Agent Skills by cmndcntrl
Showing 50 vetted skills indexed across 1 GitHub repositories.
project-discovery-workflow
Automate project discovery with a 4-phase pipeline for asset enumeration, fingerprinting, vulnerability scanning, and alerting.
hunt-llm-ai
Detect and mitigate AI and LLM vulnerabilities like prompt injection and exfiltration.
hunt-api-misconfig
Detect API security misconfigurations including mass assignment, JWT attacks, and CORS vulnerabilities.
hunt-xss
Identify and exploit reflective, stored, and DOM-based XSS vulnerabilities in web applications.
meme-coin-audit
Audit meme coin token contracts for rug pulls and honeypots on EVM and Solana.
hunt-csrf
Scan web applications for CSRF vulnerabilities using predefined patterns.
hunt-dispatch
Load attack and reconnaissance skill sets based on target fingerprinting and mode selection.
hunt-ssti
Detect and exploit server-side template injection vulnerabilities across template engines.
report-writing
Generate bug bounty reports with templates for HackerOne, Bugcrowd, Intigriti, and Immunefi.
hunt-idor
Analyze web applications for IDOR vulnerabilities using bug bounty reports and attack patterns.
bug-bounty
Automate bug bounty workflows from recon to vulnerability reporting.
hunt-saml
Detect SAML and SSO vulnerabilities including XML Signature Wrapping and XXE.
hunt-race-condition
Analyze code and system behavior to detect race condition vulnerabilities.
mid-engagement-ir-detection
Detect security state changes during red-team engagements using Python.
hunt-mfa-bypass
Detect MFA/2FA bypass vulnerabilities across seven web application patterns.
hunt-xxe
Identify XML External Entity vulnerabilities in web applications.
bugcrowd-reporting
Guide Bugcrowd submissions with VRT selection, severity overrides, and OOS rebuttals.
hunt-subdomain
Scan DNS records and verify claimability of unclaimed subdomains.
redteam-report-template
Generate structured red-team client reports from markdown using Pandoc.
supply-chain-attack-recon
Identify software supply-chain vulnerabilities via package squatting and dependency confusion.
security-arsenal
Provide security payloads and bypass techniques for web application penetration testing.
hunt-http-smuggling
Detect HTTP request smuggling vulnerabilities by analyzing header parsing inconsistencies.
hunt-business-logic
Scan web applications for business logic vulnerabilities and generate security reports.
hunt-aspnet
Detect ASP.NET security vulnerabilities and reveal configuration metadata.