abelrguezr
- 861 skills
- 0 followers
- 1 week ago last updated
- ▌ Ms Access Sqli · abelrguezr bundleUse this skill whenever testing for SQL injection vulnerabilities in MS Access databases, including Jet/ACE database engines. Trigger on any mention of MS Access, .mdb files, Access database, or SQL injection testing against legacy ASP applications. This skill covers enumeration, data extraction, and advanced exploitation techniques specific to MS Access.
- ▌ CSS Injection Pentest · abelrguezr bundleCSS injection attack techniques for web security testing. Use this skill whenever the user mentions CSS injection, style injection, attribute exfiltration, blind CSS attacks, @import exfiltration, unicode-range attacks, font-based data leakage, or any CSS-based information disclosure. Trigger for pentesting tasks involving CSS vulnerabilities, XSS search via CSS, or data exfiltration through style attributes. Make sure to use this skill for any web security assessment where CSS injection vectors are suspected or confirmed.
- ▌ Cheat Engine Reversing · abelrguezr bundleUse Cheat Engine for memory analysis, value scanning, pointer finding, and code injection during game/software reversing. Use this skill whenever the user needs to find where values are stored in memory, modify runtime values, trace what writes to addresses, create persistent pointers, or inject custom code into running processes. Also use for CTF challenges, game analysis, or understanding how programs store and modify data in memory. Make sure to use this skill when the user mentions memory scanning, game hacking, reverse engineering, finding addresses, pointer scanning, or any task involving runtime memory analysis.
- ▌ Macos Mdm Research · abelrguezr bundleResearch and analyze macOS Mobile Device Management (MDM) and Device Enrollment Program (DEP) configurations, enrollment processes, and security implications. Use this skill whenever investigating MDM implementations, analyzing device enrollment flows, researching MDM attack vectors, or documenting MDM security findings. Trigger on any mention of MDM, DEP, mobile device management, configuration profiles, SCEP, or Apple device enrollment.
- ▌ Android Adb Pentesting · abelrguezr bundleAndroid ADB pentesting and device exploration. Use this skill whenever the user needs to interact with Android devices via ADB, including connecting to devices, managing packages, transferring files, capturing screens, analyzing logs, or performing backup/restore operations. Trigger for any Android device testing, mobile security assessment, or ADB command execution tasks.
- ▌ Saprouter Pentest · abelrguezr bundleHow to pentest SAProuter (port 3299) for security assessments. Use this skill whenever the user mentions SAProuter, port 3299, SAP network penetration, SAP service discovery, or needs to enumerate/exploit SAP infrastructure. This skill covers Metasploit modules, CVE-2022-27668 exploitation, Nmap fingerprinting, and hardening recommendations. Make sure to use this skill for any SAP-related penetration testing, even if the user doesn't explicitly mention 'SAProuter' but describes SAP network access or port 3299 scanning.
- ▌ Shadow Dom Xss · abelrguezr bundleHow to identify and exploit Cross-Site Scripting (XSS) vulnerabilities in Shadow DOM contexts. Use this skill whenever the user mentions Shadow DOM, web component security, encapsulated DOM attacks, or needs to test for XSS in modern web applications using Shadow DOM. Make sure to use this skill for any pentesting task involving web components, custom elements, or when analyzing applications that use Shadow DOM for encapsulation.
- ▌ Xss Sniff Leak · abelrguezr bundleHow to leak script content using MIME type sniffing vulnerabilities. Use this skill whenever the user mentions XSS, content sniffing, X-Content-Type-Options, leaking JavaScript files, MIME type attacks, or needs to extract script content from a target. Trigger for any web security testing involving script disclosure, even if the user doesn't explicitly mention 'sniffing' or 'MIME type'.
- ▌ Blobrunner · abelrguezr bundleHow to use Blobrunner to load and execute shellcode/blobs in memory for reverse engineering and malware analysis. Use this skill whenever the user needs to execute raw shellcode, analyze PE files, run binary blobs in memory, or debug shellcode execution. Also use when the user mentions shellcode execution, memory-based code execution, or needs to run compiled binaries without traditional loading.
- ▌ Pyscript Pentest · abelrguezr bundlePyScript vulnerability assessment and pentesting. Use this skill whenever the user mentions PyScript, Pyodide, browser-based Python, web application security testing, XSS in Python contexts, SSRF via Python libraries, or needs to assess PyScript implementations for security issues. Trigger for any security review, penetration testing, or vulnerability research involving PyScript or Python-in-browser technologies.
- ▌ Threat Modeling · abelrguezr bundleCreate comprehensive threat models for applications and systems using established methodologies like STRIDE, DREAD, and PASTA. Use this skill whenever the user needs to identify security vulnerabilities, assess system risks, create data flow diagrams, or document potential threats and mitigations. Trigger for any request involving security architecture review, vulnerability assessment, attack surface analysis, or security planning for software projects.
- ▌ Linux Privilege Escalation · abelrguezr bundleHow to analyze and exploit Linux privilege escalation through user ID manipulation (ruid, euid, suid). Use this skill whenever the user mentions privilege escalation, SUID binaries, setuid/setreuid/setresuid functions, execve/system calls, or needs to understand how Linux user IDs work in security contexts. Make sure to use this skill for any Linux security analysis involving user identity, privilege boundaries, or binary execution mechanisms.
