本文へ移動
cccskills

スキルを探す

229 件(coco-research のリポジトリ) ・ 人気順

概要と使いどころ

Knowledge base from "Solving a Million-Step LLM Task with Zero Errors" (Meyerson, Paolo, Dailey, Shahrzad, Francon, Hayes, Qiu, Hodjat, Miikkulainen — arXiv:2511.09030). Use when designing long-horizon, multi-step agentic LLM pipelines that need very high reliability, applying Maximal Agentic Decomposition (MAD), first-to-ahead-by-k voting, or red-flagging error correction, estimating cost/reliability scaling laws for multi-agent systems, or studying Massively Decomposed Agentic Processes (MDAPs).

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use when analyzing suspected malware through static, dynamic, and behavioral techniques, including IOC extraction, YARA or Sigma rules, sandboxing, and anti-analysis behavior.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for reverse engineering stripped Go and Rust binaries including runtime recognition, pclntab/moduel data recovery, panic strings, and idiomatic decompilation recovery.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

.NET / C# 二进制逆向。当目标是 .NET assembly(PE 头含 CLR、.exe/.dll 托管程序)、C# 编译产物(含 NativeAOT)、红队 Sharp* 工具(Rubeus / SharpHound / SharpHound 等)、.NET 混淆程序(ConfuserEx / SmartAssembly / Babel / Eazfuscator)、.NET loader / info-stealer / 套壳 malware 时使用。优先用 dnSpyEx + de4dot,需要 AI 直接操作时联动 dnSpy MCP。不用于纯 native 二进制(走 reverse-engineering / ida-reverse)。

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

ot-ics

無料

Use for authorized OT/ICS security assessment covering Purdue model zoning, PLC/SCADA exposure, industrial protocol discovery, and safe passive-first evaluation.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

radio-sdr

無料

Use for authorized RF/SDR security research including signal identification, replay feasibility study in shielded labs, and wireless protocol analysis outside classic Wi-Fi.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized macOS and Mach-O reverse engineering including codesign, Objective-C/Swift recovery, endpoint security surfaces, and Apple platform malware analysis.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized hardware and embedded interface security research including UART/JTAG discovery, debug pad triage, secure boot overview, and offline firmware extraction support.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

固件 / IoT 渗透链。从拿到一坨 .bin / .img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工具链以 binwalk v3、unblob、EMBA、Firmadyne、AFL++ 为主。 适用场景:路由器/摄像头/智能家居固件审计、固件升级包逆向、IoT CVE 复现、嵌入式 0day 挖掘。 触发关键词:固件、firmware、IoT、binwalk、unblob、UART、JTAG、squashfs、UBI、JFFS2、Firmadyne、QEMU 全系统仿真、EMBA、固件渗透、路由器固件、嵌入式漏洞利用、bootloader、NVRAM、FAT、firmware analysis toolkit。

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

radare2

無料

Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together with CLI analysis, `rabin2`, `rasm2`, `radiff2`, `r2pipe`, or asks for radare2 command help on Windows/Linux/macOS.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it when the vulnerability is already understood and the remaining task is exploitation; use pwn instead. Do not use it for pure web workflows, log or disk forensics, or standalone crypto problems unless reversing the implementation is the real blocker.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新

Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.

日本語の概要は準備中です。原文の説明を表示しています。

coco-research/coco5362026年10月11日 更新