SnailSploit | Kai Aizen
Community@snailsploit
GenAI Security Researcher | AI Red Teamer | Offensive Security Author of AATMF /P.R.O.M.P.T/ SEF frameworks| 50+ CVEs | Same Attack, Different Substrate
Agent Skills by SnailSploit | Kai Aizen
Showing 47 vetted skills indexed across 1 GitHub repositories.
offensive-fuzzing
Guides offensive fuzzing campaigns from harness writing through crash triage across multiple fuzzer frameworks.
oauth-attacks
Tests OAuth 2.0 implementations for redirect, state, PKCE, and token handling vulnerabilities.
offensive-jwt
Tests JWT implementations for algorithm confusion, weak secrets, and header injection vulnerabilities.
race-condition
Tests web applications for TOCTOU race condition vulnerabilities using concurrent request techniques.
request-smuggling
Tests web infrastructure for HTTP request smuggling desynchronization vulnerabilities across proxy and server chains.
file-upload
Tests web application file upload endpoints for validation bypasses and exploitation paths.
offensive-krack-fragattacks
Tests WPA2 supplicants for KRACK and FragAttacks vulnerabilities using Vanhoef's test scripts.
offensive-advanced-redteam
Guides full-lifecycle red team engagements covering C2 infrastructure, evasion, OPSEC, and reporting.
offensive-osint
Guides OSINT reconnaissance across domains, people, infrastructure, cryptocurrency, and geospatial intelligence.
offensive-reporting
Writes penetration test reports with CVSS scoring, evidence handling, and executive summaries.
bug-identification
Identify software vulnerabilities through static analysis, dynamic analysis, fuzzing, and AI-assisted techniques.
windows-mitigations
Analyze Windows exploit mitigations including DEP, ASLR, CFG, and CET.
exploit-development
Guides users through exploit development lifecycle from bug identification to weaponization and mitigation bypasses.
initial-access
Detail initial access techniques including phishing and credential stuffing mapped to MITRE ATT&CK TA0001.
oauth-attacks
Test OAuth 2.0 and OIDC implementations for redirect_uri bypass and token leakage.
parameter-pollution
Analyze server-side and client-side parameter parsing to exploit HTTP Parameter Pollution vulnerabilities.
fuzzing-methodology
Guide software fuzzing campaigns with techniques and workflows for AFL++ and libFuzzer.
sql-injection
Test SQL injection vulnerabilities across database types and bypass strategies.
fast-checking
Provide a speed-optimized offensive security checklist for rapid assessments.
windows-boundaries
Analyze Windows security mitigations and bypass techniques for offensive operations.
open-redirect
Identify and test open redirect vulnerabilities in web applications.
ai-security
Assess AI and LLM systems for prompt injection and adversarial vulnerabilities.
keylogger-architecture
Analyze low-level keylogger architectures and input capture mechanisms.
vulnerability-classes
Teach core vulnerability classes with real-world CVE case studies.