
from decepticon4,341
Directory, vhost and API enumeration hub with CMS scanning, WAF detection, auth mapping and cookie auditing — a reconnaissance orchestration skillset.
This skill organizes web-application reconnaissance into a hub of focused sub-skills. It documents workflows for directory and vhost discovery, API endpoint fuzzing, CMS fingerprinting, WAF detection, authentication-surface mapping, and cookie/session audits. The SKILL.md provides orchestration rules, deduplication patterns for HTTP probes, and output file conventions for downstream analysis.
Use when conducting authorized web application security testing or research where automated enumeration is required. It is intended for controlled pentesting contexts — do not run against targets without permission. The skill is a coordinator that loads specialized sub-skills depending on tags like sqli, lfi, or auth.
Intended for advanced agent frameworks and tooling used in security research (autonomous pentest agents, langchain-driven orchestrators, or other recon-capable agents). Use only in authorized environments.
Web reconnaissance hub skill from the Decepticon framework that orchestrates directory fuzzing, vhost discovery, API enumeration, CMS scanning, WAF detection, auth mapping, and cookie auditing. It's well-structured as a hub linking to sub-skills but contains no runnable scripts itself. No authorization or legal guardrails are present, which is concerning for offensive security tooling.
Hub skill with no executable scripts. Security score reflects missing authorization guardrails and offensive security nature, not malicious intent. The sub-skills it references (sqli, ssti, lfi exploits) would need separate auditing for higher-risk concerns. Dual-use tool — legitimate for authorized pentesting but no guardrails prevent misuse.
Scanner Skill — Decepticon
High-volume codebase scanner that shards work, ranks suspicious locations, and promotes a concise set of candidates for deeper analysis.
AD Overview (Decepticon)
Playbook and workflows for Active Directory offensive operations: BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync and LAPS extraction.
APT29 (Cozy Bear) Adversary Emulation Profile
Adversary-emulation profile that maps APT29 (Cozy Bear) ATT&CK TTPs to Decepticon tooling for realistic, cloud- and identity-focused red-team exercises.
T5 — Model & API Exploitation
Techniques to probe and exploit LLM APIs: rate-limit abuse, token-cost amplification, schema bypass, model-version manipulation, and related probes.
DAO Governance Attack
Techniques and reconnaissance steps for attacking or testing DAO governance: flash-loan voting, delegation hijack, quorum dilution, proposal spam, time-lock byp