Find the skill for your next task.

Browse reusable Agent Skills, each with a clear purpose and practical guidance.

command-injection

Hunt OS command injection (CWE-78) — user input reaching shell, exec, or system calls. Covers argument-array bypasses, path confusion, and template-string injection in modern frameworks.

4.72k repo starsObserved in 1 repos
DevOps & Security

conops-template

Concept of Operations document creation — executive summary, threat actor profiling, attack narrative, kill chain design, communication plan, deconfliction.

4.72k repo starsObserved in 1 repos
Business

curate-research

把一批 Harness Engineering 调研候选(文章/论文/工具的 URL)走完「抓取→翻译→评审→收录→清理」流水线,整合进本仓库 works/ 与 references/articles.md,并保持 C1–C9 计数一致。当用户说"处理这批调研候选 / 收录这些链接 / 整理 translate / 把这几篇翻译收进来"时使用。这是仓库给自己用的策展 harness。

4.72k repo starsObserved in 1 repos
Research

decepticon

Drive Decepticon — an autonomous multi-agent red-team framework — over MCP to run authorized penetration tests and bug-bounty engagements end to end, then watch and steer them live from chat. Launch an engagement against a target, poll its transcript to narrate progress, send messages to refocus it, and pull findings as SARIF. Use when the user asks to run a pentest/red-team engagement, hunt a bug bounty, do recon, exploit/scan a host, web app, API, network, cloud, Active Directory, mobile app, or smart contract WITH Decepticon — or to check/resume a running engagement or report what Decepticon found. Triggers: run a decepticon engagement, pentest this with decepticon, bug bounty, recon this target, red team this, scan this host, resume the engagement, what did decepticon find, decepticon status. Do NOT use for ad-hoc local tool runs (running nmap/sqlmap/ffuf directly) when no Decepticon server is involved — this drives the Decepticon orchestrator, not raw tools.

4.72k repo starsObserved in 1 repos
DevOps & Security

engagement-startup

Mandatory first-turn startup procedure — checks for existing engagements, resume/new selection, workspace initialization.

4.72k repo starsObserved in 1 repos
Agent Building

ics-dnp3

DNP3 attack — TCP/20000 (or 19999 serial-over-TCP) outstation enumeration, binary input / analog input poll, control relay output block (CROB) actuation, unsolicited reporting abuse, DNP3 Secure Authentication (DNP3-SA) downgrade, vendor-specific objects.

4.72k repo starsObserved in 1 repos
DevOps & Security

ics-overview

Use when the target is an industrial control system or operational technology network running Modbus, BACnet, S7Comm/S7Comm Plus, DNP3, OPC-UA, or any PLC/HMI/SCADA stack. Engagements MUST set RoE flag industrial_safety_critical=true; this catalog gates every write-scope operation behind explicit operator confirmation regardless of HITL middleware.

4.72k repo starsObserved in 1 repos
DevOps & Security

ldapi

LDAP injection — auth bypass via filter manipulation, blind data extraction, search filter abuse, DN injection.

4.72k repo starsObserved in 1 repos
DevOps & Security

o365-credential-harvest

Harvest and replay O365 / Entra ID access via the OAuth device-code flow and captured tokens (TokenTactics-style), skipping the password + MFA prompts.

4.72k repo starsObserved in 1 repos
DevOps & Security

open-web

Resilient public-page reading and OSINT keyword search — web_search (allowlisted-provider OSINT) and web_fetch (curl_cffi TLS-impersonation grid + headless-browser fallback that gets past WAF/403/anti-bot). Use when a fetch is blocked, a page is JS-rendered, or you need open-web OSINT about a target/org.

4.72k repo starsObserved in 1 repos
Research