Ashton Vaughan
Community@ashtonvaughan · Brisbane Australia
18yo IT student @ QUT, Brisbane. Hacking since 9. Building security agents, LLM inference, and tooling for AI agents.
Agent Skills by Ashton Vaughan
Showing 29 vetted skills indexed across 1 GitHub repositories.
negative-testing
Test error handling paths with malformed inputs and boundary conditions.
hardware
Assess IoT hardware security weaknesses across firmware, embedded interfaces, and physical attack surfaces.
anomaly-detection
Profile API endpoints and rank anomalies by deviation from baseline behavior.
hunt
Orchestrate end-to-end bug bounty hunts across HackerOne, Bugcrowd, and Intigriti programs.
vps
Provision and manage Ubuntu 22.04 VPS infrastructure for OOB callbacks and IP rotation.
blind-injection
Detect and prove blind injection surfaces using OOB, timing, and boolean techniques.
idor-harness
Test API endpoints with two accounts to detect IDOR vulnerabilities.
target-research
Create structured target models for bug bounty reconnaissance.
h1-submit
Automate validated bug bounty finding submission as HackerOne H1 reports via API.
headless-mode
Automate unattended API hypothesis testing with stealth delays and logging.
campaign-planner
Coordinate multi-session bug bounty hunts into structured campaigns with attack paths and progress tracking.
memory-corruption
Hunt memory-corruption vulnerabilities in C/C++/Rust binaries through fuzzing and crash triage.
feedback
Classify HackerOne analyst responses and route them to triage handlers.
reverse-engineering
Reverse engineer binaries and firmware using static and dynamic analysis workflows.
blockchain
Identify and mitigate blockchain security risks in smart contracts.
parallel-hunting
Orchestrate parallelized hypothesis testing across non-overlapping endpoint clusters with 3-5 agents.
exploit-gate
Enforce a pre-submission exploit verification gate for vulnerability reports.
mobile
Identify and validate mobile application security weaknesses across Android and iOS.
crypto-audit
Identify cryptographic implementation weaknesses in target crypto operations.
cloud
Identifies and exploits cloud attack surfaces in authorized bug bounty programs.
request-smuggling
Detect HTTP request smuggling and desync vulnerabilities across front-end and back-end proxies.
report-psychology
Generate structured H1 vulnerability reports with CVSS 3.1 scoring.
creds
Manage bug bounty credentials across targets with token-based authentication flows.
sast
Identify security weaknesses in source code across languages and frameworks.