← all publishers

duriantaco

@duriantaco source repo

15 published skills

  1. Skylos 2 · duriantaco bundle
    Run, interpret, or modify Skylos safely. Use when the user asks to scan code with Skylos, explain SKY-* findings, triage dead-code false positives, audit security/secrets/SCA/LLM behavior, update Skylos rules/docs/CI, benchmark analyzer behavior, or change this repository safely.
    0
    installs
  2. Skylos · duriantaco bundle
    Run, interpret, or modify Skylos safely. Use when the user asks to scan code with Skylos, explain SKY-* findings, triage dead-code false positives, audit security/secrets/SCA/LLM behavior, update Skylos rules/docs/CI, benchmark analyzer behavior, or change this repository safely.
    0
    installs
  3. Skylos Security · duriantaco bundle
    Investigate and harden Skylos security behavior. Use when the user asks to validate a security finding, reproduce a scanner bypass, assess false negatives, review LLM evidence filters, analyze CI/cloud policy trust boundaries, classify severity, or add regression tests for security-sensitive analyzer behavior.
    0
    installs
  4. Hunt Lfi · duriantaco bundle
    Investigate authorized local file inclusion, path traversal, and arbitrary file-read boundaries. Use when typed discovery identifies path, file, page, template, include, download, or document inputs, target-observed file-read replay contracts, local-file markers, or suspected traversal-normalization failures.
    0
    installs
  5. Hunt Rce · duriantaco bundle
    Investigate authorized server-side command and code-execution boundaries. Use when typed discovery or target-origin behavior identifies command injection, process-launching, diagnostic, converter, expression-evaluation, parser, include, or other server-side execution-sink signals.
    0
    installs
  6. Hunt Xss · duriantaco bundle
    Investigate authorized reflected, stored, and DOM cross-site scripting boundaries. Use when typed discovery identifies controllable HTML or JavaScript contexts, reflection sinks, stored render workflows, DOM source-to-sink flows, browser execution signals, or suspected executable markup injection.
    0
    installs
  7. Hunt Xxe · duriantaco bundle
    Investigate authorized XML external entity and XML parser boundaries. Use when typed discovery identifies XML or SOAP request bodies, document imports, XML or SVG uploads, DOCTYPE handling, entity-resolution behavior, parser errors, or a suspected external-entity primitive.
    0
    installs
  8. Hunt Idor · duriantaco bundle
    Investigate object-level and tenant authorization boundaries on authorized web or API targets. Use when typed routes or operator context expose object identifiers, account or tenant selectors, user-owned resources, GraphQL object lookups, or suspected cross-identity access.
    0
    installs
  9. Hunt Sqli · duriantaco bundle
    Investigate authorized SQL injection boundaries on web and API inputs. Use when typed discovery or target-origin evidence identifies query-backed parameters, database-error signals, boolean or timing SQL differentials, SQL-filter behavior, or a suspected injectable login, search, sort, filter, or identifier input.
    0
    installs
  10. Hunt Ssrf · duriantaco bundle
    Investigate authorized server-side request forgery and URL-fetch boundaries. Use when typed discovery identifies server-side webhooks, callbacks, previews, proxying, imports, remote-resource fetches, URL parser differentials, or a suspected server-origin request primitive.
    0
    installs
  11. Hunt Ssti · duriantaco bundle
    Investigate authorized server-side template injection boundaries. Use when typed discovery or target-origin behavior identifies server-rendered inputs, evaluated-expression differentials, template-engine errors, rendering workflows, or suspected Jinja, Twig, FreeMarker, Mako, ERB, Smarty, Thymeleaf, or Django template evaluation.
    0
    installs
  12. Hunt GRAPHQL · duriantaco bundle
    Investigate authorized GraphQL schemas, operations, resolvers, and object-authorization boundaries. Use when typed discovery identifies GraphQL endpoints, introspection, query or mutation names, global object identifiers, resolver errors, or API access-control signals.
    0
    installs
  13. Analyze Satcom · duriantaco bundle
    Inspect authorized offline satellite and SATCOM artifacts without transmitting. Use for TLE sets, CCSDS Space Packet streams, telemetry or telecommand captures, sequence-counter anomalies, spacecraft identifiers, packet-length validation, or passive mission-data triage.
    0
    installs
  14. Hunt File Upload · duriantaco bundle
    Investigate authorized file-upload, stored-file, and upload-parser boundaries. Use when typed discovery identifies upload forms, multipart requests, filename or content-type handling, stored-file readback, image or document ingestion, archive processing, XML or SVG parsing, or suspected upload-policy bypasses.
    0
    installs
  15. Hunt Deserialization · duriantaco bundle
    Investigate authorized unsafe deserialization and serialized-data trust boundaries. Use when typed discovery identifies encoded object cookies or tokens, pickle or object streams, YAML type tags, serialized uploads or imports, type-confusion errors, or suspected server-side object reconstruction.
    0
    installs