- ▌ Macos Red Teaming · abelrguezr bundlemacOS red teaming and offensive security operations. Use this skill whenever the user mentions macOS penetration testing, MDM abuse (JAMF, Kandji), Active Directory attacks on macOS, keychain extraction, or any macOS-specific offensive security tasks. This includes scenarios where the user wants to enumerate macOS systems, abuse MDM configurations, extract credentials from keychains, or perform AD-based attacks from macOS hosts.
- ▌ Android Tapjacking Test · abelrguezr bundleTest Android applications for tapjacking vulnerabilities. Use this skill whenever you're doing Android app security testing, pentesting, or analyzing exported activities for clickjacking risks. Trigger when the user mentions tapjacking, clickjacking, overlay attacks, exported activities, or Android UI security testing.
- ▌ IOS App Extensions Pentest · abelrguezr bundleiOS app extension security testing. Use this skill whenever the user needs to test iOS app extensions for security vulnerabilities, analyze extension configurations, or perform static/dynamic analysis on iOS app extensions. Trigger for any iOS security testing involving app extensions, custom keyboards, share extensions, Today widgets, or extension-related security assessments. Don't wait for the user to explicitly mention "extensions" - if they're doing iOS app security testing, check for extensions.
- ▌ Network Services Pentesting Rusersd · abelrguezr bundleEnumerate usernames from hosts running the rusersd protocol (ports 512-514). Use this skill whenever you need to discover user accounts on a target system, perform network reconnaissance, or when rusersd, rusers, or RPC port mapper services are mentioned. This is a critical enumeration technique for penetration testing and security assessments.
- ▌ Couchdb Pentest · abelrguezr bundlePentest CouchDB databases on ports 5984/6984. Use this skill whenever the user mentions CouchDB, document databases, port 5984, port 6984, or needs to enumerate/exploit CouchDB instances. This includes database enumeration, credential testing, privilege escalation, and RCE exploitation.
- ▌ Fastcgi Pentesting · abelrguezr bundlePentest FastCGI services (typically port 9000) for enumeration, RCE, and SSRF exploitation. Use this skill whenever you need to test FastCGI/PHP-FPM services, probe for misconfigurations, craft FastCGI payloads for RCE, or leverage SSRF to reach internal FastCGI listeners. Trigger on mentions of FastCGI, PHP-FPM, port 9000, FPM status pages, or when you need to exploit FastCGI misconfigurations.
- ▌ Bolt Cms Pentesting · abelrguezr bundleHow to exploit Bolt CMS for Remote Code Execution (RCE) via Twig template injection. Use this skill when pentesting Bolt CMS installations, when you need to check for SSTI vulnerabilities in Bolt CMS, or when you have admin access to a Bolt CMS instance and want to escalate to RCE. This skill covers the complete exploitation chain from admin login to code execution.
- ▌ Symfony Pentest · abelrguezr bundlePentest Symfony applications - fingerprint versions, test for known CVEs (CVE-2019-18889, CVE-2025-64500, CVE-2024-51736, CVE-2025-47946, CVE-2026-24739), exploit APP_SECRET disclosure via _fragment, test PATH_INFO bypass, check for exposed .env files, debug routes, and common misconfigurations. Use this skill whenever the user mentions Symfony, PHP frameworks, web application security testing, or needs to assess a Symfony-based application (Drupal, Shopware, Ibexa, OroCRM all embed Symfony components).
- ▌ Opc Ua Pentesting · abelrguezr bundlePentest OPC UA (Open Platform Communications Unified Access) industrial control systems. Use this skill whenever the user mentions OPC UA, industrial protocols, PLCs, SCADA systems, port 4840, or wants to assess OT/ICS security. This skill covers discovery, enumeration, vulnerability assessment, and exploitation of OPC UA servers including legacy security policy attacks and CVE exploitation.
- ▌ Pentest Kibana · abelrguezr bundleHow to pentest Kibana instances on port 5601. Use this skill whenever you need to assess Kibana security, enumerate Kibana services, check for authentication bypass, explore Elasticsearch data through Kibana, or identify vulnerabilities in the Elastic Stack. Trigger this skill for any Kibana-related security assessment, port 5601 enumeration, or Elastic Stack penetration testing.
- ▌ Hsqldb Pentesting · abelrguezr bundleHow to pentest HSQLDB (HyperSQL Database) services on port 9001. Use this skill whenever the user mentions HSQLDB, port 9001, Java database exploitation, JDBC attacks, or needs to interact with HSQLDB during security assessments. This skill covers connection methods, default credentials, Java Language Routines for system property enumeration, and file writing techniques for reverse shells.
- ▌ Nfs Pentesting · abelrguezr bundlePentest NFS (Network File System) services on port 2049. Use this skill whenever the user mentions NFS, network file sharing, port 2049, showmount, nfs exports, or needs to enumerate/mount/exploit NFS shares. This skill helps with NFS enumeration, mounting shares, exploiting misconfigurations like no_root_squash, escaping export directories, and privilege escalation via NFS.
- ▌ Angular Security Audit · abelrguezr bundleSecurity audit and pentesting guide for Angular applications. Use this skill whenever you need to assess Angular app security, look for XSS vulnerabilities, check for bypassSecurityTrust misuse, audit template injection risks, test for open redirects, or review Angular security configurations. Trigger this for any Angular security review, code audit, or vulnerability assessment of Angular/TypeScript frontend applications.
- ▌ Grafana Pentest · abelrguezr bundlePentest Grafana instances for misconfigurations and CVE-2024-9264 SQL Expressions RCE/LFI vulnerability. Use this skill whenever you need to assess Grafana security, check for exposed credentials in config files, enumerate data sources, or test for the CVE-2024-9264 vulnerability that allows authenticated users to execute arbitrary commands via DuckDB shellfs extension. Trigger this skill for any Grafana security assessment, penetration test, or vulnerability scan.
