Sachin Sharma
Community@elementalsouls · India
Offensive Security Engineer | Adversary Simulation, Custom Tooling & Automated Reconnaissance | Exploring AI Red Teaming & LLM Security
Agent Skills by Sachin Sharma
Showing 77 vetted skills indexed across 1 GitHub repositories.
hunt-llm-ai
Detect prompt injection, data exfiltration, and cross-tenant leaks in LLM-powered applications.
hunt-api-misconfig
Detect API misconfigurations including mass assignment, prototype pollution, and OData WAF bypasses.
hunt-rag-vector
Detect vector-store and embedding-layer weaknesses in RAG pipelines during authorized security testing.
hunt-jwt-crypto
Detect and exploit JWT signature forgery flaws including alg:none and RS256-to-HS256 key confusion.
hunt-exceptional-conditions
Detect verbose error pages and fail-open behavior by sending malformed input to endpoints.
hunt-nextjs
Detect Next.js vulnerabilities including Server Actions abuse, middleware bypass, and image optimizer SSRF.
hunt-springboot
Detect and exploit Spring Boot vulnerabilities including Actuator exposure, SpEL injection, and Spring4Shell.
hunt-captcha-bypass
Tests web applications for six CAPTCHA bypass patterns including field omission, token replay, and missing server-side validation.
ios-redteam-pipeline
Analyzes iOS apps through IPA acquisition, static analysis, secret extraction, and Frida runtime instrumentation.
hunt-fintech-graphql
Detects money-movement, ledger, and authorization flaws in fintech GraphQL APIs.
hunt-cicd
Detects CI/CD pipeline vulnerabilities across Jenkins, GitHub Actions, GitLab CI, and Terraform state.
hunt-brute-force
Detect missing rate limiting, OTP brute-force paths, and username enumeration on authentication endpoints.
hunt-saml
Detects SAML and SSO vulnerabilities including signature wrapping, comment injection, and signature stripping.
recon-scope-triage
Validates asset ownership in ASM and recon output before security testing begins.
hunt-xxe
Detect and exploit XXE vulnerabilities in XML parsers, file uploads, and SAML endpoints.
hunt-subdomain
Detects and validates subdomain takeover vulnerabilities across cloud and SaaS providers.
hunt-laravel
Detects Laravel-specific vulnerabilities including Ignition RCE, Telescope exposure, and mass assignment flaws.
hunt-sqli
Detects and exploits SQL and NoSQL injection vulnerabilities using payloads from disclosed bug bounty reports.
hunt-html-injection
Detect HTML injection vulnerabilities by reflecting unsanitized markup in web application responses.
hunt-ato
Detects and validates eleven account takeover paths across password reset, OAuth, JWT, and session flows.
hunt-forgot-password
Detects five authentication flaws in forgot-password and account recovery flows.
vmware-vcenter-attack
Maps external attack paths against internet-exposed VMware vCenter, Workspace ONE, and Aria instances.
hunt-dom
Detect DOM clobbering, postMessage hijacking, service worker abuse, and CSS exfiltration vulnerabilities in web applications.
hunt-spa-api
Extract backend API routes from SPA JavaScript bundles and test them for missing authentication.