Browse Skills
11972 skills across 8 categories
🐞
4w ago
DOM Vulnerability Hunter
DOM Vulnerability Hunter finds and exploits client-side DOM vulnerabilities such as DOM clobbering, PostMessage misconfigurations, service worker abuse, and CSS exfiltration. Use it when auditing web applications for DOM XSS, client-side auth bypass, or token theft without server-side interaction.
Quality
3.6K559
🔓
4w ago
Enterprise VPN Attack
Enterprise VPN Attack catalogs fingerprinting methods and CVEs for SSL VPN/remote-access appliances such as Cisco ASA/AnyConnect, Fortinet, Citrix, Palo Alto, Pulse Secure, SonicWall, and F5. Use it when a perimeter exposes an SSL VPN gateway to test pre-auth RCE, SSRF, path traversal, and default credentials.
Quality
3.6K559
🐛
4w ago
Exceptional Conditions Hunter
Exceptional Conditions Hunter probes web endpoints with malformed or unexpected input to surface verbose error pages, stack traces, and internal file paths or library versions. Use it when testing APIs, forms, or query parameters for error-disclosure vulnerabilities.
Quality
3.6K559
🕵️
4w ago
Hunt ASP.NET
Hunt ASP.NET detects ASP.NET Webforms, WCF, and SharePoint attack surfaces such as ViewState deserialization, machineKey recovery, and trace.axd/elmah.axd disclosure to find high-value vulnerabilities in bug bounty programs.
Quality
3.6K559
🔓
4w ago
Hunt ATO
Hunt ATO catalogs nine distinct account takeover paths, including password reset flaws, email change without re-auth, OAuth account-link CSRF, MFA bypass, session fixation, JWT manipulation, and SSO subdomain takeover. Use it when hunting ATO chains or testing password reset, email change, MFA, OAuth, session, and JWT primitives toward a critical finding.
Quality
3.6K559
🔍
4w ago
Hunt Brute Force
Hunt Brute Force identifies missing or weak rate limiting on login, OTP/2FA, password-reset, and credential-stuffing endpoints to find brute force, enumeration, and ReDoS vulnerabilities. Use it when testing web apps for brute force, user enumeration, or rate-limit bypass via headers like X-Forwarded-For.
Quality
3.6K559
🛡️
4w ago
Hunt Clickjacking
Hunt Clickjacking tests for missing X-Frame-Options and CSP frame-ancestors headers, then proves a sensitive page can be framed and clicked cross-site to confirm a UI redressing vulnerability.
Quality
3.6K559
🕵️
4w ago
Hunt CORS Misconfigurations
Hunt CORS Misconfigurations probes CORS headers and browser behavior to find credentialed cross-origin read flaws, including origin reflection with credentials, null-origin trust, and subdomain regex bypass. Use it when testing API endpoints, SPAs, or any app emitting Access-Control-* headers.
Quality
3.6K559
🕵️
4w ago
Hunt CSRF
Hunt CSRF identifies cross-site request forgery vulnerabilities in authenticated web applications using patterns from 15 public bug bounty reports, including SameSite bypasses and account takeover chains. Use it when testing state-changing endpoints, token validation, and cookie SameSite attributes.
Quality
3.6K559
🎯
4w ago
Hunt Deserialization
Hunt Deserialization detects and exploits insecure deserialization vulnerabilities in Java, PHP, Python, .NET, and Ruby applications to achieve RCE. Use when testing targets that process serialized objects, including Log4Shell/JNDI, ysoserial, PHP object injection, pickle, BinaryFormatter, and Marshal.load.
Quality
3.6K559
🧑⚖️
4w ago
APM Review Panel
APM Review Panel runs a fan-out panel of specialist agents to review a labelled pull request in microsoft/apm. It aggregates findings from mandatory and conditional specialists plus a CEO synthesizer, then writes one advisory recommendation comment (no verdict labels, no merge gating). Use when a non-trivial PR needs cross-cutting recommendation on architecture, CLI logging, DevX UX, supply-chain
Quality
3.5K324
🛡️
4w ago
APM Spec Guardian
APM Spec Guardian runs a four-panel adversarial advisory review on pull requests that touch the OpenAPM specification, schemas, or conformance fixtures, returning a ship recommendation keyed off a shocked_meter scale. Use it when a PR changes normative spec artifacts and needs expert panel findings before a maintainer decides to ship.
Quality
3.5K324