Hiago
Community@uphiago · Brasil
pretty much everything
Agent Skills by Hiago
Showing 171 vetted skills indexed across 1 GitHub repositories.
hunt-xss
Detect and validate reflected, stored, and DOM-based XSS vulnerabilities in web applications.
recon-sector
Runs sector-parameterized reconnaissance probes against WordPress-heavy SMB target lists.
hunt-mcp-security
Test Model Context Protocol servers for tool access control, injection, and output poisoning flaws.
hunt-saml
Tests SAML and SSO implementations for signature wrapping, parser differential, and assertion manipulation vulnerabilities.
llm-prompt-injection
Tests authorized LLM applications for prompt injection, system-prompt exposure, and RAG data-boundary failures.
security-arsenal
Provides payloads, bypass techniques, and submission rules for web vulnerability testing.
hunt-dom
Detect DOM clobbering, postMessage, service worker, and CSS exfiltration vulnerabilities in web applications.
bb-local-toolkit
Guides end-to-end bug bounty hunting from recon through validated vulnerability reporting.
wstg-web-pentest
Executes a 12-phase OWASP WSTG-aligned web application penetration test with concrete commands and verification criteria.
agentiko-worker
Operate restricted Alpine Linux containers for reconnaissance and penetration testing tasks.
agentiko-hermes
Automate distributed offensive security reconnaissance and pentesting workflows via Telegram and SSH containers.
docker-privesc
Escalate Docker container privileges to host root access.
recon-plumbing
Identify exposed PII, payment endpoints, and misconfigurations on plumbing company websites.
recon-daycare
Detect exposed minor PII and WordPress vulnerabilities in daycare websites.
hunt-llm-ai
Identify exploitable LLM/AI vulnerabilities crossing trust boundaries with validation gates.
recon-roofing
Enumerate roofing company domains, WordPress assets, and insurance claim endpoints.
hunt-api-misconfig
Detect API security misconfigurations across REST, OData, GraphQL, and ASP.NET Core APIs.
hunt-write-gap
Detect unprotected write endpoints in authenticated APIs for penetration testing.
hunt-cors
Detect CORS misconfigurations enabling credentialed cross-origin reads of authenticated data.
meme-coin-audit
Detect rug pull vectors and security flaws in EVM and Solana token contracts.
recon-churches
Discover church domains and detect WordPress vulnerabilities for authorized penetration testing.
hunt-csrf
Detect modern CSRF vulnerabilities including SameSite bypasses and OAuth RelayState flaws.
hunt-dispatch
Automate targeted skill selection and loading for /hunt offensive security engagements.
hunt-nextjs
Detect Next.js 13/15 vulnerabilities including Server Actions auth bypass and Image Optimization SSRF.