SKILL.md packages that extend Claude Code, Cursor, Copilot, and other AI agents.
Tags

xianzhi-research
A structured vulnerability research framework distilled from 5600+ security docs, covering web injection, deserialization, binary exploitation, domain pentest,

crucible
Adversarial review skill: iteratively attack artifacts (designs, plans, code, docs) and surface fatal/significant issues until clean or escalation.

claude-bughunter
A five-phase bug-hunting workflow and critical-thinking playbook that orients security hunting sessions, maps steps from recon to report, and enforces quality g

decepticon
Adversary-emulation profile that maps APT29 (Cozy Bear) ATT&CK TTPs to Decepticon tooling for realistic, cloud- and identity-focused red-team exercises.

claude-bughunter
Guided hunting methodology for server-side request forgery (SSRF): detection, OOB validation, payloads, bypass techniques, and escalation chains.

red-team-blue-team-agent-fabric
A comprehensive, defensive test suite that runs protocol and decision-layer security checks against AI agent systems to surface vulnerabilities before deploymen

decepticon
Playbook and workflows for Active Directory offensive operations: BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync and LAPS extraction.

decepticon
Techniques and reconnaissance steps for attacking or testing DAO governance: flash-loan voting, delegation hijack, quorum dilution, proposal spam, time-lock byp

Anthropic Cybersecurity Skills
Guided procedures to identify DCSync-capable accounts and extract Active Directory credential hashes (KRBTGT, admin) for authorized red-team testing and validat

ISC-Bench
Benchmark template for evaluating spam-detection models using anchored spam campaign examples (contains harmful anchoring content).

skills
A 13-option prompt stack for public-market investment research: company deep-dives, industry maps, earnings previews, red-teaming, PM briefs and autopilot workf

decepticon
Techniques to probe and exploit LLM APIs: rate-limit abuse, token-cost amplification, schema bypass, model-version manipulation, and related probes.

claude-bughunter
Enumerate and assess on-prem Microsoft SharePoint servers for version disclosure, anonymous endpoints, legacy SOAP login abuse, ToolShell preconditions (CVE-202

joshft
Goal-directed red team assessment skill for live systems with source-code access; enforces isolation and intensity gating before active testing.

joshft
Live adversarial red team assessment and goal-directed penetration testing.

bb-huge
Expert-level guide for executing Kerberos-based attacks in AD environments, including roasting, ticket forging, and delegation abuse.