all publishers

ShulkwiSEC

@shulkwisec source repo

354 published skills · page 3 of 4

  1. ▌
    Mobile Weak Crypto · shulkwisec
    Detects weak or misconfigured cryptography in mobile apps (Android/iOS). Trigger on: hardcoded keys, ECB mode, DES, 3DES, RC4, MD5, SHA-1, SecureRandom misuse, static IV, reused IV, Math.random, arc4random, CommonCrypto, CryptoKit, Android Keystore, SecKey, AES-ECB, RSA without OAEP, insufficient key size, predictable seed, insecure key storage, broken hash, PBKDF2 iteration count. Covers MASVS-CRYPTO-1 (algorithm choice) and MASVS-CRYPTO-2 (key management).
    21 repo stars
  2. ▌
    Path Traversal Lfi · shulkwisec
    Path traversal and LFI playbook. Use when file paths, download endpoints, include operations, archive extraction, or wrapper behavior may expose filesystem control.
    21 repo stars
  3. ▌
    Pentester Opencode · shulkwisec
    Full penetration test using MCP tools — recon, scanning, exploitation, and reporting. Tailored for OpenCode (BYO LLM). Supports network/web targets and local codebases. Chains into analyze-cve, threat-modeling, and remediate skills automatically.
    21 repo stars
  4. ▌
    Security Passwords · shulkwisec bundle
    Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).
    21 repo stars
  5. ▌
    Security Usernames · shulkwisec bundle
    Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing.
    21 repo stars
  6. ▌
    Security Webshells · shulkwisec bundle
    Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.
    21 repo stars
  7. ▌
    Sqli SQL Injection · shulkwisec bundle
    SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.
    21 repo stars
  8. ▌
    Subdomain Takeover · shulkwisec
    Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned cloud resources, expired third-party services, or unclaimed SaaS tenants that an attacker can register to serve content under the victim's domain.
    21 repo stars
  9. ▌
    Web Fingerprinting · shulkwisec
    Identify web server type/version, framework, and application entry points via banner grabbing, HTTP header analysis (Server, X-Powered-By, X-Generator), cookie names (CAKEPHP, laravel_session, wp-settings), HTML meta generators, robots.txt, source map files (.map), JS hardcoded secrets, and Google dorking (site:, inurl:, filetype:, intitle:) with tools Nikto, WhatWeb, Wappalyzer, Nmap, Shodan, Burp Suite, OWASP ZAP, Waybackurls.
    21 repo stars
  10. ▌
    Websocket Security · shulkwisec
    WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.
    21 repo stars
  11. ▌
    Windows Av Evasion · shulkwisec bundle
    AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.
    21 repo stars
  12. ▌
    Business Logic Vuln · shulkwisec
    Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.
    21 repo stars
  13. ▌
    Csp Bypass Advanced · shulkwisec
    Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.
    21 repo stars
  14. ▌
    Default Credentials · shulkwisec
    Identify and exploit default or weak credentials on web application login forms, admin panels, CMS backends (WordPress wp-admin, Joomla, Drupal), and embedded device management interfaces. Signals include framework fingerprinting (WhatWeb, Wappalyzer, Nikto), exposed admin paths from robots.txt/dirbusting, and weak password policy acceptance of "Password1" or "123456". Tools: Burp Suite Intruder, Hydra, Medusa, OWASP ZAP.
    21 repo stars
  15. ▌
    Hackerone Brain MCP Server · shulkwisec
    Use the H1 Brain MCP Server to pull HackerOne program policies, scope definitions, and disclosed vulnerability reports directly into Claude's context. Based on Critical Thinking Bug Bounty Podcast Episode 166.
    21 repo stars
  16. ▌
    Kernel Exploitation · shulkwisec bundle
    Linux kernel exploitation playbook. Use when exploiting kernel vulnerabilities (UAF, OOB, race condition, type confusion) for privilege escalation via commit_creds, modprobe_path overwrite, or kernel ROP chains in CTF and real-world scenarios.
