Agent Skills by yliken
Showing 25 vetted skills indexed across 1 GitHub repositories.
file-access-vuln
Test file access and upload workflows for misconfigurations and vulnerabilities.
injection-checking
Route attacker-controlled input to the appropriate injection testing sub-skill.
saml-sso-assertion-attacks
Analyze SAML SSO assertions for signature validation and trust boundary weaknesses.
api-sec
Route API security tasks to appropriate deep-dive sub-skills.
graphql-and-hidden-parameters
Discover GraphQL schema gaps via introspection, hidden fields, and batching.
clickjacking
Detect web page frameability by inspecting X-Frame-Options and CSP frame-ancestors headers.
path-traversal-lfi
Identify and exploit path traversal and LFI vulnerabilities to expose sensitive files.
hack
Route vulnerability testing tasks to security categories based on reconnaissance context.
type-juggling
Identify and exploit PHP loose comparison and magic hash bypass patterns.
api-recon-and-docs
Discover reachable API endpoints, schemas, and documentation across REST, GraphQL, and mobile APIs.
sqli-sql-injection
Identify and exploit SQL injection vectors across multiple DBMS.
business-logic-vuln
Identify business logic vulnerabilities in workflows and state transitions.
recon-and-methodology
Organize reconnaissance workflows for bug bounty engagements.
csrf-cross-site-request-forgery
Identify and validate CSRF vulnerabilities in state-changing web flows.
recon-for-sec
Map target scope and plan initial reconnaissance routes.
idor-broken-object-authorization
Identify and exploit IDOR and broken object authorization vulnerabilities across APIs and UI paths.
oauth-oidc-misconfiguration
Assess OAuth2/OpenID Connect misconfigurations across redirect_uri, state, PKCE, and token binding.
request-smuggling
Detect and map HTTP request smuggling vulnerabilities across proxies and backends.
race-condition
Identify and test race conditions and TOCTOU bugs in web applications.
insecure-source-code-management
Detect exposed .git, .svn, and .hg metadata during authorized assessments.
api-authorization-and-bola
Detects and tests API authorization gaps in object access and function controls.
http-parameter-pollution
Detect inconsistent interpretation of duplicate HTTP parameters across server, proxy, and application layers.
xslt-injection
Identify and exploit XSLT processing weaknesses across engines.
auth-sec
Route authentication and authorization testing tasks to appropriate sub-skills.