- ▌ GRAPHQL Pentest · abelrguezr bundleSecurity testing for GraphQL endpoints. Use this skill whenever you need to test GraphQL APIs for vulnerabilities, enumerate schemas, detect exposed endpoints, or assess security configurations. Trigger this skill for any GraphQL security assessment, penetration testing, or API security review involving GraphQL endpoints.
- ▌ Laravel Pentest · abelrguezr bundleLaravel application security testing and exploitation. Use this skill whenever the user mentions Laravel, PHP web application pentesting, APP_KEY exploitation, cookie decryption, deserialization attacks, or any Laravel-specific vulnerability research. This skill covers APP_KEY brute-forcing, cookie forgery, RCE via gadget chains, file upload bypasses, and environment override attacks.
- ▌ Client Side Template Injection Csti · abelrguezr bundleHow to detect and exploit Client Side Template Injection (CSTI) vulnerabilities in web applications. Use this skill whenever the user mentions template injection, AngularJS, VueJS, Mavo, or wants to test for client-side code execution vulnerabilities. Also trigger when users ask about XSS via template engines, JavaScript injection through templates, or when they find double curly braces in web forms that might be processed by a template engine.
- ▌ Phar Deserialization · abelrguezr bundleHow to exploit PHP PHAR deserialization vulnerabilities. Use this skill whenever you need to test for or exploit deserialization vulnerabilities in PHP applications, especially when dealing with file inclusion via phar:// protocol, file operations like file_get_contents(), fopen(), file_exists(), md5_file(), filemtime(), or filesize(). Make sure to use this skill when you find PHP code that processes file paths with phar:// protocol or when you can control file paths in PHP applications.
- ▌ Cookie Tossing · abelrguezr bundleHow to identify and exploit cookie tossing vulnerabilities in web applications. Use this skill whenever the user mentions cookie attacks, session manipulation, subdomain cookie control, session fixation, CSRF token manipulation, or wants to test for cookie-related vulnerabilities in web security assessments. Make sure to use this skill for any pentesting task involving cookies, session handling, or subdomain security.
- ▌ Soap Threadlocal Auth Bypass · abelrguezr bundleHow to identify and exploit SOAP/JAX-WS ThreadLocal authentication bypass vulnerabilities in Java web services. Use this skill whenever the user mentions SOAP endpoints, JAX-WS handlers, authentication bypass, ThreadLocal, WebLogic, JBoss, GlassFish, or any SOAP-based Java web service security testing. Also trigger when users are investigating SOAP header-based authentication, middleware authentication caching, or Java EE security handler chains. This skill covers reconnaissance, exploitation, and validation of ThreadLocal-based authentication bypass attacks.
- ▌ Unicode Injection Pentest · abelrguezr bundleHow to find and exploit Unicode injection vulnerabilities in web applications. Use this skill whenever you're testing for XSS, SQLi, or other injection vulnerabilities and want to try Unicode-based bypass techniques. Trigger this when you encounter input validation, WAF filters, or encoding issues that might be vulnerable to Unicode normalization attacks, emoji injection, or Windows Best-Fit character mapping exploits.
- ▌ Distcc Pentest · abelrguezr bundleHow to identify and exploit Distcc vulnerabilities on port 3632. Use this skill whenever the user mentions Distcc, port 3632, distributed compilation, or needs to test for CVE-2004-2687. Make sure to use this skill for any network service enumeration that reveals port 3632, or when the user wants to check for remote code execution via Distcc misconfigurations.
- ▌ Docker Pentesting · abelrguezr bundleDocker security assessment and exploitation. Use this skill whenever the user needs to enumerate Docker services, exploit misconfigured Docker APIs (ports 2375/2376), escape containers, discover secrets in running containers, or perform privilege escalation via Docker. Trigger on mentions of Docker, containerization, container escape, Docker API, port 2375, port 2376, container security, or any Docker-related security testing.
- ▌ Privilege Escalation Write To Root · abelrguezr bundlePrivilege escalation techniques when you can write to root-owned files. Use this skill whenever you have write access to system files owned by root and need to escalate privileges. This includes scenarios where you can modify /etc/ld.so.preload, git hooks, schema handlers, or any root-executed scripts in user-writable directories. Make sure to use this skill when you discover writable paths that root processes might execute or modify.
- ▌ Cisco Vmanage Privilege Escalation · abelrguezr bundlePrivilege escalation techniques for Cisco vManage/Catalyst SD-WAN Manager. Use this skill whenever you have a low-privilege shell on a Cisco vManage system and need to escalate to root. Trigger this when you see vManage, Catalyst SD-WAN, confd, cmdptywrapper, or when you have a vmanage/neteng user shell and need root access. Also use when analyzing Cisco SD-WAN vulnerabilities or reviewing CVE-2025-20122, CVE-2024-20475, or Neo4j deserialization attacks on vManage.
- ▌ Ret2win Exploit · abelrguezr bundleHow to solve ret2win CTF challenges by exploiting buffer overflows to call a hidden win function. Use this skill whenever the user mentions ret2win, buffer overflow exploitation, calling a win/flag function, CTF binary exploitation, stack overflow to redirect execution, or any challenge where you need to overwrite a return address to execute a specific function. This applies to 32-bit and 64-bit binaries, with or without ASLR/PIE protections.