    21 repo stars
  17. ▌
    Mobile Code Quality · shulkwisec
    Detects code quality vulnerabilities in mobile apps (Android/iOS). Trigger on: SQL injection in SQLite, JavaScript injection in WebViews, intent injection, unsafe deserialization, NSKeyedUnarchiver, NSCoding, Java serialization, Parcelable, buffer overflow, JNI native code, PIE disabled, NX disabled, stack canary absent, RELRO, ARC disabled, third-party library CVE, vulnerable dependency, outdated SDK, targetSdkVersion, update enforcement missing, implicit Intent, URL loading in WebView, object persistence, memory corruption, OWASP dependency check. Covers MASVS-CODE-1/2/3/4.
    21 repo stars
  18. ▌
    Ntlm Relay Coercion · shulkwisec bundle
    NTLM relay and authentication coercion playbook. Use when capturing and relaying NTLM authentication to escalate privileges via SMB, LDAP, HTTP, or MSSQL relay targets, combined with PetitPotam, PrinterBug, and other coercion methods.
    21 repo stars
  19. ▌
    Prototype Pollution · shulkwisec
    Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON bodies, deep assign), when configuring libraries via untrusted keys, or when hunting RCE gadgets via polluted Object.prototype in Node or the browser.
    21 repo stars
  20. ▌
    Session Search Tool · shulkwisec
    Build a custom session search tool that indexes and queries past Claude Code CLI chat logs to retrieve historical findings, techniques, and context. Based on Critical Thinking Bug Bounty Podcast Episode 166.
    21 repo stars
  21. ▌
    Web Cache Deception · shulkwisec bundle
    Web cache deception and poisoning playbook. Use when CDN, reverse proxy, or application caching may serve sensitive authenticated content to other users due to path confusion or cache key manipulation.
    21 repo stars
  22. ▌
    Web Cache Poisoning Complete Deep Dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21 repo stars
  23. ▌
    Ad Asreproast Attack · shulkwisec bundle
    Exploit Active Directory environments using AS-REP Roasting. This skill details how to identify user accounts with the 'Do not require Kerberos preauthentication' (DONT_REQ_PREAUTH) attribute set, request their AS-REP tickes without a password, and crack the encrypted component offline to recover plaintext credentials.
    21 repo stars
  24. ▌
    Business Logic Flaws · shulkwisec
    Business logic flaws are application vulnerabilities where valid functions are abused in unintended ways: price manipulation via hidden field tampering, workflow step-skipping, function call limit bypass (coupon reuse), process timing exploitation (race conditions on balance updates), and request forging via guessable/predictable parameters. Detect using Burp Suite proxy interception, HTTP POST/GET parameter analysis, and misuse-case testing against multi-step workflows. Tools: Burp Suite, OWASP ZAP.
    21 repo stars
  25. ▌
    Defi Attack Patterns · shulkwisec
    DeFi attack pattern playbook. Use when analyzing flash loan attacks, price oracle manipulation, MEV sandwich attacks, governance exploits, bridge vulnerabilities, and token standard edge cases in decentralized finance protocols.
    21 repo stars
  26. ▌
    Dependency Confusion · shulkwisec
    Supply-chain testing via package-manager dependency confusion: when internal package names resolve to attacker-controlled public registries, leading to malicious install and script execution. Use for npm/pip/gem/Maven/Composer/Docker manifest review and authorized red-team supply-chain exercises.
    21 repo stars
  27. ▌
    Django SQL Injection · shulkwisec bundle
    Identify and exploit SQL Injection vulnerabilities in Django applications, specifically focusing on edge cases involving raw querysets (`RawSQL`), improper use of `.extra()`, and poorly sanitized filters where Django's typical ORM protections are bypassed.
    21 repo stars
  28. ▌
    Kerberoasting Attack · shulkwisec bundle
    Exploit Active Directory environments using Kerberoasting. This skill details how to identify Service Principal Names (SPNs) associated with user accounts, request their TGS tickets, and crack the RC4 encrypted component offline to recover service account passwords.
