Agent Skills by Ricardo Domingues
Showing 22 vetted skills indexed across 1 GitHub repositories.
scan-fase-17
Test GraphQL endpoints for introspection, authorization, and denial-of-service vulnerabilities.
scan-fase-10
Extract third-party service integrations and exposed API keys from frontend JS bundles and network traffic.
scan-fase-19
Map external and internal attack surfaces with infrastructure reconnaissance.
scan-fase-21
Fuzz target URLs with wordlists to discover hidden API endpoints and parameters.
scan-fase-20
Identifies Supabase RLS weaknesses via REST and GraphQL probes, delivering vulnerability findings and remediation steps.
scan-fase-11
Identify authentication and authorization bypass weaknesses via header, path, and parameter manipulation.
scan-fase-16
Map workflows and state transitions to identify business-logic vulnerabilities.
scan-fase-8
Analyze JWT authentication implementations for signing algorithm and claim integrity weaknesses.
scan-fase-1
Identify configurations, secrets, and attack-surface exposure from JS-bundled web applications.
scan-fase-6
Test Supabase Realtime WebSocket channels for unauthorized data access and RLS bypasses.
scan-fase-7
Identify HTTP security header misconfigurations and bypass opportunities across endpoints.
scan-fase-0
Detect backend technology and extract configurations from a target URL.
scan-fase-9
Identify and exploit GraphQL, mass assignment, IDOR, and race condition vulnerabilities.
scan-deep
Enrich initial-scan.json findings into a Pydantic-conformant deep-scan.json report.
scan-full
Orchestrate end-to-end security scans across phases FASE 0-21 on a target URL.
scan-fase-14
Test authenticated web apps for IDOR and privilege escalation vulnerabilities.
skill-creator
Generate Claude skill scaffolds with SKILL.md frontmatter and starter resources.
scan-fase-15
Run FASE 15 supplemental scans combining Nuclei, Retire.js, Arjun, SQLMap, and Commix.
scan-fase-5
Identify authentication weaknesses in Supabase-backed apps across signup, login, password reset, and OAuth flows.
scan-fase-2
Extract REST, GraphQL, and error-based schema signals into a structured YAML data model.
scan-fase-3
Test Supabase Row Level Security across REST and GraphQL channels.
scan-fase-4
Enumerate Supabase buckets, edge functions, and RPC endpoints for unauthorized access.