Agent Skills by brucesongs
Showing 72 vetted skills indexed across 1 GitHub repositories.
security-misconfiguration
Detect and remediate security misconfigurations across web, cloud, and container deployments.
knowledge-ops
Transform session findings into persistent knowledge graphs with linked relationships.
web-xxe
Identify and exploit XML External Entity vulnerabilities in XML-processing endpoints.
binary-reverse
Analyze compiled binaries with radare2 and Ghidra to identify vulnerabilities.
multi-agent-collaboration
Coordinates multiple specialized agents for penetration testing via task decomposition and parallel execution.
docker-patterns
Create reproducible Docker-based security labs with localhost-only bindings and isolation.
detection-engineering
Create and validate Sigma rules, YARA signatures, and SIEM queries as code.
crypto-attacks
Detect weak algorithms, padding, and key management flaws in TLS and JWT configurations.
social-intelligence
Extract real-time social intelligence signals from Reddit, Hacker News, and X.
autonomous-loops
Automate repetitive reconnaissance, scanning, and learning cycles across multiple targets.
secret-management-attack
Map leaked credentials across code, containers, cloud, and CI/CD pipelines.
council
Analyze security questions from attack, defense, and audit perspectives.
network-pentest
Run reconnaissance, scanning, and exploitation workflows against network targets.
tool-mastery
Quantify Kali Linux tool proficiency across 518 tools with structured verification.
mcp-server-patterns
Design secure MCP server patterns that wrap Kali tools with validation and audit logging.
supply-chain-security
Audit dependencies, generate SBOMs, and harden CI/CD pipelines.
vulnerability-assessment
Identify and prioritize security weaknesses using automated scanning and CVE analysis.
recon-osint
Perform OSINT reconnaissance to build target profiles from public sources.
digital-forensics
Analyze disk images, memory dumps, and network artifacts with forensic tools.
security-bounty-hunter
Automate bug bounty reconnaissance, triage, and reporting with CVSS scoring.
ad-ldap-attack
Enumerate Active Directory LDAP environments to reveal users, groups, SPNs, and credential artifacts.
data-scraper-agent
Collect unstructured web data from CVE databases and threat feeds into structured JSON/CSV records.
deep-research
Plan and execute multi-source security research into cited intelligence reports.
exa-search
Perform semantic search across security research results using the Exa API.