    21 repo stars
  29. ▌
    LLM Prompt Injection · shulkwisec bundle
    LLM prompt injection playbook. Use when testing AI/LLM applications for direct injection, indirect injection via RAG/browsing, tool abuse, data exfiltration, MCP security risks, and defense bypass techniques.
    21 repo stars
  30. ▌
    Os Command Injection Complete Deep Dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21 repo stars
  31. ▌
    Password Reset Flaws · shulkwisec
    Exploit weak password reset and change flows via CSRF on reset forms, cross-user password modification by swapping username parameters, token predictability in reset links, reset displaying old password in plaintext (revealing weak storage), missing current-password verification on change forms, and session hijacker lockout via passwordless change. Test with Burp Suite, OWASP ZAP following OWASP Forgot Password Cheat Sheet.
    21 repo stars
  32. ▌
    Race Conditions Deep Dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21 repo stars
  33. ▌
    Vlan Hopping Attacks · shulkwisec bundle
    Execute VLAN Hopping attacks to bypass Layer 2 network segmentation constraints. Exploit misconfigured switch ports utilizing Switch Spoofing natively via Dynamic Trunking Protocol (DTP) and specifically Double Tagging (802.1Q) inherently to unconditionally access isolated networks natively.
    21 repo stars
  34. ▌
    Buffer Overflow Stack · shulkwisec bundle
    Identify, exploit, and write custom payloads for classic Stack-Based Buffer Overflows in 32-bit and 64-bit applications. Use this skill when conducting exploit development, reverse engineering custom network protocols, or preparing for advanced certifications (OSCP, OSEP). Covers fuzzing, controlling EIP/RIP, identifying bad characters, generating shellcode, finding return/JMP instructions, and gaining reverse shells.
    21 repo stars
  35. ▌
    Business Logic Bypass · shulkwisec bundle
    Identify and exploit flaws in the core business rules and logic of web applications. This skill focuses on manipulation of application workflows, pricing, inventory limitations, and multi-step processes. Use this skill when bug hunting or testing e-commerce, banking, or SaaS platforms where standard technical vulnerabilities (e.g., XSS/SQLi) are not present but the application's logic is flawed.
    21 repo stars
  36. ▌
    CSV Formula Injection · shulkwisec
    CSV/spreadsheet formula injection (DDE, Excel/LibreOffice, Google Sheets IMPORT*). Use when exports, imports, or user fields feed spreadsheets or reporting tools.
    21 repo stars
  37. ▌
    Dll Hijacking Privesc · shulkwisec bundle
    Exploit local systems via DLL load order hijacking. This skill details how to identify applications on Windows that insecurely load Dynamic Link Libraries (DLLs) and how to substitute a legitimate DLL with a malicious one to achieve privilege escalation or persistent access.
    21 repo stars
  38. ▌
    Dns Rebinding Attacks · shulkwisec
    DNS rebinding attack playbook. Use when testing applications that trust DNS resolution for origin checks, interact with internal services from browser context, or when SSRF is not possible server-side but the target has client-side fetch/XHR to attacker-controlled domains.
    21 repo stars
  39. ▌
    Docker Daemon Privesc · shulkwisec bundle
    Exploit misconfigured Docker environments, specifically focusing on privilege escalation via an exposed Docker daemon socket (`docker.sock`) or membership in the local `docker` user group to achieve root access on the host system.
    21 repo stars
  40. ▌
    IOS Pentesting Tricks · shulkwisec bundle
    iOS pentesting playbook. Use when testing iOS applications for keychain extraction, URL scheme hijacking, Universal Links exploitation, runtime manipulation, binary protection analysis, data storage issues, and transport security bypass during authorized mobile security assessments.
    21 repo stars
  41. ▌
    Kubernetes Pentesting · shulkwisec
    Kubernetes penetration testing playbook. Use when targeting Kubernetes clusters via API server, RBAC enumeration, service account abuse, etcd access, Kubelet API, pod escape, cloud-specific metadata, admission webhook bypass, and registry secrets.
