netvar1337
- 736 skills
- 0 followers
- 21 hours ago last updated
- ▌ Claude Red AI Offensive AI Security · netvar1337 bundleAI/LLM security offensive checklist: prompt injection, jailbreaking, model extraction, training data poisoning, adversarial inputs, LLM-assisted attack automation, and AI system reconnaissance. Use when assessing AI/ML systems, red-teaming LLMs, or researching AI attack vectors.
- ▌ Claude Red Web Offensive Waf Bypass · netvar1337 bundleWAF bypass techniques checklist: encoding bypass (URL/HTML/Unicode/double encoding), case variation, comment injection, HTTP header manipulation, chunked encoding, IP rotation, timing attacks, and payload obfuscation per WAF vendor. Use when WAF is blocking payloads during web app tests.
- ▌ Router Reverse Skill Router Docs Generator · netvar1337 bundleCreates task-oriented technical documentation with progressive disclosure. Use when writing READMEs, API docs, architecture docs, or markdown documentation. Also use this skill at the END of any completed reverse engineering, penetration testing, CTF, or security analysis task to generate a formal report in the user's project directory. Trigger keywords: write report, write docs, produce a report, writeup, technical documentation, report, documentation.
- ▌ Router Reverse Skill Router Dotnet Reverse · netvar1337 bundle.NET / C# binary reverse engineering. Use when the target is a .NET assembly (PE header containing CLR, .exe/.dll managed program), C# compiler output (including NativeAOT), red team Sharp* tools (Rubeus / SharpHound / etc.), .NET obfuscated programs (ConfuserEx / SmartAssembly / Babel / Eazfuscator), or .NET loaders / info-stealers / wrapped malware. Prefer dnSpyEx + de4dot; integrate with dnSpy MCP when the AI needs to operate directly. Not for pure native binaries (use reverse-engineering / ida-reverse).
- ▌ Router Reverse Skill Router Email Security · netvar1337 bundleUse for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.
- ▌ Router Reverse Skill Router Ghidra Reverse · netvar1337 bundleUse for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.
- ▌ Router Reverse Skill Router Mobile Reverse · netvar1337 bundleUse for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.
- ▌ Router Reverse Skill Router Threat Hunting · netvar1337 bundleUse for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.
- ▌ Memory Safety Analyst · netvar1337Classify memory-safety defects, evaluate exploitability, and prioritize remediation based on primitive quality and mitigation interaction.
- ▌ Claude Red Web Offensive File Upload · netvar1337 bundleFile upload vulnerability checklist: MIME type bypass, extension bypass, magic byte manipulation, path traversal in filenames, stored XSS via SVG/HTML upload, server-side processing attacks, and race conditions. Use for assessing file upload endpoints in web app pentests or bug bounty.
- ▌ Hack Skills HTTP Host Header Attacks · netvar1337HTTP Host header injection and routing abuse playbook. Use when the application trusts the Host header for generating URLs, routing requests, or access control — enabling password reset poisoning, web cache poisoning, SSRF via routing, and virtual host bypass.
- ▌ Tdd · netvar1337 bundleTest-driven development. Use when the user wants to build features or fix bugs test-first, mentions "red-green-refactor", "strict TDD", "test-driven-development", or wants integration tests.
- ▌ R2js · netvar1337 bundleExecute arbitrary radare2 commands and r2js scripts via r2xsql when SQL surfaces are insufficient. Use for custom analysis passes, ESIL emulation, anything r2's tables don't expose, or to bridge SQL queries with r2 SDK behavior.
- ▌ Spec · netvar1337 bundleUse when creating/amending SPEC.md or recording bugs into section B ('write the spec', 'bug: ...').
- ▌ Byovd · netvar1337BYOVD (Bring Your Own Vulnerable Driver) attack workflow: identify vulnerable signed drivers, map IOCTLs, arbitrary physical/virtual memory, MSR R/W, kernel code exec. Use for BYOVD, vulnerable .sys abuse, signed-driver primitives. Do NOT use for writing a new WDM/KMDF driver from scratch (kernel-dev) or generic exploit-dev without a driver primitive.
- ▌ Check · netvar1337Use for read-only SPEC.md vs code drift detection ('check drift', 'check invariants').
- ▌
- ▌ Aitodo · netvar1337Resolve tasks described in `AITODO` comments by implementing the required code changes and removing the comments.
- ▌ Deepen · netvar1337Use when improving module design without changing behavior ('deepen this', /ck:deepen).
- ▌ Ot Ics · netvar1337 bundleUse for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.
- ▌ R2http · netvar1337 bundleUse when Codex needs to start, discover, or communicate with a radare2 or iaito HTTP webserver and run stateful radare2 commands over POST /cmd with curl, especially to replace r2mcp or one-shot r2 command lines during long binary analysis.
- ▌ Review · netvar1337 bundleUse before high-blast-radius builds to adversarially review SPEC.md ('review the spec', /ck:review).
- ▌ Aiclean · netvar1337Clean and refactor code with a focus on unnecessary complexity, reducing lines of code, improving readability, and preferring radare2-native portable APIs.
- ▌ Ailogic · netvar1337Find logic bugs in C code for radare2 by analyzing control flow, state transitions, and silent assumptions.
- ▌ Aisolve · netvar1337Use when asked to resolve one tractable TODO or XXX comment from a codebase; selects, implements, and verifies a real fix.
- ▌ Caveman · netvar1337 bundleUltra-compressed communication mode. Cuts token usage ~75% by speaking like caveman while keeping full technical accuracy. Supports intensity levels: lite, full (default), ultra, wenyan-lite, wenyan-full, wenyan-ultra. Use when user says "caveman mode", "talk like caveman", "use caveman", "less tokens", "be brief", or invokes /caveman. Also auto-triggers when token efficiency is requested.
- ▌ Classes · netvar1337 bundleRecover C++ class hierarchies, vtables, and RTTI from a compiled binary via r2xsql's classes and class_methods tables. Use when asked about class/inheritance structure, vtable layout, virtual method tables, or 'what C++ classes does this binary define'.
- ▌ Harness · netvar1337Configures a harness. A meta-skill that defines specialized agents and creates the skills those agents will use. Use when (1) asked to 'configure a harness' or 'build a harness,' (2) asked for 'harness design' or 'harness engineering,' (3) building a harness-based automation system for a new domain/project, (4) reconfiguring or extending a harness, or (5) handling operations/maintenance requests for an existing harness, such as 'inspect the harness,' 'audit the harness,' 'harness status,' or 'synchronize agents/skills.'
- ▌ Loop Me · netvar1337 bundleGrill me about specs for the workflows I want to build, within this workspace.
- ▌ Radius2 · netvar1337 bundleUse radius2 symbolic execution with radare2 to find inputs that reach or avoid code paths.
- ▌
- ▌ Aireview · netvar1337Review source code in commit changes, functions or files and report only high-confidence findings in a structured task-note format.
- ▌ Ponytail · netvar1337Use for laziest correct solution ('ponytail', 'yagni', 'do less'). Modes: lite/full/ultra; default off until enabled.
- ▌ Cloud K8S · netvar1337 bundleUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
- ▌ Glm Tight · netvar1337Use when the operator asks for concise execution, reduced token use, minimal implementation, no yapping, "tight mode," "be brief," or "just do it." Produce the smallest verified result with no routine narration.
- ▌ Omniwire · netvar1337Infrastructure layer for AI agent swarms — 88 MCP tools for mesh control, A2A protocol, OmniMesh VPN, CyberSync, web scraping, firewall management, browser automation, and more. ~80ms execution.