QianYuchen avatar

QianYuchen

Community

@hanmujun

1Followers
|
3Public Repos
|
109Published Skills

QianYuchen maintains 152 offensive-security skills covering CTF solving, web exploitation, network service pentesting, reverse engineering, and post-exploitation tradecraft.

Skills Distribution
DomainCybersecurit...Web Application Ex.. (30%)CTF Challenge Solv.. (20%)Network Service & .. (20%)Binary Exploitatio.. (15%)

Agent Skills by QianYuchen

Showing 109 vetted skills indexed across 1 GitHub repositories.

hanmujunhanmujun
1

judge-ctf

Diagnoses stuck CTF challenge attempts and recommends a different next approach.

Community
Basic
hanmujunhanmujun
1

ctf-forensics

Solves authorized CTF forensics challenges across packet captures, disk, memory, and steganography.

Community
Basic
hanmujunhanmujun
1

ctf-flag-hunting

Searches CTF challenge artifacts and outputs for genuine flag candidates.

Community
Basic
hanmujunhanmujun
1

ctf-misc

Solves authorized CTF miscellaneous challenges covering encodings, jail escapes, protocols, and puzzles.

Community
Basic
hanmujunhanmujun
1

ctf-reverse

Analyzes authorized CTF reverse-engineering binaries, bytecode, VMs, and obfuscated code.

Community
Intermediate
hanmujunhanmujun
1

ctf-agent

Orchestrates authorized CTF question-bank competitions through API-driven state machine workflows.

Community
Advanced
hanmujunhanmujun
1

ctf-web

Routes and solves authorized CTF web and API challenges through source audit and injection analysis.

Community
Intermediate
hanmujunhanmujun
1

ctf-ai-ml

Solves authorized CTF challenges involving AI, ML models, adversarial learning, and LLM security.

Community
Basic
hanmujunhanmujun
1

ctf-pwn

Solves authorized CTF binary exploitation challenges involving memory corruption, ROP, and heap attacks.

Community
Intermediate
hanmujunhanmujun
1

ctf-osint

Solves authorized CTF OSINT challenges using public information and challenge-provided scope.

Community
Basic
hanmujunhanmujun
1

ctf-flag-verification

Validates candidate CTF flags against challenge ownership and reproducible evidence before submission.

Community
Basic
hanmujunhanmujun
1

ctf-crypto

Solves authorized CTF cryptography, encoding, RSA, and lattice challenges with reproducible scripts.

Community
Basic
hanmujunhanmujun
1

ctf-source-audit

Audits authorized CTF challenge source code to identify exploitable trust boundaries and flag paths.

Community
Basic
hanmujunhanmujun
1

efficiency-rules

Applies time, attempt, and output budgets to prioritize authorized CTF challenges.

Community
Basic
hanmujunhanmujun
1

ssh-pentesting

Tests SSH services through enumeration, credential attacks, tunneling, and known vulnerability exploitation.

Community
Advanced
hanmujunhanmujun
1

ksubdomain-brute

Performs stateless high-speed subdomain brute-forcing and verification using ksubdomain raw sockets.

Community
Basic
hanmujunhanmujun
1

web-vuln-scan

Tests a single web application for vulnerabilities using fingerprint-driven scanning and manual testing.

Community
Intermediate
hanmujunhanmujun
1

ctf-solve

Triages CTF challenges and routes execution to specialized category skills.

Community
Advanced
hanmujunhanmujun
1

binary-exploitation-methodology

Analyze ELF binaries and develop exploitation strategies for stack, heap, and format string vulnerabilities.

Community
Advanced
hanmujunhanmujun
1

injection-checking

Routes injection testing workflows across XSS, SQLi, SSRF, XXE, SSTI, and command injection sinks.

Community
Intermediate
hanmujunhanmujun
1

naabu-portscan

Scans hosts and network segments for open ports using naabu SYN and CONNECT scanning.

Community
Intermediate
hanmujunhanmujun
1

gogo-scan

Scan ports and identify service fingerprints using the gogo network scanner.

Community
Basic
hanmujunhanmujun
1

cache-poisoning-smuggling

Detect and exploit web cache poisoning and HTTP request smuggling in proxied architectures.

Community
Advanced
hanmujunhanmujun
1

prototype-pollution

Tests JavaScript applications for prototype pollution via __proto__ and constructor.prototype injection paths.

Community
Intermediate

Frequently Asked Questions About QianYuchen

FAQPage Schema
What tasks can I perform using QianYuchen's skills?▼

You can solve authorized CTF challenges across web, crypto, pwn, forensics, OSINT, and reverse categories; run reconnaissance with port scanning and subdomain enumeration; exploit injection flaws like SQLi, XSS, SSRF, and SSTI; crack password hashes; and execute post-exploitation including privilege escalation, lateral movement, and webshell management.

Who are these skills designed for?▼

These skills target penetration testers, red team operators, and CTF competitors working in authorized environments. They assume familiarity with offensive security concepts such as ROP chains, NTLM relay, Active Directory attacks, and binary protection bypasses like ASLR, NX, and stack canaries.

What runtime environment do the CTF skills require?▼

The ctf-solve, ctf-malware, ctf-pentest, and ctf-writeup skills require a filesystem-based agent such as Claude Code with bash, Python 3, and internet access for tool installation. They orchestrate specialized ctf-* skills and use Bash, Read, Write, Edit, Glob, Grep, Task, WebFetch, and WebSearch capabilities.

Are QianYuchen's skills open source and free to use?▼

The core CTF skills including ctf-forensics, ctf-web, ctf-crypto, ctf-pwn, ctf-reverse, ctf-solve, and ctf-writeup are explicitly MIT licensed and free. Many other skills reference open-source utilities such as nmap, nuclei, hashcat, sqlmap, and ffuf, though some manifests omit explicit license fields.

What prerequisites and dependencies do these skills need?▼

High-speed scanners like ksubdomain and masscan require root privileges for raw socket access. Binary exploitation skills expect GDB, pwntools, Ghidra, or angr. Hash cracking uses hashcat with GPU acceleration or John the Ripper. All skills are scoped to authorized testing and CTF competition contexts only.