- ▌ Integer Overflow Exploitation · abelrguezr bundleHow to identify, analyze, and exploit integer overflow and underflow vulnerabilities in C/C++, Rust, and Go code. Use this skill whenever the user mentions integer overflow, underflow, arithmetic bugs, size calculation vulnerabilities, heap overflow from integer issues, or wants to audit code for numeric type vulnerabilities. Also use when analyzing binary exploitation challenges involving arithmetic operations, buffer size calculations, or memory allocation based on user-controlled numeric input.
- ▌ AI Fuzzing Assistant · abelrguezr bundleAI-assisted fuzzing and vulnerability discovery. Use this skill whenever the user wants to generate fuzzing seeds, evolve grammars, analyze crashes, create proof-of-vulnerability exploits, or generate patches for discovered bugs. Trigger on mentions of fuzzing, AFL++, libFuzzer, vulnerability discovery, crash analysis, exploit generation, or security testing with LLMs.
- ▌ Ntlm Credential Theft · abelrguezr bundleTechniques for capturing NetNTLMv2 hashes through Windows authentication coercion. Use this skill whenever the user needs to steal NTLM credentials, capture NetNTLMv2 hashes, perform SMB authentication attacks, exploit writable shares for credential theft, or coerce Windows authentication to an attacker-controlled SMB server. Trigger for any request involving NTLM relay, NetNTLMv2 capture, Windows credential harvesting, SMB lure attacks, or authentication bypass techniques.
- ▌ Angr Binary Analysis · abelrguezr bundleUse angr for binary analysis, reverse engineering, and symbolic execution. Use this skill whenever the user needs to analyze binaries, extract binary information (architecture, entry points, symbols, sections), perform dynamic analysis with simulation managers, solve CTF challenges with symbolic execution, hook functions, or work with bitvectors and constraints. Trigger this skill for any binary analysis task, reverse engineering work, CTF binary challenges, or when examining ELF/PE files programmatically.
- ▌ Lfi2rce Phpinfo · abelrguezr bundleHow to exploit Local File Inclusion (LFI) to Remote Code Execution (RCE) using PHPInfo() output. Use this skill whenever you need to escalate LFI vulnerabilities to RCE, especially when phpinfo() pages are accessible, or when you're testing for file inclusion vulnerabilities that could lead to code execution. Make sure to use this skill when you find LFI sinks combined with phpinfo() endpoints, or when you need to convert file inclusion into command execution on PHP applications.
- ▌ Zabbix Pentest · abelrguezr bundleZabbix security assessment and exploitation. Use this skill whenever the user mentions Zabbix monitoring, CVE-2024-22120, Zabbix SQLi, Zabbix cookie forgery, Zabbix RCE, or any Zabbix-related security testing. Trigger for Zabbix web UI assessment, port 10051/10050 enumeration, session cookie analysis, blind SQLi exploitation, admin privilege escalation, and post-exploitation activities on Zabbix infrastructure.
- ▌ Python Pentesting · abelrguezr bundleHow to test for Python-based vulnerabilities including code execution, SSTI (Server-Side Template Injection), deserialization attacks, and sandbox escapes. Use this skill whenever the user mentions Python vulnerabilities, template injection, pickle deserialization, sandbox bypass, or needs to test Python code execution in web applications. Make sure to use this skill for any pentesting task involving Python backends, even if the user doesn't explicitly name the vulnerability type.
- ▌ Socks Pentesting · abelrguezr bundlePentest SOCKS proxy services (port 1080). Use this skill whenever you need to enumerate, brute force, or validate SOCKS proxies. Trigger when the user mentions SOCKS, port 1080, proxy enumeration, socks5, proxychains, or any scenario involving SOCKS proxy testing, authentication checks, or egress validation through proxies.
- ▌ Ibm Mq Pentesting · abelrguezr bundlePentest IBM MQ message brokers on port 1414. Use this skill whenever the user mentions IBM MQ, message queues, port 1414, punch-q, pymqi, or needs to enumerate/exploit IBM MQ instances. This skill covers enumeration of queue managers, channels, and queues, plus exploitation techniques including message dumping and remote code execution via PCF commands.
- ▌ Squid Pentest · abelrguezr bundlePentest Squid HTTP proxy on port 3128. Use this skill whenever you discover a Squid proxy service, need to enumerate proxy capabilities, pivot through a proxy to scan internal networks, or configure proxychains for HTTP interaction. Trigger on mentions of Squid, HTTP proxy, port 3128, proxy pivoting, or internal network scanning through proxies.
- ▌ Iscsi Pentesting · abelrguezr bundlePentest iSCSI (Internet Small Computer Systems Interface) services on port 3260. Use this skill whenever you need to enumerate, authenticate, or mount iSCSI targets during security assessments. Trigger this skill when you see port 3260 open, need to discover iSCSI targets, want to access remote block storage, or are investigating storage vulnerabilities during penetration testing.
- ▌ Tacacs Pentest · abelrguezr bundleHow to pentest TACACS+ authentication systems on port 49. Use this skill whenever the user mentions TACACS, TACACS+, port 49, network device authentication, AAA services, Cisco network pentesting, or wants to test network access control systems. This skill covers intercepting authentication keys, performing MitM attacks, brute-forcing encryption keys, and decrypting TACACS+ traffic.
- ▌ Redis Pentesting · abelrguezr bundlePentest Redis instances (port 6379) for enumeration, authentication bypass, data exfiltration, and RCE. Use this skill whenever the user mentions Redis, port 6379, key-value stores, in-memory databases, or needs to test Redis security. This includes checking for authentication, dumping databases, exploiting misconfigurations, and testing for known CVEs like CVE-2025-49844, CVE-2025-46817, CVE-2025-46818.
