Wyl-cmd avatar

Wyl-cmd

Community

@Wyl-cmd

10Followers
|
24Public Repos
|
83Published Skills

Wyl-cmd maintains 152 offensive security skills covering bug bounty hunting, red-team recon, web/API exploitation, and vulnerability reporting for authorized testing.

Skills Distribution
DomainCybersecurit...Web & API Vulnerab.. (40%)Reconnaissance & O.. (25%)Red-Team Infrastru.. (15%)AI/LLM & Emerging .. (10%)

Agent Skills by Wyl-cmd

Showing 83 vetted skills indexed across 1 GitHub repositories.

Wyl-cmdWyl-cmd
6

gen-docs

Update CLI user documentation from git commits, staged changes, and changelogs.

Community
Intermediate
Wyl-cmdWyl-cmd
6

gen-rust

Ports Python code changes to Rust implementations while synchronizing tests and E2E verification.

Community
Advanced
Wyl-cmdWyl-cmd
6

release

Automates the version bump and release workflow for Kimi Code CLI packages.

Community
Intermediate
Wyl-cmdWyl-cmd
6

pull-request

Creates and submits a GitHub pull request using the gh CLI.

Community
Basic
Wyl-cmdWyl-cmd
6

gen-changelog

Generate changelog entries from git branch changes and sync them to documentation sites.

Community
Intermediate
Wyl-cmdWyl-cmd
6

codex-worker

Spawn and manage parallel Codex CLI agents in tmux sessions with isolated git worktrees.

Community
Intermediate
Wyl-cmdWyl-cmd
6

worktree-status

Audit git worktrees for dirty state and merge status before cleanup.

Community
Intermediate
Wyl-cmdWyl-cmd
6

translate-docs

Translate and synchronize bilingual Chinese-English documentation pages and changelogs.

Community
Basic
Wyl-cmdWyl-cmd
6

file-access-vuln

Routes file access and upload testing workflows to path traversal or upload vulnerability skills.

Community
Basic
Wyl-cmdWyl-cmd
6

hunt-llm-ai

Test LLM and agentic AI applications for prompt injection, exfiltration, and cross-tenant data leaks.

Community
Advanced
Wyl-cmdWyl-cmd
6

hunt-write-gap

Tests API endpoints for unauthorized write access when read access is properly protected.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-xss

Detect and validate reflected, stored, and DOM-based XSS vulnerabilities in web applications.

Community
Advanced
Wyl-cmdWyl-cmd
6

meme-coin-audit

Detect rug pulls and audit token contracts on EVM and Solana chains.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-csrf

Detects and validates CSRF vulnerabilities in web applications using browser-accurate exploitation models.

Community
Advanced
Wyl-cmdWyl-cmd
6

hunt-dispatch

Fingerprints targets and loads the matching red team or WAPT skill set for /hunt.

Community
Advanced
Wyl-cmdWyl-cmd
6

cross-wave-delta-analysis

Compare recon wave outputs to classify new, regressed, and persistent findings.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-mcp-security

Tests Model Context Protocol servers for tool access control, injection, and output poisoning vulnerabilities.

Community
Intermediate
Wyl-cmdWyl-cmd
6

auto-vuln-hunt

Automates reconnaissance, vulnerability scanning, and PoC verification against a target URL.

Community
Advanced
Wyl-cmdWyl-cmd
6

report-writing

Writes impact-first bug bounty reports for HackerOne, Bugcrowd, Intigriti, and Immunefi.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-idor

Detects IDOR vulnerabilities in APIs and web applications using authorization testing methodology.

Community
Advanced
Wyl-cmdWyl-cmd
6

ops-proxyns

Routes all process traffic through Tor using Linux network namespaces for pentest OPSEC.

Community
Intermediate
Wyl-cmdWyl-cmd
6

bug-bounty

Orchestrates bug bounty hunting from recon through validated vulnerability reporting.

Community
Advanced
Wyl-cmdWyl-cmd
6

github-secret-hunting

Detect leaked API keys, tokens, and credentials in public GitHub repositories.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-saml

Detects and exploits SAML/SSO vulnerabilities including XML Signature Wrapping, signature stripping, and parser differentials.

Community
Advanced

Frequently Asked Questions About Wyl-cmd

FAQPage Schema
What tasks can I perform using Wyl-cmd's skills?

You can run full bug bounty pipelines: recon and asset discovery, hunting 30+ vulnerability classes (XSS, SSRF, IDOR, SQLi, race conditions, ATO chains), AI/LLM prompt-injection testing, cloud and Kubernetes misconfiguration checks, and CVSS-scored report writing for HackerOne, Bugcrowd, Intigriti, and Immunefi.

Who are these skills designed for?

They target bug bounty hunters, penetration testers, and red-team operators conducting authorized security assessments. Skills like redteam-mindset, pentest-playbook, and bug-bounty orchestrator assume familiarity with Burp Suite, curl, nmap, and standard web exploitation methodology.

What are the runtime prerequisites and dependencies?

Most skills require Linux with curl, python3, nmap, masscan, subfinder, httpx, and nuclei. Specialized skills add playwright, ffuf, dnsx, shodan CLI, awscli, or gowitness. The ops-proxyns skill routes all traffic through Tor via Linux network namespaces before engagement start.

Are Wyl-cmd's skills open source and what do they cost?

The majority of skills carry an MIT license by author uphiago and are free to use. They are distributed as skill manifests for the KXNS/Kimi Code CLI environment, with no stated commercial licensing or usage fees in the manifest.

Do these skills cover AI and LLM security testing?

Yes. Dedicated skills cover prompt injection, indirect injection via documents, ASCII smuggling, tool-use exfiltration, system-prompt extraction, MCP vulnerabilities, and OWASP Agentic AI categories ASI01-ASI10, targeting chatbots, RAG pipelines, and agentic copilots.