Sachin Sharma avatar

Sachin Sharma

Community

@elementalsouls · India

309Followers
|
38Public Repos
|
77Published Skills

Offensive Security Engineer | Adversary Simulation, Custom Tooling & Automated Reconnaissance | Exploring AI Red Teaming & LLM Security

Agent Skills by Sachin Sharma

Showing 77 vetted skills indexed across 1 GitHub repositories.

elementalsoulselementalsouls
4.0k

hunt-llm-ai

Detect prompt injection, data exfiltration, and cross-tenant leaks in LLM-powered applications.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-api-misconfig

Detect API misconfigurations including mass assignment, prototype pollution, and OData WAF bypasses.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-rag-vector

Detect vector-store and embedding-layer weaknesses in RAG pipelines during authorized security testing.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-jwt-crypto

Detect and exploit JWT signature forgery flaws including alg:none and RS256-to-HS256 key confusion.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-exceptional-conditions

Detect verbose error pages and fail-open behavior by sending malformed input to endpoints.

Community
Intermediate
elementalsoulselementalsouls
4.0k

hunt-nextjs

Detect Next.js vulnerabilities including Server Actions abuse, middleware bypass, and image optimizer SSRF.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-springboot

Detect and exploit Spring Boot vulnerabilities including Actuator exposure, SpEL injection, and Spring4Shell.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-captcha-bypass

Tests web applications for six CAPTCHA bypass patterns including field omission, token replay, and missing server-side validation.

Community
Intermediate
elementalsoulselementalsouls
4.0k

ios-redteam-pipeline

Analyzes iOS apps through IPA acquisition, static analysis, secret extraction, and Frida runtime instrumentation.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-fintech-graphql

Detects money-movement, ledger, and authorization flaws in fintech GraphQL APIs.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-cicd

Detects CI/CD pipeline vulnerabilities across Jenkins, GitHub Actions, GitLab CI, and Terraform state.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-brute-force

Detect missing rate limiting, OTP brute-force paths, and username enumeration on authentication endpoints.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-saml

Detects SAML and SSO vulnerabilities including signature wrapping, comment injection, and signature stripping.

Community
Intermediate
elementalsoulselementalsouls
4.0k

recon-scope-triage

Validates asset ownership in ASM and recon output before security testing begins.

Community
Intermediate
elementalsoulselementalsouls
4.0k

hunt-xxe

Detect and exploit XXE vulnerabilities in XML parsers, file uploads, and SAML endpoints.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-subdomain

Detects and validates subdomain takeover vulnerabilities across cloud and SaaS providers.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-laravel

Detects Laravel-specific vulnerabilities including Ignition RCE, Telescope exposure, and mass assignment flaws.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-sqli

Detects and exploits SQL and NoSQL injection vulnerabilities using payloads from disclosed bug bounty reports.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-html-injection

Detect HTML injection vulnerabilities by reflecting unsanitized markup in web application responses.

Community
Intermediate
elementalsoulselementalsouls
4.0k

hunt-ato

Detects and validates eleven account takeover paths across password reset, OAuth, JWT, and session flows.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-forgot-password

Detects five authentication flaws in forgot-password and account recovery flows.

Community
Intermediate
elementalsoulselementalsouls
4.0k

vmware-vcenter-attack

Maps external attack paths against internet-exposed VMware vCenter, Workspace ONE, and Aria instances.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-dom

Detect DOM clobbering, postMessage hijacking, service worker abuse, and CSS exfiltration vulnerabilities in web applications.

Community
Advanced
elementalsoulselementalsouls
4.0k

hunt-spa-api

Extract backend API routes from SPA JavaScript bundles and test them for missing authentication.

Community
Intermediate