- ▌ Postgresql Pentesting · abelrguezr bundlePostgreSQL database penetration testing and exploitation. Use this skill whenever the user needs to enumerate, exploit, or escalate privileges in PostgreSQL databases. Trigger on mentions of PostgreSQL, pgsql, port 5432, database pentesting, SQL injection against PostgreSQL, privilege escalation in databases, or any PostgreSQL security assessment tasks. This skill covers connection enumeration, privilege analysis, file system access, RCE techniques, and post-exploitation.
- ▌ Apache Pentesting · abelrguezr bundleApache web server pentesting and exploitation techniques. Use this skill whenever the user mentions Apache, web server vulnerabilities, .htaccess, mod_rewrite, PHP handlers, CVE-2021-41773, confusion attacks, LFI, RCE, or any Apache-related security testing. This includes checking PHP extensions, exploiting misconfigurations, testing for path traversal, handler confusion, and accessing restricted files.
- ▌ Django Pentest · abelrguezr bundleDjango security testing and exploitation. Use this skill whenever the user mentions Django applications, web app pentesting, SSTI vulnerabilities, pickle deserialization, session cookie attacks, or Django-specific CVEs. Trigger for any Django security assessment, vulnerability testing, or exploitation scenarios.
- ▌ Golang Connect Vulnerability · abelrguezr bundleTest for Go HTTP CONNECT method path normalization bypass vulnerabilities. Use this skill when analyzing Go web applications for path traversal issues, when investigating HTTP CONNECT method handling, or when security testing Go-based servers. This skill helps identify cases where the CONNECT method bypasses standard path normalization that other HTTP methods apply. Make sure to use this skill whenever you're testing Go web servers, investigating path traversal vulnerabilities, or analyzing HTTP method handling in Go applications.
- ▌ Joomla Pentest · abelrguezr bundlePentest Joomla CMS installations. Use this skill whenever the user mentions Joomla, wants to enumerate a Joomla site, check for Joomla vulnerabilities, perform brute-force attacks on Joomla, exploit Joomla RCE vulnerabilities, or assess Joomla security. Trigger for any Joomla-related security testing, vulnerability assessment, or penetration testing tasks.
- ▌ Moodle Pentest · abelrguezr bundleSecurity assessment and penetration testing for Moodle learning management systems. Use this skill whenever the user mentions Moodle, LMS security, educational platform pentesting, or needs to assess Moodle installations for vulnerabilities. Trigger for any Moodle-related security work including reconnaissance, vulnerability scanning, exploitation, or post-exploitation activities.
- ▌ Jboss Pentest · abelrguezr bundleSecurity assessment and enumeration of JBoss application servers. Use this skill whenever the user mentions JBoss, JBoss AS, JBoss EAP, or needs to enumerate Java application servers, check for default credentials, find exposed management consoles, or assess JMX vulnerabilities. Trigger for any web application security testing involving JBoss servers, even if the user doesn't explicitly name JBoss but describes Java EE application server assessment.
- ▌ Nginx Pentest · abelrguezr bundleAudit and test Nginx servers for common misconfigurations and vulnerabilities. Use this skill whenever you need to assess Nginx security, check for LFI vulnerabilities, test for HTTP request splitting, analyze proxy configurations, or identify dangerous directives. Trigger this skill for any Nginx security assessment, configuration review, or penetration testing task involving Nginx web servers.
- ▌ Vuejs Security Audit · abelrguezr bundleSecurity audit and vulnerability assessment for Vue.js applications. Use this skill whenever the user mentions Vue.js security, XSS vulnerabilities, Vue application hardening, frontend security review, or needs to identify security issues in Vue code. Trigger for any Vue.js code review, security assessment, or when users ask about protecting Vue applications from attacks.
- ▌ HTTP Connection Request Smuggling · abelrguezr bundleDetect and test HTTP Connection Request Smuggling vulnerabilities where reverse proxies only validate Host/:authority headers on the first request of a TCP/TLS connection. Use this skill whenever the user mentions HTTP smuggling, connection-state attacks, Host header validation, reverse proxy vulnerabilities, HTTP/2 coalescing abuse, or wants to test for SSRF-like access through connection reuse. Also trigger for requests about testing load balancers, CDNs, or proxies for first-request-only validation weaknesses.
- ▌ Xs Search Connection Pool · abelrguezr bundleXS-Search connection pool timing attack for web pentesting. Use this skill whenever you need to exfiltrate data from a target page you cannot directly read, when you can control content that affects page load time, or when you have a CSRF/HTML injection vector and need to extract secrets like flags, tokens, or sensitive data. This technique works when you can make the target load different content based on what you're testing and measure timing differences through connection pool exhaustion. Make sure to use this skill for any XS-Leak, XS-Search, timing-based data exfiltration, or when you have HTML injection without JS execution and need to read protected content.
- ▌ Timing Side Channel Attack · abelrguezr bundleHow to perform timing-based side-channel attacks using performance.now() to extract hidden data from web applications. Use this skill whenever you need to brute-force secrets, flags, or sensitive data by measuring response time differences. Trigger this when the user mentions timing attacks, performance.now, side-channel extraction, CTF challenges with time-based vulnerabilities, or any scenario where response time correlates with secret data.
