Agent Skills by carlos-reyes-utp
Showing 31 vetted skills indexed across 1 GitHub repositories.
lazyweb
Search real product UI screenshots and design patterns via Lazyweb MCP.
hunt-api-misconfig
Identify API security misconfigurations enabling privilege escalation and token forgery.
hunt-xss
Identify and validate XSS vulnerabilities across reflected, stored, and DOM-based scenarios.
hunt-csrf
Detect exploitable CSRF weaknesses in authenticated web applications.
hunt-ssti
Detect server-side template injection via engine-specific reflection probes.
report-writing
Convert validated security findings into submission-ready bug bounty reports.
bug-bounty
Guide end-to-end bug bounty workflows from recon to validated vulnerability reporting.
hunt-race-condition
Test one-time business logic endpoints for duplicate effects under concurrent request timing.
mid-engagement-ir-detection
Capture and analyze security-state changes during red-team engagements to produce evidence-grade IR findings.
bugcrowd-reporting
Select VRT nodes, override severity, and structure Bugcrowd submission descriptions.
hunt-subdomain
Detect DNS misconfigurations enabling subdomain takeover via CNAME chain fingerprinting.
redteam-report-template
Generate client-facing red-team report templates with structured findings and DOCX output.
security-arsenal
Provide structured payload sets and triage rules for web security testing.
hunt-business-logic
Identifies business logic vulnerabilities in web application workflows.
hunt-sharepoint
Fingerprint Microsoft SharePoint Server versions and probe anonymous endpoints for misconfigurations.
hunt-sqli
Probe application inputs to identify and confirm SQL injection vulnerabilities.
bb-methodology
Orchestrates bug bounty hunting with a non-linear 5-phase workflow and critical-thinking framework.
redteam-mindset
Guide red-team operators through reproducible finding validation and full-scope probing.
offensive-osint
Generate structured external reconnaissance probes and triage guidance for authorized OSINT.
hunt-cache-poison
Detect cache poisoning by testing unkeyed headers and URL manipulations.
hunt-ato
Hunt account takeover paths across authentication and OAuth workflows.
hunt-misc
Probe role boundaries, auth flows, and token scope enforcement for misc vulnerabilities.
hunt-ssrf
Map URL parameters and confirm SSRF sinks via out-of-band callbacks.
bb-local-toolkit
Guide bug bounty engagements through recon, hunting, validation, and reporting.