SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

claude-bughunter
A five-phase bug-hunting workflow and critical-thinking playbook that orients security hunting sessions, maps steps from recon to report, and enforces quality g

claude-bughunter
Guided hunting methodology for server-side request forgery (SSRF): detection, OOB validation, payloads, bypass techniques, and escalation chains.

security-skill
Send concurrent request bursts to detect TOCTOU, coupon reuse, double-spend and other web endpoint race conditions.

opencode-skills-collection
Structured workflow for testing REST and GraphQL API security: auth, authorization, rate limiting, input validation and error handling.

antigravity-awesome-skills
Structured workflow for testing REST and GraphQL API security: authentication, authorization, input validation, rate limiting, and common API vulnerabilities.

antigravity-awesome-skills
A step-by-step workflow for testing REST and GraphQL APIs, covering authentication, authorization, input validation, rate limiting, GraphQL checks, and error-ha

bountyforge
Orchestrates parallelized bug-bounty audits across smart contracts and web/APIs, producing deduplicated, gate-evaluated, platform-ready vulnerability reports fo

antigravity-awesome-workspace-skill
A comprehensive security testing framework for REST and GraphQL APIs, covering auth, rate limiting, and input validation.

awesome-skills-cn
A structured workflow for testing REST and GraphQL APIs covering discovery, authentication, authorization, input validation, rate limiting, and error handling.

bounty-hunter-skill
Persona skill: 'Atlas' — a profit-focused developer persona for discovering, evaluating and executing paid bounties or freelance tasks with ROI-aware workflows.

claude-bughunter
Enumerate and assess on-prem Microsoft SharePoint servers for version disclosure, anonymous endpoints, legacy SOAP login abuse, ToolShell preconditions (CVE-202

bb-huge
Advanced methodology for detecting Broken Object Level Authorization and Insecure Direct Object References in APIs.

marketplace
Automate professional red teaming and bug bounty workflows, from subdomain enumeration to vulnerability discovery.