Wyl-cmd
Community@Wyl-cmd
Wyl-cmd maintains 152 offensive security skills covering bug bounty hunting, red-team recon, web/API exploitation, and vulnerability reporting for authorized testing.
Agent Skills by Wyl-cmd
Showing 83 vetted skills indexed across 1 GitHub repositories.
gen-docs
Update CLI user documentation from git commits, staged changes, and changelogs.
gen-rust
Ports Python code changes to Rust implementations while synchronizing tests and E2E verification.
release
Automates the version bump and release workflow for Kimi Code CLI packages.
pull-request
Creates and submits a GitHub pull request using the gh CLI.
gen-changelog
Generate changelog entries from git branch changes and sync them to documentation sites.
codex-worker
Spawn and manage parallel Codex CLI agents in tmux sessions with isolated git worktrees.
worktree-status
Audit git worktrees for dirty state and merge status before cleanup.
translate-docs
Translate and synchronize bilingual Chinese-English documentation pages and changelogs.
file-access-vuln
Routes file access and upload testing workflows to path traversal or upload vulnerability skills.
hunt-llm-ai
Test LLM and agentic AI applications for prompt injection, exfiltration, and cross-tenant data leaks.
hunt-write-gap
Tests API endpoints for unauthorized write access when read access is properly protected.
hunt-xss
Detect and validate reflected, stored, and DOM-based XSS vulnerabilities in web applications.
meme-coin-audit
Detect rug pulls and audit token contracts on EVM and Solana chains.
hunt-csrf
Detects and validates CSRF vulnerabilities in web applications using browser-accurate exploitation models.
hunt-dispatch
Fingerprints targets and loads the matching red team or WAPT skill set for /hunt.
cross-wave-delta-analysis
Compare recon wave outputs to classify new, regressed, and persistent findings.
hunt-mcp-security
Tests Model Context Protocol servers for tool access control, injection, and output poisoning vulnerabilities.
auto-vuln-hunt
Automates reconnaissance, vulnerability scanning, and PoC verification against a target URL.
report-writing
Writes impact-first bug bounty reports for HackerOne, Bugcrowd, Intigriti, and Immunefi.
hunt-idor
Detects IDOR vulnerabilities in APIs and web applications using authorization testing methodology.
ops-proxyns
Routes all process traffic through Tor using Linux network namespaces for pentest OPSEC.
bug-bounty
Orchestrates bug bounty hunting from recon through validated vulnerability reporting.
github-secret-hunting
Detect leaked API keys, tokens, and credentials in public GitHub repositories.
hunt-saml
Detects and exploits SAML/SSO vulnerabilities including XML Signature Wrapping, signature stripping, and parser differentials.
Frequently Asked Questions About Wyl-cmd
FAQPage SchemaWhat tasks can I perform using Wyl-cmd's skills?▼
You can run full bug bounty pipelines: recon and asset discovery, hunting 30+ vulnerability classes (XSS, SSRF, IDOR, SQLi, race conditions, ATO chains), AI/LLM prompt-injection testing, cloud and Kubernetes misconfiguration checks, and CVSS-scored report writing for HackerOne, Bugcrowd, Intigriti, and Immunefi.
Who are these skills designed for?▼
They target bug bounty hunters, penetration testers, and red-team operators conducting authorized security assessments. Skills like redteam-mindset, pentest-playbook, and bug-bounty orchestrator assume familiarity with Burp Suite, curl, nmap, and standard web exploitation methodology.
What are the runtime prerequisites and dependencies?▼
Most skills require Linux with curl, python3, nmap, masscan, subfinder, httpx, and nuclei. Specialized skills add playwright, ffuf, dnsx, shodan CLI, awscli, or gowitness. The ops-proxyns skill routes all traffic through Tor via Linux network namespaces before engagement start.
Are Wyl-cmd's skills open source and what do they cost?▼
The majority of skills carry an MIT license by author uphiago and are free to use. They are distributed as skill manifests for the KXNS/Kimi Code CLI environment, with no stated commercial licensing or usage fees in the manifest.
Do these skills cover AI and LLM security testing?▼
Yes. Dedicated skills cover prompt injection, indirect injection via documents, ASCII smuggling, tool-use exfiltration, system-prompt extraction, MCP vulnerabilities, and OWASP Agentic AI categories ASI01-ASI10, targeting chatbots, RAG pipelines, and agentic copilots.