yaklang.io Project
Official@yaklang
Offers a comprehensive security assessment framework for web, API, and binary exploitation, enabling advanced vulnerability research and penetration testing.
Agent Skills by yaklang.io Project
Showing 63 vetted skills indexed across 1 GitHub repositories.
dependency-confusion
Tests package managers for dependency confusion where public registries override private packages.
prototype-pollution
Tests JavaScript applications for prototype pollution via __proto__ and constructor.prototype injection paths.
csv-formula-injection
Tests CSV and spreadsheet exports for formula and DDE injection vulnerabilities.
defi-attack-patterns
Analyzes DeFi protocols for flash loan, oracle manipulation, MEV, governance, and bridge attack vectors.
ai-ml-security
Assess AI/ML systems for supply chain attacks, adversarial examples, model extraction, and privacy leaks.
clickjacking
Tests web pages for frameability and builds clickjacking proof-of-concept attacks against sensitive actions.
arbitrary-write-to-rce
Convert arbitrary write primitives into code execution via GOT, hooks, and vtable targets.
type-juggling
Exploit PHP loose comparison and magic hash collisions to bypass authentication and signature checks.
ios-pentesting-tricks
Tests iOS applications for keychain, URL scheme, runtime, storage, and transport security weaknesses.
smart-contract-vulnerabilities
Audit Solidity and EVM smart contracts for reentrancy, overflow, access control, and MEV vulnerabilities.
mobile-ssl-pinning-bypass
Bypass SSL certificate pinning on Android and iOS apps to intercept HTTPS traffic.
hash-attack-techniques
Exploits hash weaknesses including length extension, MD5 collisions, and HMAC timing leaks.
kernel-exploitation
Exploits Linux kernel vulnerabilities for privilege escalation using ROP chains and heap techniques.
rsa-attack-techniques
Recover RSA plaintext by exploiting weak keys, small exponents, shared factors, and padding oracles.
android-pentesting-tricks
Tests Android applications for SSL pinning, component exposure, WebView flaws, and root detection weaknesses.
subdomain-takeover
Detects and exploits dangling DNS records pointing to unclaimed cloud and SaaS resources.
expression-language-injection
Detect and exploit EL injection in SpEL, OGNL, and Java EL expression evaluators.
cors-cross-origin-misconfiguration
Tests CORS misconfigurations including reflected origins, null origins, and allowlist bypasses.
crlf-injection
Detects and exploits CRLF injection in HTTP response headers, redirects, cookies, and logs.
api-auth-and-jwt-abuse
Tests API authentication and JWT implementations for token trust, header spoofing, and rate-limit weaknesses.
file-access-vuln
Identify and test file-access and upload workflow vulnerabilities across download endpoints and file paths.
injection-checking
Map attacker-controlled input to relevant injection deep-dive skills.
saml-sso-assertion-attacks
Validate SAML assertions for signature coverage, audience checks, and ACS handling.
api-sec
Route API security assessments to focused testing workflows based on observed indicators.
Frequently Asked Questions About yaklang.io Project
FAQPage SchemaWhat specific security tasks does this framework support?▼
The framework supports comprehensive security assessments including web application penetration testing, API authorization validation, binary reverse engineering, memory forensics, and cryptographic analysis of classical and lattice-based ciphers.
Which technical personas benefit from these capabilities?▼
Security researchers, penetration testers, and red team operators utilize these capabilities to identify vulnerabilities in complex web services, cloud-native infrastructure, and compiled software binaries.
What are the primary dependencies for running these security modules?▼
Execution requires a compatible runtime environment capable of handling binary analysis libraries, network traffic capture processing, and constraint solving engines like Z3 or Unicorn for symbolic execution tasks.