Vulnerability Scanning
-
zhaoxuya520 Bundle Ot IcsAuthorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
12.8k -
zhaoxuya520 Bundle Code AuditPerforms authorized source-code security reviews using SAST tools like Semgrep and CodeQL, with manual verification of findings and fix recommendations.
12.8k -
zhaoxuya520 Bundle Ida ReverseProvides a complete workflow for IDA Pro reverse engineering of binaries (PE, ELF, APK, DLL, SO, firmware) using bundled PowerShell scripts to manage the MCP server and open files, then leverages 72 MCP tools for survey, decompilation, cross-references, data-flow tracing, patching, and reporting.
12.8k -
zhaoxuya520 Bundle Edr Bypass ReReverse-engineers EDR, Defender, and AV hook tables, ETW providers, and AMSI implementations to build targeted bypasses including unhooking, indirect syscalls, ETW patching, and call stack spoofing for authorized red team operations.
12.8k -
zhaoxuya520 Bundle Dotnet ReverseProvides a structured workflow for reverse engineering .NET and C# binaries, including deobfuscation with de4dot, static analysis via dnSpyEx IL view, dynamic debugging, and reliable IL patching for red-team tools and malware.
12.8k -
zhaoxuya520 Bundle Go Rust ReverseReverse engineers stripped Go and Rust binaries by recovering runtime metadata, symbols, panic strings, and idiomatic decompilation patterns.
Audited 12.8k -
zhaoxuya520 Bundle Identity FederationAuthorized assessment of federated identity systems covering SAML, OIDC, and OAuth2 flows, SSO misconfigurations, and token confusion issues.
12.8k -
wpeace-hch Bundle Wpegpt AnalyzerAutomates reverse engineering of PE and ELF binaries by driving IDA with the WPeGPT plugin, producing structured reports on program purpose, network IoCs, suspicious functions, and vulnerability assessment.
93 -
agentskillexchange Skill Rust Crate AnalyzerFetches crate metadata from crates.io and docs.rs APIs for Rust package discovery, and analyzes feature flags, dependency audits via RustSec Advisory DB, and MSRV compatibility.
28 -
agentskillexchange Skill NPM Package AnalyzerAnalyzes npm packages by fetching registry metadata, evaluating bundle size via the bundlephobia API, checking security advisories with npm audit, and mapping dependency trees using arborist.
28 -
tinh2 Skill OwaspSystematically audits a web application against the OWASP 2021 Top 10, producing severity-rated, file-level findings with fixes for each category.
13 -
nimoqup046-collab Skill Find BugsReviews local branch changes for bugs, security vulnerabilities, and code quality issues, using a structured checklist and verification process.
Audited 2 -
sakamoto-family-smile Skill Security ScanAudits Claude Code configuration files for security vulnerabilities, misconfigurations, and injection risks using AgentShield, covering CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions.
0 -
sakamoto-family-smile Skill Laravel SecurityHardens Laravel applications against common vulnerabilities with guidance on authentication, authorization, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
Audited 0 -
sakamoto-family-smile Skill Defi Amm SecurityProvides a security checklist and hardened Solidity patterns for auditing AMM contracts, liquidity pools, and swap flows, covering reentrancy, CEI ordering, donation attacks, oracle manipulation, slippage, admin controls, and integer math.
Audited 0 -
pwdev-solucoes Skill Docker SpecialistOtimiza imagens Docker com multi-stage builds, reduz tamanho, acelera builds e aplica práticas de segurança, incluindo análise de vulnerabilidades com Trivy.
2 -
mhassan0000 Skill Repo ScanAudits source code across C++, Android, iOS, and Web to classify files, detect embedded third-party libraries, and produce four-level verdicts with interactive HTML reports.
1 -
galyarderlabs Bundle SecurityAssess cloud configuration risks including IAM privilege escalation, public storage exposure, network over-permissioning, and infrastructure-as-code misconfigurations.
20 -
cloudthinker-ai Skill AWS GuarddutyAnalyze AWS GuardDuty findings, detectors, suppression rules, and member accounts with parallel execution and anti-hallucination guardrails.
Audited 7 -
vikingokft Skill Wp Security SecretsAudits WordPress plugin and theme code for secret-handling issues: hardcoded credentials, weak randomness, insecure password storage, cookie flags, and secret leakage in logs.
Audited 0 -
phoroth Bundle 007Runs a structured 6-phase security audit covering attack-surface mapping, STRIDE/PASTA threat modeling, technical checklists, red/blue team exercises, and a final verdict, plus incident-response and monitoring playbooks.
3 -
lucaspmarie-a11y Bundle 007Runs security audits, threat modeling, and hardening for code and infrastructure, covering OWASP checks, code review, incident response, and red/blue team exercises.
5 -
lucaspmarie-a11y Skill Find BugsReviews local branch changes for bugs, security vulnerabilities, and code quality issues, producing a prioritized report with severity ratings and concrete fixes.
Audited 5 -
shulkwisec Skill CsptHunt Client-Side Path Traversal vulnerabilities where attacker-controlled input is concatenated into the path of a fetch() or XHR request, enabling redirection and chaining to XSS or data exfiltration.
Audited 21 -
zhaoxuya520 Bundle Reverse Skill RouterRoutes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear.
12.8k -
zhaoxuya520 Bundle Radio SdrGuides authorized RF/SDR security research for signal identification, demodulation analysis, and replay feasibility studies in shielded lab environments.
12.8k -
zhaoxuya520 Bundle Binary DiffMigrates symbols and reverse-engineering results from an older binary version to a newer one using LLM-based structured diffing of disassembly and pseudocode, enabling rapid offset and function-name mapping when PDBs are missing.
Audited 12.8k -
zhaoxuya520 Bundle Thick ClientAuthorized security testing framework for desktop thick clients covering local storage, IPC, update channels, traffic interception, and client-side trust boundaries.
12.8k -
zhaoxuya520 Bundle Threat HuntingGuides blue-team threat hunting and detection engineering with hypothesis-driven workflows, Sigma/YARA rule creation, SIEM query design, and validation using Atomic Red Team in authorized environments.
12.8k -
zhaoxuya520 Bundle Database SecurityPerforms authorized database security assessments across PostgreSQL, MySQL, MSSQL, MongoDB, and Redis, checking exposure, authentication, authorization, dangerous configurations, and exploit paths.
12.8k -
zhaoxuya520 Bundle Patch Diff ExploitAnalyzes vendor security patches via binary diffing to reverse-engineer vulnerabilities, write proof-of-concept exploits, and weaponize N-day exploits against unpatched systems.
12.8k -
zhaoxuya520 Bundle Browser Extension ReverseGuides authorized reverse engineering of Chrome and Firefox browser extensions, covering manifest analysis, background workers, and credential or traffic logic recovery.
12.8k -
agentskillexchange Skill Snyk Agent ScanScans AI agents, MCP servers, and skills for security vulnerabilities from the command line, detecting prompt injections, tool poisoning, toxic flows, malware payloads, and credential handling issues across 15+ risk categories.
28 -
agentskillexchange Skill Owasp Zap ScannerRuns OWASP ZAP security scans against web applications using Java or Docker, with setup guidance and links to upstream documentation.
Audited 28 -
agentskillexchange Skill Checkov Iac ScannerScans infrastructure-as-code files for security and compliance misconfigurations using Checkov, with support for Terraform, Kubernetes, and other formats.
Audited 28 -
agentskillexchange Skill Csp Policy AnalyzerParses and evaluates Content Security Policy headers using csp-parse and csp-evaluator libraries. Identifies overly permissive directives, missing protections, and generates tightened policy recommendations.
Audited 28