← all publishers

crtvrffnrt

@crtvrffnrt source repo

23 published skills

  1. Pentest Xss · crtvrffnrt bundle
    XSS assessment skill for reflected XSS, stored XSS, DOM XSS, blind XSS, CSP bypass, WAF bypass, source-to-sink analysis, browser context validation, safe payload design, and evidence collection.
    0
    installs
  2. Pentest Gemini Az · crtvrffnrt
    Azure, Microsoft 365, Microsoft Graph, and Entra ID operator skill using the current Azure CLI session and `az rest` for scoped read, list, create, update, delete, and evidence collection tasks.
    0
    installs
  3. Web Pentest Skill · crtvrffnrt
    Analyze supplied artifacts from authorized web assessments with bounded defensive reasoning, evidence review, resumable workflow planning, and static reporting. Use for offline artifact analysis and explicitly reviewed task planning; never for autonomous exploitation, unreviewed target scanning, or executing model-generated commands.
    0
    installs
  4. Incident Response Bec · crtvrffnrt
    BEC and AiTM incident-response skill for suspicious sign-ins, mailbox abuse, forwarding, inbox rules, session theft, token replay, consent abuse, and secondary phishing.
    0
    installs
  5. Pentest Shodan Helper · crtvrffnrt
    Shodan CLI-only search workflow for query design, filter selection, count/stats validation, and search-result retrieval through /root/.local/bin/shodan.
    0
    installs
  6. Incident Response Main · crtvrffnrt bundle
    Defensive incident-response companion for Microsoft Entra ID, Microsoft 365, Defender, and mixed identity or endpoint incidents. Use for sign-in triage, public-IP enrichment, initial scoping, containment planning, and analyst-ready notes.
    0
    installs
  7. Pentest Gemini Sub Htb · crtvrffnrt
    Controlled lab skill for Hack The Box, CTF, and private lab workflows from reconnaissance, enumeration, vulnerability research, exploitation, foothold, and privilege escalation through evidence consolidation.
    0
    installs
  8. Pentest Osint Linkedin · crtvrffnrt bundle
    Authenticated LinkedIn OSINT helper using local `cookies.txt` and bundled scripts for people, company, role, certification, post, and network-context research.
    0
    installs
  9. Pentest Web Enumeration · crtvrffnrt bundle
    Authorized web enumeration for one or many websites or web applications, including live-target normalization, HTTP and TLS fingerprinting, technology and platform identification, virtual-host discovery, crawling, JavaScript and API endpoint extraction, focused directory and sensitive-file discovery, CMS-specific checks, and Nuclei-led early vulnerability triage. Use when the owner phase is practical HTTP(S) information gathering intended to identify web applications, exposed attack surface, and evidence-backed initial-access candidates before focused validation.
    0
    installs
  10. Incident Response Report · crtvrffnrt
    Incident-response reporting skill for decision-ready summaries, timelines, containment records, executive handoff, remediation plans, and unresolved evidence gaps.
    0
    installs
  11. Pentest Hacktricks Finder · crtvrffnrt
    Support skill for HackTricks technique research, payload ideas, bypasses, prerequisites, caveats, and edge-case behavior across web, network, cloud, and application security topics. Use as owner only when research is the current blocker.
    0
    installs
  12. Pentest Business Logic Abuse · crtvrffnrt
    Business logic and workflow abuse assessment for state-machine manipulation, race conditions, replay, quota abuse, order-of-operations flaws, delegated execution abuse, and unauthorized state transitions. Hands off to recon, input/protocol, exploit, or reporting workflows when those become the owner phase.
    0
    installs
  13. Pentest Cve Reverse Engineer · crtvrffnrt
    Manual vulnerability research skill for finding advisories, downloading affected and fixed artifacts, diffing patches, confirming root cause, and writing reliable reports across products and technologies.
    0
    installs
  14. Incident Response Fileanalyser · crtvrffnrt bundle
    Static malware reverse-engineering and threat-intelligence triage for unknown files, Windows EXE/PE binaries, scripts, archives, ISOs, JavaScript, PowerShell, documents, and unpacked payloads. Use when a user provides a sample path, hash, filename, or file and asks whether it is malicious, benign, suspicious, contains IoCs, or should be reverse engineered with Ghidra, strings, capa, YARA, public TI, and structured phase artifacts.
    0
    installs
  15. Pentest Recon Surface Analysis · crtvrffnrt
    Reconnaissance and attack-surface mapping for endpoint discovery, asset inventory, service enumeration, technology fingerprinting, control-plane surfaces, trust boundaries, and prioritized next tests.
    0
    installs
  16. Pentest Input Protocol Manipulation · crtvrffnrt
    Input validation and protocol manipulation assessment for injection, parser differential testing, request smuggling, method tampering, header confusion, serialization abuse, and payload mutation. Hands off to authz, business-logic, exploit, or reporting workflows when those become the owner phase.
    0
    installs
  17. Pentest Web Application Logic Mapper · crtvrffnrt
    Web application logic mapper for spidering, crawling, hidden API discovery, workflow mapping, state-machine analysis, route relationships, and handoff targets for authz, business logic, XSS, input/protocol, OOB, CVE, exploit, or reporting workflows.
    0
    installs
  18. Pentest Advanced Access Control Auditor · crtvrffnrt
    Focused authorization assessment for access control, IDOR, BOLA, BFLA, RBAC, object ownership, function authorization, tenant isolation, and horizontal or vertical privilege escalation. Uses paired roles, alternate objects, methods, and controls to prove boundaries safely.
    0
    installs
  19. Pentest Cve Vulnerability Research Helper · crtvrffnrt
    CVE and vulnerability research skill for exact CVE lookup, product/version applicability, exploit maturity, KEV/PoC status, source ranking, contradiction handling, and non-destructive validation guidance.
    0
    installs
  20. Pentest Exploit Execution Payload Control · crtvrffnrt
    Deterministic exploit execution and payload control from validated primitives. Use for exploit implementation, payload hardening, chaining confirmed weaknesses, post-exploitation proof, controlled impact demonstration, reliability notes, and rollback or containment planning.
    0
    installs
  21. Pentest Outbound Interaction Oob Detection · crtvrffnrt
    Outbound interaction and OOB validation for SSRF callbacks, blind XSS beacons, webhook abuse, XXE/OOB behavior, DNS/HTTP/HTTPS callback correlation, asynchronous server-side interaction proof, and egress validation.
    0
    installs
  22. Pentest Authentication Authorization Review · crtvrffnrt
    Authentication and authorization security assessment for sessions, tokens, MFA, account takeover, IDOR, BOLA, BFLA, privilege escalation, tenant isolation, and identity boundary validation. Hands off to recon, input/protocol, access-control deep dive, exploit, or reporting workflows when those become the owner phase.
    0
    installs
  23. Pentest Evidence Structuring Report Synthesis · crtvrffnrt
    Evidence structuring and report synthesis for confirmed findings, severity ranking, remediation guidance, executive summaries, technical appendices, and unresolved evidence gaps. Hands off to live validation workflows when proof is incomplete.
    0
    installs