Pentest Commands
Provide a comprehensive command reference for penetration testing tools including network scanning, exploitation, password cracking, and web application testing. Enable quick command lookup during security assessments.
Attack Chain Web3
Web3 attack chain plugin — apply Web3 state, economic, cryptographic, and consensus semantics on top of attack-chaining-core for authorized testing of smart contracts, DeFi, bridges, wallets, and validators.
Evidence Packager
Assemble a reproducible, minimal, tamper-evident evidence bundle for a security finding, preserving provenance and separating observed facts from interpretation.
Html Injection Testing
Identify and exploit HTML injection vulnerabilities that allow attackers to inject malicious HTML content into web applications. This vulnerability enables attackers to modify page appearance, create phishing pages, and steal user credentials through injected forms.
Meme Coin Audit
Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich amplification, LP drain, bonding curve exploits), pump.fun/Raydium/Jupiter integration risks, token…
Web Exploit Test
Localhost-only, stdlib evidence verifier: scan, JWT matrix, race controls.
Attack Surface Mapper
Build an evidence-backed map of externally and internally reachable attack surfaces, trust boundaries, privileged transitions, security assets, and high-value audit targets before vulnerability hunting.
Burp Suite Testing
Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows.
Linux Privilege Escalation
Execute systematic privilege escalation assessments on Linux systems to identify and exploit misconfigurations, vulnerable services, and security weaknesses that allow elevation from low-privilege user access to root-level control.
Privilege Escalation Methods
Provide comprehensive techniques for escalating privileges from a low-privileged user to root/administrator access on compromised Linux and Windows systems. Essential for penetration testing post-exploitation phase and red team operations.
Code Injection Detector
|
Encrypting And Decrypting Data
Validate encryption implementations and cryptographic practices. Use when reviewing data security measures. Trigger with 'check encryption', 'validate crypto', or 'review security keys'.
Pentest Checklist
Provide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities.
Bb Methodology
Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other skills based on current hunting phase. Also use when asking "what should I do next"…
Open Kritt
>
Threads Auto Post
Threads affiliate auto-post: v19 — Browserless HTTP primary + Shopee buyer-review 5★+media HD + Pinterest fallback + 1-post=1-link forever. Content CERITA/TIPS Viewbait v5: post_1 first line ALL CAPS + total ≥210 chars. Cron no_agent=true, script_timeout≥900, THREADS_ALLOW_UI_FALLBACK=0. See references/viewbait-v5-and-cron-timeout-fix.md. Triggers: post threads, review image, caption/hook, provid…
Web2 Vuln Classes
Complete reference for 24 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic, race conditions, OAuth/OIDC, file upload (10 bypass techniques), GraphQL, LLM/AI (ASI01-ASI10 agentic framework), API misconfig (mass assignment, JWT attacks, prototype pollu…
Threads Auto Reply
Threads affiliate auto-reply. v10 stealth: 9router LLM + burst-rest scheduler + sleep window + log-normal delay. See refs/stealth-v10-architecture.md, refs/9router-model-selection.md, refs/moderation-false-positives.md, scripts/threads_human_behavior.py, scripts/threads_content_gen.py. v9 templates fallback. Triggers: 'reply threads', 'komen threads', 'nimbrung'.
Report Writing
Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use "could potentially" — prove it or don't report.
Forensics Data Collector
|
Bughunter Os
Complete bug bounty hunting & smart contract audit operating system. 8-phase methodology + 5 knowledge bases (attack patterns, real-world exploits, protocol playbooks, orchestrator) covering 340+ files. Use when starting a new audit, hunting bugs in DeFi protocols, building PoC exploits, writing reports, or analyzing smart contract attack surfaces.
Attack Chaining Core
Domain-neutral attack chain analysis — determine whether independently identified security primitives compose into a realistic, authorized, evidence-backed attack path with greater impact.
Syadagentic
A Claude skill from Sekolah76/syadagentic.
