Agent Skills by Prohao42
Showing 92 vetted skills indexed across 2 GitHub repositories.
ssti-server-side-template-injection
Detect server-side template injection vulnerabilities using polyglot probes and engine fingerprinting.
defi-attack-patterns
Analyze DeFi protocols for flash loan, oracle, MEV, and governance attack patterns.
browser-exploitation-v8
Analyze V8 JavaScript engine vulnerabilities and sandbox bypass techniques.
xxe-xml-external-entity
Detect, exploit, and mitigate XML External Entity injection vulnerabilities.
linux-privilege-escalation
Identify Linux privilege escalation vectors via SUID/SGID, capabilities, cron jobs, and kernel exploits.
container-escape-techniques
Explore container escape techniques for penetration testing in Docker, LXC, or Kubernetes.
active-directory-kerberos-attacks
Exploit Kerberos vulnerabilities in Active Directory for reconnaissance and privilege escalation.
path-traversal-lfi
Identify and exploit path traversal and local file inclusion vulnerabilities in web applications.
llm-prompt-injection
Test AI/LLM applications for prompt injection and defense bypass techniques.
401-403-bypass-techniques
Bypass 401/403 access controls using path, method, header, and protocol techniques.
arbitrary-write-to-rce
Convert arbitrary writes to code execution across glibc versions.
linux-lateral-movement
Automate lateral movement across Linux hosts using SSH agent hijacking and credential harvesting.
dangling-markup-injection
Exfiltrate CSRF tokens and session data via dangling HTML markup.
authbypass-authentication-flaws
Identify and bypass authentication flaws in web applications.
ssrf-server-side-request-forgery
Identify and exploit Server-Side Request Forgery vulnerabilities in target systems.
windows-privilege-escalation
Exploit Windows system vulnerabilities to escalate privileges and gain administrative access.
jwt-oauth-token-attacks
Execute JWT and OAuth token attacks for security testing.
jndi-injection
Detect and exploit JNDI injection in Java applications via RMI and LDAP.
kernel-exploitation
Identify and exploit Linux kernel vulnerabilities for privilege escalation.
symmetric-cipher-attacks
Provides hands-on techniques for exploiting cryptographic weaknesses in systems and applications.
xss-cross-site-scripting
Deliver advanced XSS attack strategies for bypassing WAFs and CSPs.
anti-debugging-techniques
Detect and bypass anti-debugging techniques in Linux and Windows binaries.
subdomain-takeover
Detect and exploit subdomain takeovers via unclaimed CNAME, NS, and MX records.
active-directory-acl-abuse
Exploit misconfigured Active Directory permissions with BloodHound-guided attacks.