage -> attack-surface map -> ranked hypotheses -> investigate (RE / fuzz / audit) -> a finding deepens the loop, a dead-end pivots to a new approach. Uses the full wiki + hunt skillset. Scaffolds and persists state under raw/research/<project>/. Triggers - "research", "find a cve", "analyze this binary/library", "audit this code for vulns".
- [Screenshot Burp](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-screenshot-burp) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-screenshot-burp`
  Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng>/poc/) by driving the Burp MCP + the Kali GUI. Replays a request in a Repeater tab, sends it, and grabs the request+response panes - a Burp-native PoC (client report / CTF writeup). Use when you want the evidence to come from Burp rather than a curl/terminal card, or whenever you drive a target through Burp and need the i…
- [Hunt Secrets](https://agentstack.voostack.com/l/skill-encod3d-sec-torch-hunt-secrets) — Skill · Free · security-reviewed — `agentstack add skill-encod3d-sec-torch-hunt-secrets`
  Exposed-secrets hunting - .git/ dir + history mining, exposed .env/config files, hardcoded keys in JS bundles + source maps, S3/blob exposure, public-repo secret search, CI/CD leakage. Live-validation mandatory. Wiki-first, FIND schema output.

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