Graphql Audit
GraphQL security hunting — introspection abuse, field suggestion enumeration (clairvoyance), batching DoS, IDOR via aliasing, auth bypass, injection via arguments, subscription abuse, depth/complexity bombs, and WAF bypass. Covers graphw00f fingerprinting, gqlmap, graphql-cop, and inql. Use when a target exposes a /graphql, /api/graphql, or GQL-over-HTTP endpoint.
Triage Validation
Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer = kill the finding and move on. Saves N/A ratio.
Bug Bounty Disclosure
Skill end-to-end buat authorized/good-faith bug bounty & coordinated vulnerability disclosure ke developer atau pemilik projek — untuk SEMUA jenis bug (web, API, infra, mobile, cloud, smart contract/web3, agent/LLM), crypto maupun non-crypto. Pakai skill ini setiap kali user mau triase & verifikasi temuan, bikin PoC, NYARI kontak dev/owner (security.txt, SECURITY.md, GitHub, WHOIS, on-chain, sosm…
Memory Forensics
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.
Web2 Vuln Classes
Complete reference for 25 web2 bug classes with root causes, detection patterns, bypass tables, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic, race conditions, OAuth/OIDC (PKCE, state, alg confusion, OIDC discovery-document misconfig, Spring x-application-context leak, .env/404 differential, Kong gateway version disclosure, actuator in…
Ethical Hacking Methodology
Master the complete penetration testing lifecycle from reconnaissance through reporting. This skill covers the five stages of ethical hacking methodology, essential tools, attack techniques, and professional reporting for authorized security assessments.
Attack Chain Web2
Web2 attack chain plugin — apply Web2 trust boundaries and composition rules on top of attack-chaining-core for authorized testing of web apps, APIs, identity, cloud, and internal services.
Api Fuzzing Bug Bounty
Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.
Http2 Specific Attacks
>-
Captcha Solver
Universal local sidecar anti-bot & captcha solver (Cloudflare Turnstile, Aliyun 2.0, Arkose FunCaptcha, Akamai, BotGuard, PerimeterX, DataDome, AWS WAF, reCAPTCHA, hCaptcha).
Bug Bounty Workflow
Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-cha…
Hermes Guardrail Bypass
Bypass all Hermes non-model security guardrails (threat patterns, memory scanning, cron scanning, skill install guards). Run after every Hermes update.
Malware Analyst
Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification.
Cicd Security
CI/CD pipeline security hunting — GitHub Actions workflow injection, secret exfiltration, self-hosted runner poisoning, dependency confusion, OIDC token theft, and supply chain attacks. Covers sisakulint scanning, manual workflow analysis, and chaining CI/CD bugs into critical findings. Use when a target has public repos, GitHub Actions, CircleCI, Jenkins, or GitLab CI.
Guidelines Advisor
Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies, and evaluate testing. Provides actionable recommendations.
Exploitability Analyzer
Adversarially assess whether a verified bug primitive can be exercised by a realistic attacker in production and produce the claimed security impact with measurable reliability.
Cosmos SDK + EVM chain audits: see references/cosmos-sdk-chain-audit.md
Smart contract security audit — 11 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy, BFT/consensus/liveness), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for any Solidity/Rust contract audit or when deciding whether…
Mobile Pentest
Mobile app pentest for bug bounty (Android APK + iOS IPA) — runtime-first workflow: install app, proxy through Burp/mitmproxy, drive the UI, capture packets, then test the API exactly like a web target; escalate to decompile (apktool/jadx) and Frida/objection only when traffic is SSL-pinned, encrypted, or absent. Covers APK/IPA decompile for hardcoded secrets + hidden API endpoints + base URLs th…
Credential Attack
Password spray methodology for bug bounty — when to do it vs web-vuln hunting, the wordlist-gen + breach-check + osint-employees + spray pipeline, mode selection (http-form / oauth / o365 / okta), rate-limit + lockout tactics, BBP legal guardrails, success detection, and the spray → authenticated /hunt chain pattern. Use when assessing whether credential attack is worth running on a target, picki…
Security Arsenal
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, or to check if a finding is submittable. Also use when asked about what NOT to submit.
Web2 Recon
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch). Use when starting recon on any web2 target or when asked about asset discovery, subdomai…