    21 repo stars
  42. ▌
    Linux Security Bypass · shulkwisec
    Linux security mechanism bypass playbook. Use when facing restricted bash/rbash, read-only or noexec filesystems, AppArmor, SELinux, seccomp filters, or audit logging that must be evaded during post-exploitation.
    21 repo stars
  43. ▌
    Macos Security Bypass · shulkwisec bundle
    macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentest engagements.
    21 repo stars
  44. ▌
    Recon And Methodology · shulkwisec
    Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fingerprinting technology, and building a structured testing plan for a new target.
    21 repo stars
  45. ▌
    Rsa Attack Techniques · shulkwisec bundle
    RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to recover plaintext by exploiting weak keys, small exponents, shared factors, or padding oracles.
    21 repo stars
  46. ▌
    Smtp Open Relay Abuse · shulkwisec bundle
    Identify and exploit SMTP Open Relays. This skill teaches how to test mail servers to determine if they process email delivery regardless of the sender or recipient domain, enabling attackers to spoof internal addresses and bypass basic anti-phishing controls.
    21 repo stars
  47. ▌
    Traffic Analysis Pcap · shulkwisec
    Traffic analysis and PCAP forensics playbook. Use when analyzing network captures including Wireshark filters, protocol analysis (HTTP/DNS/FTP/SMTP/USB/WiFi), data extraction, covert channel detection, PCAP repair, TLS decryption, and tshark command-line analysis.
    21 repo stars
  48. ▌
    Upload Insecure Files · shulkwisec bundle
    Insecure file upload playbook. Use when testing upload validation, storage paths, processing pipelines, preview behavior, overwrite risks, and upload-to-RCE chains.
    21 repo stars
  49. ▌
    Waf Bypass Techniques · shulkwisec bundle
    WAF bypass methodology and generic evasion techniques. Use when a web application firewall blocks injection payloads (SQLi, XSS, RCE) and you need to craft bypasses using encoding, protocol-level tricks, or WAF-specific weaknesses.
    21 repo stars
  50. ▌
    Yara Rule Development · shulkwisec bundle
    Develop and deploy advanced YARA rules, the industry standard "pattern-matching swiss army knife" for malware researchers. Use this skill to identify, classify, and hunt for specific malicious binaries (APT implants, ransomware) across enterprise networks, memory dumps, and VirusTotal based on hexadecimal signatures, API imports, and behavioral strings.
    21 repo stars
  51. ▌
    API Auth And JWT Abuse · shulkwisec
    API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.
    21 repo stars
  52. ▌
    Arbitrary Write To Rce · shulkwisec
    Arbitrary write to RCE playbook. Use when you have an arbitrary write primitive (from heap exploitation, format string, or OOB write) and need to convert it into code execution by targeting GOT, hooks, _IO_FILE vtable, exit_funcs, TLS_dtor_list, modprobe_path, .fini_array, or C++ vtables.
    21 repo stars
  53. ▌
    AWS Imdsv2 Ssrf Bypass · shulkwisec bundle
    Exploit Server-Side Request Forgery (SSRF) vulnerabilities to extract AWS IAM credentials from the Instance Metadata Service version 2 (IMDSv2). This skill details how to bypass the token requirement of IMDSv2 by chaining HTTP verbs (PUT then GET) if the SSRF vulnerability allows full control over the request headers and methods.
    21 repo stars
  54. ▌
    Bgp Hijacking Concepts · shulkwisec bundle
    Understand the mechanics of Border Gateway Protocol (BGP) Hijacking, where an attacker creatively manipulates Internet routing tables to intercept, monitor, or drop massive volumes of network traffic destined for legitimate Autonomous Systems (AS).
    21 repo stars
  55. ▌
    Cspt · shulkwisec
    Hunt Client-Side Path Traversal vulnerabilities where attacker-controlled input is concatenated into the path of a fetch() or XHR request, enabling redirection and chaining to XSS or data exfiltration.