- ▌ Format String Exploit · abelrguezr bundleHow to exploit format string vulnerabilities in C programs. Use this skill whenever the user mentions format strings, printf vulnerabilities, sprintf/fprintf issues, GOT overwrites, arbitrary memory read/write, stack leaks, or any C program that takes user input as a format string. Also trigger for CTF challenges involving format string bugs, pwn tasks with printf-family functions, or when analyzing binaries for format string vulnerabilities.
- ▌ IOS Exploitation · abelrguezr bundleiOS exploitation research and analysis. Use this skill whenever the user mentions iOS security, exploit mitigations, kernel/userland heap analysis, PAC/BTI/ASLR/DEP, XNU kernel structures, iOS exploit chains, or any iOS security research task. This skill helps understand iOS hardening mechanisms, analyze kernel heap structures, work with exploitation tools like Ghidra/BinDiff, and understand modern iOS exploit patterns.
- ▌ Off By One Heap Exploit · abelrguezr bundleHow to exploit off-by-one heap overflow vulnerabilities in glibc. Use this skill whenever the user mentions heap exploitation, off-by-one vulnerabilities, glibc heap attacks, tcache poisoning, chunk size corruption, or any scenario where a single-byte write can corrupt heap metadata. Also trigger for CVE-2023-6779, syslog exploits, safe-linking bypasses, or when analyzing heap-based vulnerabilities in CTF challenges or real-world targets.
- ▌ Unsorted Bin Attack · abelrguezr bundleHow to perform unsorted bin heap attacks in glibc-based CTF challenges. Use this skill whenever the user mentions heap exploitation, unsorted bins, glibc malloc attacks, chunk corruption, arbitrary writes via heap, or needs to bypass tcache for heap attacks. Also trigger when users discuss global_max_fast manipulation, heap infoleaks, or transitioning from unsorted bin to fast bin attacks.
- ▌ Stack Overflow Exploitation · abelrguezr bundleHow to analyze and exploit stack overflow vulnerabilities in binary programs. Use this skill whenever the user mentions stack overflows, buffer overflows, EIP/RIP control, return address manipulation, CTF binary exploitation, or needs help finding offsets and crafting exploits for vulnerable programs. This includes ret2win, shellcode placement, ROP chains, and analyzing real-world CVEs with stack-based vulnerabilities.
- ▌ Archive Extraction Path Traversal · abelrguezr bundleSecurity skill for detecting, testing, and mitigating archive extraction path traversal vulnerabilities (Zip-Slip, CVE-2025-8088, etc.). Use this skill whenever the user mentions archives (ZIP, RAR, TAR, 7-ZIP), file extraction, path traversal, zip-slip, archive security, or wants to test archive handling code. Also trigger when users ask about secure archive extraction, vulnerable code patterns, or creating security test cases for archive utilities.
- ▌ Python Security Research · abelrguezr bundleHow to research and understand Python security vulnerabilities including sandbox escapes, deserialization attacks, and Pyscript exploitation. Use this skill whenever the user mentions Python security, sandbox bypass, deserialization vulnerabilities, Pyscript hacking, Keras model attacks, or needs to understand Python-based attack vectors for security research, penetration testing, or defensive analysis.
- ▌ IOS Pasteboard Pentest · abelrguezr bundleHow to test iOS applications for pasteboard security vulnerabilities. Use this skill whenever you need to analyze iOS app clipboard usage, check for sensitive data exposure via UIPasteboard, or perform static/dynamic analysis of iOS pasteboard implementations. Make sure to use this skill when pentesting iOS apps and you need to check clipboard/pasteboard security, analyze data sharing mechanisms, or look for sensitive information leakage through UIPasteboard.
- ▌ Xssi Cross Site Script Inclusion · abelrguezr bundleHow to detect and test for Cross-Site Script Inclusion (XSSI) vulnerabilities in web applications. Use this skill whenever you're doing web application security testing, penetration testing, or vulnerability assessment and need to check for XSSI issues. This includes testing for static JavaScript exposure, dynamic JavaScript with authentication, JSONP callback hijacking, and non-script file inclusion attacks. Make sure to use this skill when reviewing JavaScript endpoints, JSONP implementations, or any scenario where scripts might be loaded from different origins.
- ▌ IOS Corellium Connect · abelrguezr bundleHow to connect to Corellium iOS VMs for exploitation and testing. Use this skill whenever the user mentions Corellium, iOS virtual machines, connecting to iOS devices, uploading binaries to iOS, installing .ipa files, SSH to iOS VMs, or any iOS exploitation/testing workflow involving Corellium. This includes Quick Connect, VPN setup, file transfers, app installation, port forwarding, and remote debugging.
- ▌ House Of Einherjar · abelrguezr bundleHow to perform House of Einherjar heap exploitation to allocate memory at arbitrary addresses. Use this skill whenever the user mentions heap exploitation, glibc heap attacks, arbitrary memory allocation, off-by-one overflow exploitation, tcache poisoning, fast bin attacks, or any CTF challenge involving heap manipulation. This is essential for binary exploitation tasks where you need to control malloc() return addresses.
- ▌ Vectored Overloading Pe Injection · abelrguezr bundleWindows PE injection technique using Vectored Exception Handlers (VEHs) and hardware breakpoints to disguise malicious code as legitimate DLLs. Use this skill when analyzing or implementing Vectored Overloading attacks, investigating VEH-based evasion techniques, understanding how attackers bypass kernel-level telemetry by hijacking the Windows loader, or when you need to detect this technique in security tools. Trigger this skill for any questions about VEH injection, hardware breakpoint exploitation, module overloading, or Windows loader manipulation.
