baiqigo
Community@baiqigo
baiqigo maintains 93 evidence-gated offensive security skills for authorized web/API penetration testing, bug bounty hunting, and vulnerability validation.
Agent Skills by baiqigo
Showing 91 vetted skills indexed across 1 GitHub repositories.
jsreverser-mcp-playbook
Guides MCP-based frontend JavaScript reverse engineering from page observation through local environment rebuilding.
hunt-client-reverse
Reverse-engineer first-party JavaScript bundles to recover routes, parameters, and token flows.
evidence-verifier
Verifies artifact integrity, provenance chains, and redaction before graph promotion decisions.
hunt-path-traversal
Validates path traversal boundaries in download, preview, and archive endpoints using controlled marker files.
hunt-llm-ai
Validates data boundaries and tool authorization in LLM chat and agent applications.
hunt-ldap-injection
Validates LDAP filter and attribute boundaries in authentication and directory search interfaces.
hunt-web-crypto
Validates client-side Web Crypto usage and key handling through evidence-gated black-box testing.
blackbox-vuln-orchestrator
Routes authorized black-box Web and API testing evidence into ranked next-action plans.
hunt-mfa-flow
Validates server-side MFA enforcement, one-time code binding, and step-up authentication on sensitive endpoints.
hunt-rag-vector
Validates tenant and ACL isolation in RAG pipelines and vector stores.
hunt-cors
Tests web applications for exploitable CORS misconfigurations with browser-verified proof of credentialed cross-origin reads.
hunt-jwt-crypto
Detect and exploit JWT signature forgery flaws including alg:none and RS256-to-HS256 key confusion.
hunt-xss
Validates XSS vulnerabilities by executing canary payloads in isolated browser contexts.
hunt-csrf
Detects and validates CSRF vulnerabilities in web applications using evidence-gated black-box testing.
hunt-nextjs
Validates Next.js and React SSR applications for exposed data, server actions, and known CVEs.
hunt-springboot
Validates Spring Boot and Actuator exposure through evidence-gated read-only probes.
hunt-ssti
Detects server-side template injection and escalates to RCE across Jinja2, Twig, Freemarker, ERB, and other engines.
hunt-idor
Detects and validates IDOR vulnerabilities in APIs using evidence-gated black-box testing methodology.
network-pentest
Scans TCP ports, grabs banners, and enumerates SMB, DNS, and SNMP services.
writing-for-agents
Write skills, AGENTS.md, and CLAUDE.md documents that agents follow predictably.
hunt-upload-execution
Validates whether uploaded files reach server-side execution boundaries using evidence-gated review.
hunt-cicd
Validates CI/CD pipelines for credential leaks and authorization flaws in authorized scopes.
hunt-kubernetes-exposure
Validates Kubernetes cluster exposure and RBAC misconfigurations through read-only authorized probes.
web-recon
Map target technologies, routes, and observable interfaces into typed case observations.
Frequently Asked Questions About baiqigo
FAQPage SchemaWhat tasks can I perform using baiqigo's skills?▼
You can run authorized black-box web and API vulnerability hunting across 60+ specialist routes: SQLi, XSS, SSRF, XXE, SSTI, IDOR, CSRF, JWT forgery, subdomain takeover, GraphQL, WebSocket, deserialization, and business-logic flaws, plus recon triage, evidence verification, and pre-submission report validation.
Who are these skills designed for?▼
Bug bounty hunters, penetration testers, and red-team operators working on authorized, in-scope targets. Every specialist skill enforces evidence-gated boundaries: own test accounts, marker files, no data exfiltration, no DoS, and no unauthorized targets.
How do the skills work together in a typical engagement?▼
Start with bb-methodology or blackbox-vuln-orchestrator for phase routing, run recon-scope-triage and web-recon for asset mapping, then load specialist hunt-* skills per signal. Finish with triage-validation's 7-Question Gate and evidence-hygiene redaction before submitting any report.
Are baiqigo's skills open source and what do they cost?▼
Licensing varies per skill: several carry a project license under the OpenTgtyLab Worker Protocol v1, frontend-design is Apache-2.0, and most hunt-* skills are maintained by OpenTgtyLab with public bug bounty sources. No paid tier is indicated in the manifest.
What prerequisites or dependencies do the skills require?▼
Skills assume an authorized testing scope and standard offensive-security tooling such as Burp Suite, browser DevTools, and Kali CLI/MCP routing. Protocol skills require OpenTgtyLab Worker Protocol v1 compatibility; hunting skills reference public HackerOne, Bugcrowd, and CVE report corpora.