    21 repo stars
  56. ▌
    Hack · shulkwisec
    Routes security testing tasks to the correct vulnerability category, guiding recon, validation, privilege escalation, and chain building for web application and API security assessments.
    21 repo stars
  57. ▌
    Ssti · shulkwisec
    Detect and exploit Server-Side Template Injection vulnerabilities across multiple template engines including Jinja2, Twig, Freemarker, and Velocity, with payloads for sandbox escape and remote code execution. Includes detection methodology, bypass techniques, and fix patterns.
    21 repo stars
  58. ▌
    Osint · shulkwisec
    Conduct passive OSINT reconnaissance on target organizations using a MITRE ATT&CK framework. Discovers employees, email patterns, subdomains, infrastructure, leaked credentials, and cloud assets with confidence-scored findings.
    21 repo stars
  59. ▌
    Report · shulkwisec bundle
    Generate a NullPointer Studio styled PDF penetration test report from findings.json, producing a professional dark-themed PDF with executive summary, risk dashboard, per-finding cards, and remediation summary.
    21 repo stars
  60. ▌
    API Sec · shulkwisec
    Routes API security testing into recon, authorization, token abuse, or hidden-parameter workflows based on observed endpoint characteristics.
    21 repo stars
  61. ▌
    Dom Xss · shulkwisec
    Detect and exploit DOM-based XSS vulnerabilities by auditing JavaScript for tainted data flow from controllable sources to dangerous sinks, with payloads and bypass techniques for client-side testing.
    21 repo stars
  62. ▌
    Auth Sec · shulkwisec
    Routes authentication and authorization testing efforts by identifying the primary attack surface — login mechanics, object authorization, browser trust boundaries, or identity protocols such as JWT/OAuth/SAML — before selecting a deeper skill.
    21 repo stars
  63. ▌
    Codebase · shulkwisec bundle
    Performs a white-box source code security review structured around OWASP ASVS 5.0, mapping attack surfaces, tracing data flows, and chaining into downstream penetration testing and threat modeling skills.
    21 repo stars
  64. ▌
    JWT Authentication Complete Deep Dive · shulkwisec bundle
    Provides exact payloads and bypass techniques for every PortSwigger JWT authentication lab variant, from unverified signatures to algorithm confusion attacks.
    21 repo stars
  65. ▌
    Bola Idor · shulkwisec
    Detect and exploit Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities in APIs and web applications.
    21 repo stars
  66. ▌
    Dom Based Vulnerabilities Complete Deep Dive · shulkwisec bundle
    Provides exact payloads and bypass techniques for every PortSwigger DOM-based vulnerability lab variant, including zero-day extensions and blue team detection strategies.
    21 repo stars
  67. ▌
    Remediate · shulkwisec
    Generates specific, implementable fixes for each vulnerability finding, producing code patches, configuration changes, dependency updates, and IaC fixes with before/after code and verification steps.
    21 repo stars
  68. ▌
    Param Fuzz · shulkwisec
    Systematically fuzz web applications for hidden content and input validation vulnerabilities across directories, files, parameters, and authentication bypasses.
    21 repo stars
  69. ▌
    File Upload Vulnerabilities Deep Dive · shulkwisec bundle
    Exploits file upload vulnerabilities across PortSwigger lab variants with exact payloads, bypass techniques, and zero-day escalation methods.
    21 repo stars
  70. ▌
    Email Security · shulkwisec
    Audits email infrastructure security by testing SPF, DKIM, DMARC, open relay, spoofing resilience, MTA-STS, TLS-RPT, and SMTP configuration using standard security tools.
    21 repo stars
  71. ▌
    AWS Metadata Ssrf · shulkwisec bundle
    Exploit SSRF vulnerabilities in AWS EC2-hosted applications to extract IAM credentials and User Data from the Instance Metadata Service, including techniques for bypassing basic filters against IMDSv1.