- ▌ Tls Certificates · abelrguezr bundleParse, analyze, and convert X.509 certificates and TLS-related files. Use this skill whenever the user mentions certificates, TLS, SSL, X.509, PEM, DER, PKCS#12, PKCS#7, certificate parsing, certificate validation, or anything related to cryptographic certificates and trust chains. Also use when users need to inspect certificate fields, convert between formats, or understand certificate security issues.
- ▌ Macos Keychain · abelrguezr bundleAnalyze and enumerate macOS Keychain entries for security assessments. Use this skill whenever you need to inspect keychain contents, understand ACL permissions, extract credentials, or perform keychain security analysis on macOS systems. Make sure to use this skill when the user mentions keychain, macOS credentials, password extraction, ACL analysis, or any macOS security assessment involving stored secrets.
- ▌ Flutter Ssl Bypass · abelrguezr bundleBypass SSL/TLS pinning in Flutter apps to intercept HTTPS traffic with Burp or mitmproxy. Use this skill whenever you need to intercept Flutter app traffic, bypass certificate pinning on Android/iOS, or analyze Flutter network requests. Flutter apps use BoringSSL inside libflutter.so which ignores standard Android SSL pinning bypasses - this skill covers Frida hooking, binary patching, and offset-based techniques to force certificate acceptance.
- ▌ Ident Pentesting · abelrguezr bundlePentest the Ident Protocol (port 113) to enumerate usernames associated with TCP connections. Use this skill whenever you need to identify users running services on a target, enumerate usernames for password attacks, or assess if a target has identd running. Trigger for any pentesting task involving port 113, user enumeration, connection ownership discovery, or when you want to build username lists for further attacks.
- ▌ Msrpc Pentesting · abelrguezr bundlePentest Microsoft RPC (MSRPC) services on ports 135, 593, 139, 445. Use this skill whenever you need to enumerate RPC endpoints, identify vulnerable interfaces, execute remote commands with valid credentials, or fuzz RPC services for vulnerabilities. Trigger this skill for any Windows network assessment involving RPC, DCOM, named pipes, or when you see open ports 135/593/139/445 during reconnaissance.
- ▌ Pptp Pentesting · abelrguezr bundleHow to enumerate and pentest PPTP (Point-to-Point Tunneling Protocol) services on port 1723. Use this skill whenever the user mentions PPTP, port 1723, GRE protocol, remote access tunneling, or needs to assess PPTP security during authorized penetration testing. This skill covers enumeration, brute force attacks, and known PPTP vulnerabilities.
- ▌ Nats Pentesting · abelrguezr bundlePentest NATS message bus and JetStream services. Use this skill whenever you need to enumerate, exploit, or assess NATS servers (port 4222/tcp), capture credentials via DNS hijacking, loot JetStream streams for secrets, or harden NATS deployments. Trigger this skill for any NATS-related security testing, credential harvesting, or message broker assessment tasks.
- ▌ Rexec Pentesting · abelrguezr bundlePentest and exploit Rexec (port 512) services. Use this skill whenever you encounter port 512/tcp open during enumeration, need to brute-force rexec credentials, extract credentials from network captures, or exploit legacy r-services. Trigger for any rexec-related tasks including nmap scanning, hydra brute-forcing, credential sniffing, or post-exploitation command execution.
- ▌ Rsync Pentest · abelrguezr bundlePentest rsync file sharing services on port 873. Use this skill whenever you need to enumerate, access, or exploit rsync services. Trigger this skill for any rsync-related tasks including module enumeration, authentication testing, file transfer, brute force attacks, or post-exploitation configuration analysis. Make sure to use this skill when you see port 873 open, need to test rsync shares, or want to transfer files via rsync.
- ▌ Flask Pentesting · abelrguezr bundleHow to exploit Flask web application vulnerabilities including session cookie manipulation, secret key brute-forcing, and SSRF attacks. Use this skill whenever the user mentions Flask applications, session cookies, web pentesting, SSTI vulnerabilities, or needs to decode/sign/craft Flask session cookies. Make sure to use this skill for any Flask-related security testing, cookie analysis, or web application exploitation tasks.
- ▌ Pentest Dapps · abelrguezr bundleHow to pentest decentralized applications (DApps). Use this skill whenever the user mentions DApps, Web3 applications, blockchain applications, smart contracts, or wants to audit/penetrate test any decentralized application. This includes NFT platforms, DeFi protocols, cross-chain bridges, and any application that interacts with blockchain technology. Make sure to use this skill when the user asks about Web3 security, DApp vulnerabilities, or blockchain application testing.
- ▌ Deserialization Pentest · abelrguezr bundleHow to identify and exploit insecure deserialization vulnerabilities across PHP, Python, NodeJS, Java, .NET, and Ruby. Use this skill whenever the user mentions deserialization, serialization, object injection, gadget chains, ysoserial, pickle, unserialize, ObjectInputStream, BinaryFormatter, Marshal, or any related vulnerability testing. Make sure to use this skill for any web application security testing involving serialized data, ViewState parameters, cookies with serialized objects, or when analyzing code for deserialization sinks.
- ▌ Web Vulnerability Methodology · abelrguezr bundleComprehensive web vulnerability assessment methodology and checklist. Use this skill whenever the user mentions web pentesting, vulnerability assessment, security testing, bug bounty hunting, web application security, OWASP testing, or any security audit of web applications. This skill provides a systematic approach to finding vulnerabilities across all attack vectors including proxies, user input, authentication, file handling, APIs, frameworks, and more. Make sure to use this skill for any web security testing task, even if the user doesn't explicitly mention 'pentesting' or 'vulnerability assessment'.
