Use when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a frontend interface. Covers websites, landing pages, dashboards, product UI, app shells, components, forms, settings, onboarding, and empty states. Handles UX review, visual hierarchy, information architecture, cognitive load, accessibility, performance, responsive behavior, theming, anti-patterns, typography, fonts, spacing, layout, alignment, color, motion, micro-interactions, UX copy, error states, edge cases, i18n, and reusable design systems or tokens. Also use for bland designs that need to become bolder or more delightful, loud designs that should become quieter, live browser iteration on UI elements, or ambitious visual effects that should feel technically extraordinary. Not for backend-only or non-UI tasks.
日本語の概要は準備中です。原文の説明を表示しています。
sathishssj3/Stereix-Engine☆ 22026年10月4日 更新
Hunt Spring Boot specific vulnerabilities — Actuator endpoints (heapdump, env, loggers, mappings, shutdown), Spring Expression Language (SpEL) injection → RCE, H2 console RCE, Jolokia JMX exposure, Spring4Shell (CVE-2022-22965), Spring Cloud Function SPEL (CVE-2022-22963), heap dump credential extraction. Use when target runs Spring Boot — detected via X-Application-Context header, /actuator, Whitelabel Error Page, or Java stack traces.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection enumeration via Picker.aspx, NTLM Type-2 AD topology disclosure, custom-branding module discovery, EoL farm permanent-CVE-window exploitation, FormDigest anonymous issuance, file-extension blocklist NOT-an-oracle pattern, custom-zone Forms auth bridging on-prem AD. Use when target has SharePoint headers (SPRequestGuid, X-MS-InvokeApp, X-SharePointHealthScore, MicrosoftSharePointTeamServices) or paths (/_layouts/15/, /_vti_bin/, /_api/, /_catalogs/).
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Comprehensive Windows privilege escalation methodology for offensive security engagements. Covers the full attack surface from a standard user shell to NT AUTHORITYSYSTEM: token impersonation via SeImpersonate and SeAssignPrimaryToken privileges using JuicyPotato, PrintSpoofer, GodPotato, SweetPotato, and RoguePotato; service misconfigurations including unquoted service paths, weak service DACLs, writable service binaries, and insecure service creation permissions; AlwaysInstallElevated MSI exploitation; DLL hijacking through search order abuse, phantom DLL loading, and writable PATH directory injection; UAC bypass techniques via fodhelper.exe, eventvwr.exe, CMSTP, and environment variable manipulation; scheduled task abuse for writable task actions and new task creation; registry autorun exploitation for persistence and escalation; PrintNightmare (CVE-2021-34527) for remote and local privilege escalation; and credential harvesting from SAM database extraction, DPAPI blob decryption, LSA secret dumping,...
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Comprehensive Linux privilege escalation methodology for offensive security engagements. Covers the full attack surface from a low-privilege shell to root: SUID/SGID binary abuse via GTFOBins, Linux capabilities exploitation (cap_setuid, cap_dac_override, cap_dac_read_search), sudo misconfigurations including NOPASSWD rules and Baron Samedit (CVE-2021-3156), cron job abuse through writable scripts, PATH hijacking, and wildcard injection with tar/rsync/chown. Includes writable /etc/passwd attacks, NFS no_root_squash exploitation, kernel exploits (DirtyPipe CVE-2022-0847, DirtyCow CVE-2016-5195, PwnKit CVE-2021-4034), Docker group container escapes, LD_PRELOAD and LD_LIBRARY_PATH hijacking for shared library injection, systemd service misconfigurations, and sensitive file enumeration for credential harvesting. Integrates automated enumeration with LinPEAS, linux-exploit-suggester, pspy for process monitoring, and GTFOBins for binary exploitation. Each technique includes detection signatures and defender-sid...
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
filename=shell.php, Content-Type: image/jpeg → server trusts Content-Type
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy abuse, Jenkins script-console RCE and CVE-2024-23897 file read, GitLab CI runner-token registration, Terraform state file leakage, artifact/log secret leakage, pipeline env-var disclosure. Use when target has a public GitHub/GitLab org, exposed CI dashboards (Jenkins/TeamCity/Drone/Argo), or build artifacts/images are reachable.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Hunt Insecure Deserialization — Java gadget chains (ysoserial), PHP object injection (phpggc), Python pickle RCE, .NET BinaryFormatter, Ruby Marshal.load, JNDI/Log4Shell. RCE via deserialization is almost always Critical. Use when target runs Java, PHP serialization, Python pickle, .NET, or Ruby on Rails.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Hunt Kubernetes & Docker — API anonymous access, kubelet 10250 exec (SPDY/WebSocket, NOT plain POST) and the simpler /run primitive, etcd 2379 unauth, dashboard skip-login, RBAC misconfig, secret/SA-token abuse, docker.sock host escape, runc/container-escape (Leaky Vessels CVE-2024-21626), API-server-mediated nodes/proxy RCE, EphemeralContainers node-shell, bound/projected SA-token audience+expiry abuse, admission-controller bypass, Helm/Tiller remnants. Use when target runs containerized infra, exposes K8s ports (6443/10250/10255/2379/8443), or cloud metadata reveals K8s service accounts.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Detect OS command injection via shell execution sinks where user-controlled input reaches system commands without proper sanitization.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Use when building CLI tools, implementing argument parsing, or adding interactive prompts. Invoke for CLI design, argument parsing, interactive prompts, progress indicators, shell completions.
日本語の概要は準備中です。原文の説明を表示しています。
danstrem2/clawdbot-skill-master-pack☆ 22026年2月1日 更新
使用 qshell CLI 操作七牛云。当用户提到七牛、七牛云、Qiniu、Kodo、七牛对象存储 等时触发此技能。
日本語の概要は準備中です。原文の説明を表示しています。
Scoheart/agentskills☆ 22026年8月4日 更新
Classify every destructive/gated action an agent body can attempt (git, filesystem, network, shell, github) into block/approve/allow tiers, and audit whether the pre-tool and post-tool governance backing that classification is real: blocked actions proven zero-side-effect by a negative fixture, every denial backed by a receipt and a transcript event, every block-tier denial paired with a safe alternative, and no unmanaged or same-UID body ever marked "contained." Use when building or reviewing Agent Harbor's C5 governance gate (destructive git blocker, approval request/result, denial receipts), gating a new tool surface before it can run destructive commands, or auditing whether an existing "destructive-action blocked" claim actually has evidence behind it. NOT for proving an existing sandbox boundary actually contains an adversary once an action is isolated (use sandboxed-adversarial-test-harness), deciding where in a DAG to place a human review node or designing the approval UX itself (use human-gate-designer), or designing the general work-receipt schema across an entire agent task (use agent-work-receipt-designer).
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Design polished terminal UX for CLIs and TUIs. Use for setup flows, dashboards, tables, and actionable errors. NOT for web UIs, desktop windows, API schemas, or shell automation.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新