    21 repo stars
  72. ▌
    Bb Huge · shulkwisec bundle
    Initializes bug bounty hunt workspaces, logs vulnerability findings with severity and evidence, and enriches them throughout a session.
    21 repo stars
  73. ▌
    Cross Site Scripting Xss Complete Deep Dive · shulkwisec bundle
    Provides a complete deep-dive into Cross-Site Scripting (XSS) with exact payloads and bypass techniques for every PortSwigger lab variant, from apprentice to expert level.
    21 repo stars
  74. ▌
    Xxe · shulkwisec
    Detect and exploit XML External Entity (XXE) injection vulnerabilities in XML parsers, including file disclosure, SSRF, and blind out-of-band exfiltration.
    21 repo stars
  75. ▌
    Cors Misconfiguration Complete Deep Dive · shulkwisec bundle
    Provides a structured deep-dive into CORS misconfiguration vulnerabilities with exact payloads for every PortSwigger lab variant, including zero-day escalation techniques and blue-team detection guidance.
    21 repo stars
  76. ▌
    Csrf · shulkwisec
    Detect and exploit Cross-Site Request Forgery vulnerabilities by testing for missing or predictable CSRF tokens, absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type, with payloads and bypass techniques for security testing.
    21 repo stars
  77. ▌
    Ssrf · shulkwisec
    Detect and exploit Server-Side Request Forgery vulnerabilities by identifying user-controlled URL parameters, testing for internal service access, cloud metadata endpoints, and file scheme reads, with bypass techniques for common filters.
    21 repo stars
  78. ▌
    Gh Export · shulkwisec
    Formats all confirmed pentest findings from findings.json into copy-pasteable GitHub issue markdown blocks, following the AppSec reporting guide template.
    21 repo stars
  79. ▌
    2fa Multi Factor Bypass · shulkwisec bundle
    Exploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely. Techniques include response manipulation, referal spoofing, token reuse, and predictable backup codes.
    21 repo stars
  80. ▌
    AI Redteam · shulkwisec bundle
    AI/LLM red-team assessment using the OWASP LLM Top 10 (2025) + OWASP AI Testing Guide (AITG v1, Nov 2025) frameworks, plus OWASP MCP Top 10 runtime testing for agentic/MCP targets. Tests prompt injection, jailbreaks, system prompt leakage, sensitive data extraction, excessive agency, improper output handling, model extraction, content bias, evasion, membership inference, MCP token exposure, MCP command injection, and more. Uses four tools in combination: FuzzyAI (single-turn jailbreak fuzzing), PyRIT (multi-turn orchestrated attacks), Garak (probe-based vulnerability scanning), and promptfoo (plugin-based red-team evaluation). Each tool covers different OWASP categories; running them together gives systematic coverage. Includes a conditional MCP reconnaissance phase and a post-access AI infrastructure phase (chained from /post-exploit). Produces: OWASP LLM Top 10 + AITG + MCP coverage matrix, findings per category, architecture diagram of the AI system, PoCs for confirmed exploits. Chains into /gh-export for
    21 repo stars
  81. ▌
    Colang Gen · shulkwisec bundle
    Generates NeMo Guardrails Colang (.co) files and YAML config blocks from a plain-language description of a chatbot's purpose, allowed behaviors, and constraints. Use this skill whenever a user wants to build guardrails for a chatbot, define allowed intents for an LLM, create an AI firewall with NeMo Guardrails, generate Colang flow definitions, or configure a semantic allow-list for a bot. Trigger this skill even when the user just describes what their bot should and shouldn't do — generating the Colang and YAML is almost always what they need next.
    21 repo stars
  82. ▌
    Compliance · shulkwisec bundle
    Full ASVS 5.0 compliance assessment against a codebase and/or architecture diagrams. Reads all 346 controls from the companion CSV, performs targeted code analysis per control, and produces a complete matrix marked COMPLIANT / NON_COMPLIANT / NOT_RELEVANT — with per-control reasoning and evidence (code snippets, file:line references, diagram observations). Outputs a reviewed CSV matrix and a self-contained HTML evidence report.