- ▌ Tcache Exploitation · abelrguezr bundleHow to identify and exploit Tcache bin attacks in heap vulnerabilities. Use this skill whenever the user mentions heap exploitation, tcache, malloc, free, heap overflow, double free, use-after-free, libc leaks, malloc_hook, free_hook, or any heap-related binary exploitation challenge. This skill covers Tcache poisoning, Tcache index attacks, and common CTF patterns for Glibc 2.26+.
- ▌ Python Venv · abelrguezr bundleHow to create, activate, and manage Python virtual environments. Use this skill whenever the user needs to set up an isolated Python environment, install packages in a clean environment, or troubleshoot venv-related issues. Make sure to use this skill when users mention virtual environments, venv, python environments, package isolation, or need to install Python libraries without affecting the system Python.
- ▌ IOS Pentesting · abelrguezr bundleiOS application security testing and pentesting. Use this skill whenever the user needs to test iOS apps for security vulnerabilities, analyze IPA files, perform static/dynamic analysis, check data storage security, test local authentication, or conduct mobile security assessments. Make sure to use this skill for any iOS security testing, app analysis, vulnerability assessment, or mobile pentesting tasks, even if the user doesn't explicitly mention 'pentesting' or 'security testing'.
- ▌ Mongodb Pentest · abelrguezr bundleSecurity assessment and penetration testing for MongoDB databases. Use this skill whenever the user needs to enumerate MongoDB instances, test for authentication bypass, check for ObjectID prediction vulnerabilities, assess MongoBleed (CVE-2025-14847) exposure, or perform authorized security testing on MongoDB services on ports 27017/27018. Trigger for any MongoDB security assessment, vulnerability scanning, or penetration testing task.
- ▌ Whois Pentesting · abelrguezr bundlePerform WHOIS enumeration and security testing on port 43 services. Use this skill whenever you need to enumerate domain/IP/ASN registration data, test WHOIS services for vulnerabilities, follow referral chains, or compare WHOIS vs RDAP data. Trigger this skill for any task involving WHOIS queries, domain registration lookups, IP allocation data, or testing legacy WHOIS infrastructure for injection vulnerabilities or rogue server abuse.
- ▌ X11 Pentesting · abelrguezr bundlePerform X11 (X Window System) security assessments and exploitation on port 6000. Use this skill whenever the user mentions X11, port 6000, X Window System, graphical interface pentesting, or needs to enumerate/exploit unauthenticated X11 access. This includes checking for anonymous connections, capturing screenshots, keylogging, remote desktop viewing, and obtaining shells through X11 vulnerabilities.
- ▌ Jira Confluence Pentest · abelrguezr bundleSecurity assessment and penetration testing for Jira and Confluence instances. Use this skill whenever the user needs to enumerate Jira/Confluence privileges, test for known vulnerabilities (CVE-2023-22527, CVE-2023-22515, CVE-2024-21683), assess plugin security, or perform reconnaissance on Atlassian products. Trigger on requests about Jira security, Confluence pentesting, Atlassian vulnerability scanning, privilege enumeration, or RCE testing against these platforms.
- ▌ Wsgi Pentesting · abelrguezr bundleUse this skill for WSGI/uWSGI post-exploitation attacks including magic variable exploitation, SSRF-to-uWSGI pivots via gopher protocol, and backdoor deployment. Trigger when the user mentions WSGI, uWSGI, uwsgi protocol, magic variables, UWSGI_FILE, SSRF to backend, or needs to exploit WSGI misconfigurations for RCE.
- ▌ Cookie Bomb Analysis · abelrguezr bundleAnalyze, detect, and understand cookie bomb attacks for security assessments. Use this skill whenever the user mentions cookie attacks, HTTP request size issues, DoS via cookies, browser cookie limits, or needs to test for cookie-based denial of service vulnerabilities. Trigger for any pentesting task involving HTTP headers, cookie manipulation, or request smuggling scenarios.
- ▌ Dom Xss Analysis · abelrguezr bundleAnalyze web applications for DOM-based Cross-Site Scripting (XSS) vulnerabilities. Use this skill whenever the user needs to find, understand, or exploit DOM XSS issues in JavaScript code, HTML pages, or web applications. Trigger on requests about DOM vulnerabilities, JavaScript injection, unsafe sinks, source-to-sink data flow, or any XSS-related security testing.
- ▌ SQL Login Bypass · abelrguezr bundleSQL injection payloads for testing login form vulnerabilities. Use this skill when you need to test for SQL injection vulnerabilities in authentication forms, when analyzing login bypass techniques, or when conducting authorized penetration testing on web applications. This skill provides a comprehensive collection of SQL injection payloads for XPath, LDAP, and SQL injection attacks. Make sure to use this skill whenever the user mentions SQL injection, login bypass, authentication testing, web security testing, or penetration testing on login forms.
- ▌ Mssql Injection · abelrguezr bundleMSSQL SQL injection exploitation techniques including Active Directory enumeration, SSRF via MSSQL functions, WAF bypass methods, and data exfiltration. Use this skill whenever the user mentions MSSQL, Microsoft SQL Server, SQL injection against MSSQL databases, or needs to enumerate domain users, bypass WAFs, or exfiltrate data from MSSQL servers. Trigger for any MSSQL-specific injection scenarios, not just generic SQL injection.