vichhka-git
- 4 skills
- 0 followers
- 9 hours ago last updated
- ▌ Renef · vichhka-git bundleUse when operating renef / renef.io to instrument Android ARM64 apps: hooking native and Java functions, scanning/reading/writing/patching process memory, tracing syscalls (renef-strace), stack backtraces, value/memory cheats, and writing Lua 5.4 scripts. Reach for this for SSL pinning bypass, root/debugger detection bypass, function tracing, crypto key logging, game memory editing/cheats, CTF native challenges, or porting Frida JS / GameGuardian (gg.*) scripts to renef. Triggers: "renef", "renef.io", ".renef script", "renef-strace", "hook this Android function", "bypass SSL pinning with renef", "port this Frida/GameGuardian script to renef".
- ▌ Open Tor · vichhka-git bundleSearch and access the Tor dark web and .onion hidden services. Use when user asks to search dark web, investigate .onion sites, check for dark web data leaks, fetch onion URLs, hunt ransomware groups, look up leaked credentials, conduct Tor-based OSINT, or monitor dark web activity. Provides 12 search engines, batch scraping, entity extraction, relevance scoring, and export to CSV/JSON/STIX/MISP. Requires Tor running locally (socks://127.0.0.1:9050).
- ▌ PDF Reader · vichhka-git bundleConvert PDFs to accurate Markdown for AI reading using pdf-inspector (Rust) — smart text/scanned classification, per-page OCR routing, page markers, and context-size chunking. Cross-platform (macOS/Linux/Windows).
- ▌ Kilo Security Review · vichhka-git bundleFull-stack security review skill for Kilo CLI and OpenCode that produces pentest-grade reports with CVSS scores, HackerOne bug-bounty references, working exploit PoCs, and concrete code fixes. Use this skill whenever the user asks to: audit code, security review a repo or file, find vulnerabilities, run a pentest or security scan, check OWASP Top 10 / API Top 10 / Mobile Top 10, do a bug bounty recon, conduct a threat model, review code before a release, look for SQLi / XSS / SSRF / IDOR / RCE / auth bypass, investigate a CVE, or ask "is this code secure?". Works on web, API, mobile (Android + iOS + React Native), cloud/IaC, and full-stack projects. Always use this skill — it prevents false positives, enforces PoC-backed findings, and produces reports that match professional pentest quality.