    21 repo stars
  83. ▌
    Metasploit · shulkwisec
    Exploit validation and exploitation using Metasploit Framework. Runs in a dedicated Docker container (separate from Kali). Validates CVEs discovered by nuclei, nikto, or other scanners with actual exploit modules. Covers exploit selection, payload configuration, exploitation, and post-exploitation pivoting. Uses msfconsole, msfvenom, and the Metasploit module database. Chains from /pentester, /analyze-cve, or /post-exploit when exploitable CVEs are confirmed.
    21 repo stars
  84. ▌
    Websockets Deep Dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21 repo stars
  85. ▌
    Xss Stored · shulkwisec
    Stored XSS (persistent XSS) occurs when attacker-supplied input is saved server-side and later rendered unencoded to other users. Common injection points include profile fields, comments, forum posts, file upload filenames, and application logs. Detect via PHP `$_GET/$_POST/$_REQUEST/$_FILES`, ASP `Request.Form`, JSP `request.getParameter`, and BeEF hook injection. Tools: Burp Suite, OWASP ZAP, BeEF, PHP Charset Encoder, Hackvertor.
    21 repo stars
  86. ▌
    Amend Skill · shulkwisec
    Inspects a skill's SKILL.md and its observations/runs.md log, identifies failure patterns, and proposes a targeted amendment to improve the skill. Trigger on: "improve this skill", "fix this skill", "update this skill", "why does X keep failing", "this skill is wrong", "add this to the skill", or automatically when observations/<skill-name>/runs.md contains 3 or more failure entries. Outputs the amendment as a diff the user can review before applying. Records the amendment rationale in observations/<skill-name>/runs.md after user confirmation.
    21 repo stars
  87. ▌
    Amsi Bypass · shulkwisec bundle
    Bypass the Windows Antimalware Scan Interface (AMSI) using memory patching, reflection, and obfuscation techniques. Execute undetected PowerShell, VBScript, JScript, and .NET assemblies in-memory without triggering Microsoft Defender or third-party AV/EDR solutions. Use this skill during Red Team engagements when loading offensive tools (Mimikatz, Rubeus, SharpHound) in memory on defended Windows endpoints.
    21 repo stars
  88. ▌
    Analyze Cve · shulkwisec
    CVE Vulnerability Analysis Workflow
    21 repo stars
  89. ▌
    Auth Bypass · shulkwisec
    Bypass authentication via forced browsing to protected URLs, parameter tampering (authenticated=yes, debug=true, fromtrustIP=true), session ID prediction from linear/incremental cookies, SQL injection on login forms, PHP unserialize() boolean type juggling (b:1 payload), and credential transport over HTTP. Detectable with Burp Suite, OWASP ZAP, WebGoat.
    21 repo stars
  90. ▌
    HTTP Host Header Attacks Deep Dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21 repo stars
  91. ▌
    Web LLM Attacks Deep Dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21 repo stars
  92. ▌
    LLM Testing · shulkwisec bundle
    Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.
    21 repo stars
  93. ▌
    Pwn Request · shulkwisec
    Use when hunting Pwn Request vulnerabilities where pull_request_target workflows checkout attacker-controlled PR code and execute it in a privileged context with access to repository secrets. Trigger on: "pwn request", "pull_request_target", "checkout PR head", "npm install in CI", "lifecycle scripts in CI", "preinstall script", "postinstall script", "package.json scripts CI", "npm ci ignore-scripts false", "actions/checkout ref pull request head sha", privileged workflow running PR code, "Gato-X", supply chain via PR lifecycle scripts.
