Agent Skills by NwN
Showing 65 vetted skills indexed across 1 GitHub repositories.
file-access-vuln
Route security testing for file access and upload workflows by diagnosing parameter-to-path mappings.
dependency-confusion
Detect dependency confusion risks where internal package names resolve to public registries.
injection-checking
Classify injection vulnerabilities by routing attacker-controlled input to the correct sink-focused skill.
prototype-pollution
Detect prototype pollution vulnerabilities in JavaScript via targeted payloads.
unauthorized-access-common-services
Exploit exposed unauthenticated management services using port-scoped attack playbooks.
saml-sso-assertion-attacks
Detect SAML SSO assertion, signature, and routing vulnerabilities.
api-sec
Route API security testing to the appropriate workflow based on observed endpoint signals.
ssti-server-side-template-injection
Fingerprint server-side template injection engines using polyglot probes and math evaluation.
macos-process-injection
Analyze macOS process injection vectors via DYLD, XPC, Mach IPC, and Electron runtime features.
format-string-exploitation
Exploit format-string vulnerabilities to leak stack memory and write arbitrary values.
steganography-techniques
Detect and extract hidden steganography payloads from images, audio, files, and text.
csv-formula-injection
Detect and document CSV-to-spreadsheet formula injection vectors for SLDA.
websocket-security
Detect WebSocket security weaknesses in handshake validation, session binding, and message semantics.
graphql-and-hidden-parameters
Probes GraphQL schemas to identify hidden parameters and authorization gaps.
browser-exploitation-v8
Plan V8 JavaScript engine exploitation chains from bug classes to sandbox escape vectors.
traffic-analysis-pcap
Analyze PCAP files with Wireshark/tshark to extract forensic evidence and indicators of compromise.
linux-privilege-escalation
Organizes Linux enumeration and selects exploit paths for privilege escalation.
ai-ml-security
Identify security weaknesses across AI/ML model supply chains and adversarial threats.
arbitrary-write-to-rce
Convert arbitrary write primitives into code execution across glibc versions.
hack
Route web and API security testing toward likely bug-bounty vulnerability classes.
tunneling-and-pivoting
Establish network tunnels and pivot routes to access internal services.
network-protocol-attacks
Orchestrate layer 2/3 network protocol attacks for credential capture and relay.
classical-cipher-analysis
Identify and decrypt classical ciphers using frequency analysis and Kasiski examination.
api-recon-and-docs
Enumerate API endpoints, schemas, and undocumented parameters for security testing.