# SecurityTalent

> Open-source publisher. Listings imported from github.com/SecurityTalent — credited to the original author with their license.

- **Listings:** 16
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/securitytalent
- **Website:** https://github.com/SecurityTalent

## Published listings

- [Jsa](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-jsa) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-jsa`
  A Claude skill from SecurityTalent/bugskill-ai.
- [Osint Enrich](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-osint-enrich) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-osint-enrich`
  A Claude skill from SecurityTalent/bugskill-ai.
- [JsAnalyzer](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-jsanalyzer) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-jsanalyzer`
  Static analysis for JavaScript files targeting security vulnerabilities. USE WHEN user says 'analyze js', 'scan javascript', 'find sinks', 'js security', 'analyze these js files', OR user starts Claude in a folder with JS files and wants security analysis. Extracts URLs, paths, sources, sinks, postMessage handlers, secrets, and more.
- [BugBountyWorkflow](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-bugbountyworkflow) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-bugbountyworkflow`
  Bug bounty hunting workflow and report writing expertise. USE WHEN user mentions bug bounty, vulnerability report, HackerOne, Bugcrowd, PoC creation, severity assessment, CVSS scoring, responsible disclosure, or needs help writing security reports. Provides templates and workflow guidance.
- [AsnRecon](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-asnrecon) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-asnrecon`
  ASN and IPv4 range reconnaissance using bgp.he.net. USE WHEN user mentions ASN lookup, find IP ranges, company IP space, BGP reconnaissance, owned IP addresses, network footprint, OR wants to discover what IP ranges a company owns. Searches bgp.he.net free-form, extracts ASNs and IPv4 prefixes.
- [SubdomainEnum](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-subdomainenum) — Skill · Free — `agentstack add skill-securitytalent-bugskill-ai-subdomainenum`
  Subdomain enumeration with Light and Full workflows, plus intelligent target prioritization. USE WHEN user mentions subdomain enumeration, find subdomains, subdomain recon, recon, reconnaissance, quick subdomain scan, fast recon, full recon, prioritize targets, OR wants to enumerate attack surface. Light = subfinder only (fast). Full = all tools (comprehensive). Both include optional prioritized…
- [Otp Bruteforce Testing](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-otp-bruteforce-testing) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-otp-bruteforce-testing`
  Detect, validate, and exploit OTP (one-time password) brute-force vulnerabilities in phone/email verification, MFA, password-reset, and transaction-confirmation flows. Use when a target issues numeric one-time codes (4-8 digits via SMS/email), when OTP verification endpoints appear unthrottled, when reviewing authentication or account-recovery code, or when assessing rate limiting on verification…
- [Pulse Template](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-pulse-template) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-pulse-template`
  A Claude skill from SecurityTalent/bugskill-ai.
- [403Bypass](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-403bypass) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-403bypass`
  Automated 403 Forbidden bypass testing using Jason Haddix's techniques. USE WHEN you encounter 403 responses during recon, content discovery returns 403 paths, or user mentions 403 bypass, forbidden bypass, access control bypass, or WAF bypass.
- [Crawl](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-crawl) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-crawl`
  Deep web crawling using hakrawler and gospider for subdomain discovery, endpoint extraction, and JavaScript analysis. Use this skill when users request to crawl URLs, discover subdomains, extract endpoints, map web applications, or perform reconnaissance tasks. All outputs (categorized results, bash logs, summaries) are saved to timestamped folders with format crawl_{DOMAIN}_{timestamp}.
- [ApexDiscovery](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-apexdiscovery) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-apexdiscovery`
  Comprehensive apex/root domain discovery using multiple techniques. USE WHEN user mentions find related domains, apex domains, root domains, company domains, acquisitions, subsidiary domains, reverse whois, domain footprint, OR wants to discover all domains owned by an organization before subdomain enumeration.
- [Url Parser Confusion Testing](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-url-parser-confusion-testing) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-url-parser-confusion-testing`
  Detect SSRF filter bypasses and URL-parsing inconsistencies caused by malformed URL syntax — triple-slash (http:///host/path), backslashes, encoded delimiters, userinfo, numeric IP forms, IPv4-mapped IPv6. Use when reviewing URL validation, hostname allowlists, SSRF protections, redirect handling, or any code that parses user-supplied URLs (curl/libcurl CURLU, WHATWG URL, Python urllib, Node, Go,…
- [Stack Bounds Format Auditing](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-stack-bounds-format-auditing) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-stack-bounds-format-auditing`
  Detect, audit, and validate stack buffer overflows caused by incorrect bounds arithmetic in string formatting and memory copy operations (snprintf, swprintf, sprintf, strncpy, memcpy) writing into fixed stack buffers where the size argument is not decremented as the destination pointer advances. Use when auditing C/C++ network protocol serializers, URL/URI builders, message formatters, IPC serial…
- [CacheDeception](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-cachedeception) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-cachedeception`
  Web cache deception and poisoning exploitation. USE WHEN user mentions cache deception, cache poisoning, CDN bypass, URL parsing discrepancy, path confusion, static extension bypass, or cache key manipulation. Based on Martin Doyhenard's "Gotta Cache 'em all" research.
- [TabletopExercise](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-tabletopexercise) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-tabletopexercise`
  Comprehensive cybersecurity tabletop exercise design and facilitation framework. USE WHEN designing incident response scenarios, creating executive or technical tabletops, generating atomics for exercise runners, identifying missing SOPs/playbooks, or evaluating organizational preparedness. Includes threat model integration, CISA-aligned methodologies, and automated gap analysis.
- [Bac Analyzer](https://agentstack.voostack.com/l/skill-securitytalent-bugskill-ai-bac-analyzer) — Skill · Free · security-reviewed — `agentstack add skill-securitytalent-bugskill-ai-bac-analyzer`
  Passive traffic analyzer that examines captured HTTP traffic (HAR, Caido JSON, Burp XML) to identify potential Broken Access Control (BAC) and Insecure Direct Object Reference (IDOR) vulnerabilities. USE WHEN user mentions analyze traffic, check for IDOR, BAC analysis, analyze HAR, analyze Caido, broken access control, or IDOR scan.

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
