SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

claude-bughunter
A five-phase bug-hunting workflow and critical-thinking playbook that orients security hunting sessions, maps steps from recon to report, and enforces quality g

claude-bughunter
Guided hunting methodology for server-side request forgery (SSRF): detection, OOB validation, payloads, bypass techniques, and escalation chains.

application-skills
Integrate and automate Acunetix vulnerability scans, targets, reports and scheduled scans via the Membrane CLI.

kali-docker-pentesting
Provides a Kali Linux Docker container with 200+ penetration-testing tools and guidance for running scans, exploitation, and forensics via direct docker exec co

xalgorix
Offensive/blue-team skill for authorized pentests: enumerates FreeIPA/LDAP/Kerberos environments, finds HBAC/sudo misconfigurations, reuses CCACHE/keytabs and m

xalgorix
Create, deploy, and monitor Thinkst Canary Tokens (web, DNS, document, AWS key) to detect lateral movement and credential misuse.

TerminalSkills Library
Automate penetration testing workflows by orchestrating security tools (nmap, subfinder, nuclei, sqlmap) with AI agents to find, prove, and report web applicati

Keygraph Shannon
Autonomous AI-driven pentesting tool for web apps and APIs. Performs real exploits to prove vulnerabilities with high success rates.

vibehacking
Advanced workflow for inspecting HTTP traffic, sitemaps, and WebSockets using Caido MCP tools for security analysis.

bb-huge
Comprehensive AD security auditing using MITRE ATT&CK, covering ADCS, GPOs, ACLs, and Kerberos attacks.

gStack
Performs professional-grade infrastructure and code security audits, identifying vulnerabilities and producing detailed security posture reports.

android-pentesting-skill
Comprehensive Android APK security audit with static/dynamic analysis, source-to-sink tracing, and CVSS 4.0 reporting.

vibe-pentest
A multi-agent parallel architecture for automated black-box web application penetration testing and vulnerability reporting.

skills
Professional cryptographic security audit of TLS/SSL configurations, mapped to PCI DSS 4.0, NIST, and FedRAMP compliance.

skills
Expert penetration testing skill for generating platform-specific reverse shell payloads and managing listeners in Kali Linux.

bb-huge
Expert-level guide for executing Kerberos-based attacks in AD environments, including roasting, ticket forging, and delegation abuse.

abelrguezr
Exploit SNMP services with write-accessible community strings to achieve RCE.

marketplace
Automate professional red teaming and bug bounty workflows, from subdomain enumeration to vulnerability discovery.

xalgorix
Procedures and checks to enumerate and exploit rsync daemon modules (port 873), detect unauthenticated shares, brute-force auth, and safely verify read/write ex

claude-code-plugins-plus-skills
Provides step-by-step guidance and configurations for attack surface analysis, threat modeling, and advanced security assessments.