Agent Skills by ok-helloworld
Showing 46 vetted skills indexed across 1 GitHub repositories.
vibe-pentest
Automate black-box web penetration testing with multi-agent reconnaissance and evidence-based reporting.
file-access-vuln
Route file access and upload workflow testing to path traversal or processing-chain issues.
injection-checking
Route suspected injection inputs to matching injection-testing workflows by sink context.
prototype-pollution
Probe __proto__ and constructor.prototype paths to detect prototype pollution vulnerabilities.
saml-sso-assertion-attacks
Detect SAML SSO authentication bypass paths from assertion trust misconfigurations.
api-sec
Route API security testing to workflows based on observed target patterns.
http-host-header-attacks
Identify Host header injection and routing abuse vectors in web applications.
websocket-security
Identify WebSocket handshake weaknesses, CSWSH conditions, and message-level vulnerabilities.
graphql-and-hidden-parameters
Discover hidden GraphQL fields and authorization gaps via schema and type probing.
xxe-xml-external-entity
Detect and exploit XXE vulnerabilities for file disclosure and blind OOB exfiltration.
nosql-injection
Detect NoSQL injection via MongoDB operator manipulation and blind enumeration.
clickjacking
Assess X-Frame-Options and CSP frame-ancestors to detect clickjacking vulnerabilities.
type-juggling
Probe PHP loose comparisons to verify authentication and signature bypasses.
authbypass-authentication-flaws
Identify authentication bypass risks across login, password reset, MFA, and session boundaries.
api-recon-and-docs
Discover reachable API endpoints, schemas, and versioned surfaces from REST, mobile, and GraphQL targets.
sqli-sql-injection
Identify SQL injection vulnerabilities and generate DB-specific exploitation evidence.
business-logic-vuln
Detect business workflow abuse vulnerabilities across multi-step state-machine flows.
ssrf-server-side-request-forgery
Detect and validate SSRF vulnerabilities in server-side URL fetch paths.
jndi-injection
Detect Java JNDI injection sinks and map feasible RMI, LDAP, or DNS vectors.
csrf-cross-site-request-forgery
Test state-changing endpoints for CSRF weaknesses and anti-CSRF controls.
xss-cross-site-scripting
Select context-appropriate XSS payloads for HTML, attribute, JavaScript, URL, and XML sinks.
upload-insecure-files
Validate file upload paths for bypass and processing-chain exploits.
web-cache-deception
Detect web cache deception and poisoning vulnerabilities across CDN intermediaries.
idor-broken-object-authorization
Detect IDOR and broken object level authorization across web and API requests.