Agent Skills by doriangallo
Showing 60 vetted skills indexed across 1 GitHub repositories.
file-access-vuln
Diagnose file access vulnerabilities across download endpoints and upload processing flows.
injection-checking
Route injection-class security issues to the matching deep-topic skill by sink type.
prototype-pollution
Detect prototype pollution via __proto__ and constructor.prototype merge paths.
saml-sso-assertion-attacks
Detect SAML SSO assertion trust and signature validation weaknesses.
api-sec
Classify API security issues into documentation, authorization, token, or GraphQL categories.
macos-process-injection
Guides macOS code injection via DYLD, XPC/Mach IPC weaknesses, and Electron runtimes for security assessment scenarios.
format-string-exploitation
Exploit format-string vulnerabilities for information disclosure and arbitrary memory writes.
http-host-header-attacks
Test HTTP Host header trust for redirect, cache, SSRF, and vhost bypass.
steganography-techniques
Detect and extract hidden steganographic payloads from images, audio, files, and text.
csv-formula-injection
Detect and mitigate CSV formula injection in spreadsheet exports.
websocket-security
Assess WebSocket endpoints for handshake, session binding, and message-layer vulnerabilities.
graphql-and-hidden-parameters
Probe GraphQL schemas for undocumented fields and authorization gaps.
traffic-analysis-pcap
Repairs PCAPs and analyzes HTTP, DNS, TLS, FTP, SMTP, WiFi, ICMP via protocol-aware inspection and Wireshark filters.
linux-privilege-escalation
Enumerate Linux misconfigurations and select privilege escalation paths to root.
ai-ml-security
Assess security threats across AI/ML supply chains, adversarial examples, and data privacy.
llm-prompt-injection
Identify and mitigate LLM prompt injection vulnerabilities across direct, indirect, and tool execution paths.
hack
Route web and API security testing into an ordered bug bounty methodology.
type-juggling
Identify PHP loose comparison and magic-hash authentication bypass paths.
dangling-markup-injection
Exfiltrate sensitive page data via dangling HTML markup injection.
classical-cipher-analysis
Identify and decrypt classical ciphers using frequency analysis and statistical scoring.
authbypass-authentication-flaws
Identify authentication bypass paths in login, password reset, MFA, and session workflows.
api-recon-and-docs
Enumerate API endpoints, schemas, versions, and hidden surface area for security testing.
smart-contract-vulnerabilities
Detect exploitable vulnerability patterns in Solidity/EVM smart contracts.
mobile-ssl-pinning-bypass
Bypass TLS certificate pinning in Android and iOS apps using runtime hooks and proxy CA trust fixes.