    21 repo stars
  94. ▌
    Web Exploit · shulkwisec bundle
    Deep web exploitation beyond initial scanning. Covers SQLi (blind, OOB, second-order), NoSQL injection (MongoDB, operator bypass), GraphQL injection (introspection, batching, mutation abuse), XSS (reflected/stored/DOM with full source-sink analysis), SSTI (Jinja2/Twig/Freemarker/ERB engine identification and RCE), SSRF chains, file upload bypass (polyglot creation), XXE (blind, DOCX/SVG injection, Content-Type switching), deserialization (Java/PHP/Python/.NET), command injection, path traversal (LFI wrapper bypasses), race conditions, CSRF, JWT attacks (none/key confusion/kid injection), HTTP request smuggling (CL.TE/TE.CL/H2), CRLF injection, open redirect bypass chains, CORS exploitation, web cache deception/poisoning, OAuth misconfiguration, prototype pollution, session management, and business logic flaws. Uses sqlmap (advanced modes), commix, xsser, wapiti, davtest, and manual http(action="request", ...) payloads. Every technique includes actual payloads, commands, and code snippets for immediate use. Ch
    21 repo stars
  95. ▌
    API Security · shulkwisec
    Deep API security assessment beyond surface scanning. Covers the full OWASP API Security Top 10 (2023): Broken Object Level Authorization (BOLA / IDOR), Broken Authentication, Broken Object Property Level Authorization (mass assignment + excessive data exposure), Unrestricted Resource Consumption, Broken Function Level Authorization (BFLA / vertical privilege escalation), Unrestricted Access to Sensitive Business Flows, Server-Side Request Forgery via API parameters, Security Misconfiguration, Improper Inventory Management (shadow/zombie/deprecated endpoints, v1/v2 drift), and Unsafe Consumption of third-party APIs. Works across REST, GraphQL, gRPC, SOAP, and MCP servers. Discovers APIs from OpenAPI/Swagger specs, GraphQL introspection, gRPC reflection, .well-known endpoints, JS bundles, and traffic capture. Uses kiterunner, ffuf, schemathesis, restler-fuzzer, openapi-fuzzer, graphql-cop, clairvoyance, batchql, inql, jwt_tool, postman, mitmproxy, and manual http(action="request", ...) payloads. Every techniqu
    21 repo stars
  96. ▌
    Authz Bypass · shulkwisec
    Test horizontal and vertical authorization bypass via session ID swapping between accounts, IDOR through parameter manipulation (invoice=, user=, menuitem=, EventID=), and special header injection (X-Original-URL, X-Rewrite-URL, X-Forwarded-For, X-Remote-IP, X-Client-IP with 127.0.0.1/localhost/RFC1918 values). Tools: Burp Suite with Autorize/AuthMatrix extensions, OWASP ZAP Access Control Testing add-on.
    21 repo stars
  97. ▌
    Clickjacking · shulkwisec
    Clickjacking playbook. Use when testing whether target pages can be framed, whether X-Frame-Options or CSP frame-ancestors are properly configured, and whether UI redress attacks can trigger sensitive actions.
    21 repo stars
  98. ▌
    GRAPHQL Idor · shulkwisec bundle
    Identify and exploit Insecure Direct Object Reference (IDOR) or Broken Object Level Authorization (BOLA) vulnerabilities specifically within GraphQL APIs. This skill focuses on manipulating node IDs, changing variables, and utilizing aliases to access unauthorized data.
    21 repo stars
  99. ▌
    GRAPHQL API Deep Dive · shulkwisec bundle
    Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques
    21 repo stars
  100. ▌
    Post Exploit · shulkwisec
    Post-exploitation workflow. Covers privilege escalation (Linux SUID/sudo/kernel, Windows UAC/service/token), persistence assessment, local enumeration, credential harvesting, and pivot preparation. Structured workflows for Linux and Windows targets using impacket, netexec, john, linpeas/winpeas, and standard Kali tools. Includes kernel exploit reference tables, GTFOBins exploitation chains, Potato attack selection, Docker/container escapes, DLL hijacking, SSH key harvesting, credential recovery from memory, and Windows token manipulation. Chains from /pentester or /credential-audit when access is obtained.
    21 repo stars