
from decepticon4,341
Techniques to probe and exploit LLM APIs: rate-limit abuse, token-cost amplification, schema bypass, model-version manipulation, and related probes.
Practical catalogue of attack and probe techniques targeting LLMs when exposed as APIs. Covers patterns for rate-limit and quota abuse, forcing high-cost outputs, bypassing structured-output schemas, probing model-version and context window behavior, and abusing function-calling/tool integrations. Each technique includes detection signals and defensive recommendations.
This is a red-team/reference resource for security researchers, platform defenders, and operator threat-modelling. Use when you need to design tests for cost- or quota-related abuse, validate schema enforcement, fingerprint deployed model variants, or evaluate defenses for tool- and function-call exposures. Not for automated offensive use — research and defensive validation only.
Designed for security researcher toolkits and agent frameworks that can run scripted tests and probes (e.g., LangChain/agent-driven test harnesses). Suitable as a reference for Claude Code / general LLM research workflows.
Red-team skill cataloging LLM API attack techniques (rate-limit abuse, token-cost amplification, schema bypass, model-version manipulation). No bundled scripts — purely a documentation/playbook. Well-structured SKILL.md with clear technique breakdowns and defender mitigations, but instructs agents to attack and exploit APIs which is a significant security concern.
Red-team/security-testing skill from the Decepticon framework. Contains detailed attack technique documentation with defender mitigations. Legitimate security research use case but directly instructs exploitation behavior. Security score reflects the tension between legitimate red-team value and the harm potential of following these instructions on production APIs.
Scanner Skill — Decepticon
High-volume codebase scanner that shards work, ranks suspicious locations, and promotes a concise set of candidates for deeper analysis.
AD Overview (Decepticon)
Playbook and workflows for Active Directory offensive operations: BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync and LAPS extraction.
APT29 (Cozy Bear) Adversary Emulation Profile
Adversary-emulation profile that maps APT29 (Cozy Bear) ATT&CK TTPs to Decepticon tooling for realistic, cloud- and identity-focused red-team exercises.
Web Recon — Web Application Reconnaissance Hub
Directory, vhost and API enumeration hub with CMS scanning, WAF detection, auth mapping and cookie auditing — a reconnaissance orchestration skillset.
DAO Governance Attack
Techniques and reconnaissance steps for attacking or testing DAO governance: flash-loan voting, delegation hijack, quorum dilution, proposal spam, time-lock byp