
from decepticon4,341
Techniques and reconnaissance steps for attacking or testing DAO governance: flash-loan voting, delegation hijack, quorum dilution, proposal spam, time-lock byp
Practical attack classes and reconnaissance steps for compromising DAO governance systems. Covers flash-loan-backed votes, delegation hijack, quorum dilution, proposal-spam denial-of-service, time-lock/emergency multisig bypass, and Snapshot vs on-chain voting desynchronisation. Includes code sketches, defender checks, and tooling guidance for simulating attacks on a fork.
Use this skill when assessing or simulating governance security for token-based DAOs, or when hunting for governance weaknesses during a red-team engagement. Trigger when investigating GovernorBravo-style setups, ERC20Votes delegation patterns, Snapshot-based governance flows, or when planning a governance audit.
Best used with agents that can run CLI tooling and interact with on-chain RPCs (Foundry/forge, cast, Tenderly integrations) and red-team automation frameworks.
DAO governance attack skill from the Decepticon framework, covering flash-loan vote manipulation, delegation hijack, quorum dilution, proposal spam, time-lock bypass, and snapshot desync. No bundled scripts — purely instructional markdown with Solidity snippets and cast/forge recon commands. Well-structured and references real incidents like the Beanstalk $182M exploit, but the skill's core purpose is offensive: teaching agents to identify and exploit governance vulnerabilities in DAOs.
Security score reflects adversarial purpose but no local machine exploitation vectors. The skill doesn't contain hardcoded credentials, destructive local commands, or exfiltration instructions — it targets blockchain governance, not the user's system. Flagged_malicious set to false because security_score >= 40, but this skill exists purely to enable offensive operations against DAOs. Ethical concern is significant even if technical risk to host machine is moderate.
Scanner Skill — Decepticon
High-volume codebase scanner that shards work, ranks suspicious locations, and promotes a concise set of candidates for deeper analysis.
AD Overview (Decepticon)
Playbook and workflows for Active Directory offensive operations: BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync and LAPS extraction.
APT29 (Cozy Bear) Adversary Emulation Profile
Adversary-emulation profile that maps APT29 (Cozy Bear) ATT&CK TTPs to Decepticon tooling for realistic, cloud- and identity-focused red-team exercises.
Web Recon — Web Application Reconnaissance Hub
Directory, vhost and API enumeration hub with CMS scanning, WAF detection, auth mapping and cookie auditing — a reconnaissance orchestration skillset.
T5 — Model & API Exploitation
Techniques to probe and exploit LLM APIs: rate-limit abuse, token-cost amplification, schema bypass, model-version manipulation, and related probes.