yaklang.io Project avatar

yaklang.io Project

Official

@yaklang

0Followers
|
52Public Repos
|
63Published Skills

Offers a comprehensive security assessment framework for web, API, and binary exploitation, enabling advanced vulnerability research and penetration testing.

Skills Distribution
DomainCybersecurit...Web & API Security (40%)Binary Exploitatio.. (30%)Network & Infrastr.. (20%)Cryptographic Anal.. (10%)

Agent Skills by yaklang.io Project

Showing 63 vetted skills indexed across 1 GitHub repositories.

yaklangyaklang
2.0k

dependency-confusion

Tests package managers for dependency confusion where public registries override private packages.

Official
Intermediate
yaklangyaklang
2.0k

prototype-pollution

Tests JavaScript applications for prototype pollution via __proto__ and constructor.prototype injection paths.

Official
Intermediate
yaklangyaklang
2.0k

csv-formula-injection

Tests CSV and spreadsheet exports for formula and DDE injection vulnerabilities.

Official
Intermediate
yaklangyaklang
2.0k

defi-attack-patterns

Analyzes DeFi protocols for flash loan, oracle manipulation, MEV, governance, and bridge attack vectors.

Official
Advanced
yaklangyaklang
2.0k

ai-ml-security

Assess AI/ML systems for supply chain attacks, adversarial examples, model extraction, and privacy leaks.

Official
Advanced
yaklangyaklang
2.0k

clickjacking

Tests web pages for frameability and builds clickjacking proof-of-concept attacks against sensitive actions.

Official
Intermediate
yaklangyaklang
2.0k

arbitrary-write-to-rce

Convert arbitrary write primitives into code execution via GOT, hooks, and vtable targets.

Official
Advanced
yaklangyaklang
2.0k

type-juggling

Exploit PHP loose comparison and magic hash collisions to bypass authentication and signature checks.

Official
Intermediate
yaklangyaklang
2.0k

ios-pentesting-tricks

Tests iOS applications for keychain, URL scheme, runtime, storage, and transport security weaknesses.

Official
Advanced
yaklangyaklang
2.0k

smart-contract-vulnerabilities

Audit Solidity and EVM smart contracts for reentrancy, overflow, access control, and MEV vulnerabilities.

Official
Advanced
yaklangyaklang
2.0k

mobile-ssl-pinning-bypass

Bypass SSL certificate pinning on Android and iOS apps to intercept HTTPS traffic.

Official
Advanced
yaklangyaklang
2.0k

hash-attack-techniques

Exploits hash weaknesses including length extension, MD5 collisions, and HMAC timing leaks.

Official
Advanced
yaklangyaklang
2.0k

kernel-exploitation

Exploits Linux kernel vulnerabilities for privilege escalation using ROP chains and heap techniques.

Official
Advanced
yaklangyaklang
2.0k

rsa-attack-techniques

Recover RSA plaintext by exploiting weak keys, small exponents, shared factors, and padding oracles.

Official
Advanced
yaklangyaklang
2.0k

android-pentesting-tricks

Tests Android applications for SSL pinning, component exposure, WebView flaws, and root detection weaknesses.

Official
Advanced
yaklangyaklang
2.0k

subdomain-takeover

Detects and exploits dangling DNS records pointing to unclaimed cloud and SaaS resources.

Official
Intermediate
yaklangyaklang
2.0k

expression-language-injection

Detect and exploit EL injection in SpEL, OGNL, and Java EL expression evaluators.

Official
Advanced
yaklangyaklang
2.0k

cors-cross-origin-misconfiguration

Tests CORS misconfigurations including reflected origins, null origins, and allowlist bypasses.

Official
Advanced
yaklangyaklang
2.0k

crlf-injection

Detects and exploits CRLF injection in HTTP response headers, redirects, cookies, and logs.

Official
Intermediate
yaklangyaklang
2.0k

api-auth-and-jwt-abuse

Tests API authentication and JWT implementations for token trust, header spoofing, and rate-limit weaknesses.

Official
Intermediate
yaklangyaklang
1.6k

file-access-vuln

Identify and test file-access and upload workflow vulnerabilities across download endpoints and file paths.

Official
Intermediate
yaklangyaklang
1.6k

injection-checking

Map attacker-controlled input to relevant injection deep-dive skills.

Official
Intermediate
yaklangyaklang
1.6k

saml-sso-assertion-attacks

Validate SAML assertions for signature coverage, audience checks, and ACS handling.

Official
Advanced
yaklangyaklang
1.6k

api-sec

Route API security assessments to focused testing workflows based on observed indicators.

Official
Intermediate

Frequently Asked Questions About yaklang.io Project

FAQPage Schema
What specific security tasks does this framework support?

The framework supports comprehensive security assessments including web application penetration testing, API authorization validation, binary reverse engineering, memory forensics, and cryptographic analysis of classical and lattice-based ciphers.

Which technical personas benefit from these capabilities?

Security researchers, penetration testers, and red team operators utilize these capabilities to identify vulnerabilities in complex web services, cloud-native infrastructure, and compiled software binaries.

What are the primary dependencies for running these security modules?

Execution requires a compatible runtime environment capable of handling binary analysis libraries, network traffic capture processing, and constraint solving engines like Z3 or Unicorn for symbolic execution tasks.