Hunt CORS Misconfiguration — origin-reflection with credentials, null-origin trust, subdomain-regex bypass (unanchored vs unescaped-dot vs prefix-only), pre-flight (OPTIONS) gating bypass, postMessage origin checks. High only when an attacker-controlled origin can perform a CREDENTIALED cross-origin read of sensitive data and you have proven it in a browser. Use when testing API endpoints, SPAs, or any app emitting Access-Control-* headers.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation ...
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
You are attacking Layer 2/3 infrastructure during an authorized internal engagement. ARP, DHCP, broadcast name resolution, VLAN trunking, and IPv6 autoconfiguration are all unauthenticated -- you exploit that trust to intercept credentials, redirect traffic, and cross network boundaries.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
You are helping a penetration tester enumerate and exploit Active Directory
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
LLM bugs are only worth reporting when they cross a trust boundary you can prove — an OOB callback, a verbatim-reproducible secret, a cross-tenant record, or code execution. A model 'saying something bad once' is confabulation, not a vulnerability. Read the False-Positive Gate before claiming anything.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Active Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for any Solidity/Rust contract audit or when deciding whether a DeFi target is worth hunting.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abuse, IMDSv1/v2 attacks via SSRF, K8s ServiceAccount token privilege analysis once held (token discovery / cluster exposure is owned by hunt-k8s), role-trust-policy confused-deputy, cross-account assume-role enumeration, IAM privilege escalation patterns (24+ AWS, 8+ Azure, 6+ GCP), and AWS Cognito Identity Pool unauthenticated-role attack chain (GetId → GetCredentialsForIdentity → IAM role abuse). Built for the case where recon yields a credential (key, JSON, token) and you need to know what it grants and how to escalate. Use when an AWS key / Azure secret / GCP service account JSON / K8s SA token surfaces from a code repo, JS bundle, APK, breach corpus, or SSRF chain.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
A fast Rust-based headless browser automation CLI with Node.js fallback that enables AI agents to navigate, click, type, and snapshot pages via structured commands.
日本語の概要は準備中です。原文の説明を表示しています。
danstrem2/clawdbot-skill-master-pack☆ 22026年2月1日 更新
Every product will be AI-powered. The question is whether you'll build it right or ship a demo that falls apart in production. This skill covers LLM integration patterns, RAG architecture, prompt engineering that scales, AI UX that users trust, and cost optimization that doesn't bankrupt you. Use when: keywords, file_patterns, code_patterns.
日本語の概要は準備中です。原文の説明を表示しています。
danstrem2/clawdbot-skill-master-pack☆ 22026年2月1日 更新
Manage Cloudflare DNS records, Tunnels (cloudflared), and Zero Trust policies. Use for pointing domains, exposing local services via tunnels, and updating ingress rules.
日本語の概要は準備中です。原文の説明を表示しています。
johnalbertini14-glitch/openclaw-skills☆ 22026年2月26日 更新
Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patterns. Use when installing new skills, auditing existing ones, reviewing untrusted code, or validating packages before publishing.
日本語の概要は準備中です。原文の説明を表示しています。
johnalbertini14-glitch/openclaw-skills☆ 22026年2月26日 更新
Fast X Intelligence CLI (Rust) — search, analyze, and engage on X/Twitter from the terminal. Use when: (1) user says "x research", "search x for", "search twitter for", "what are people saying about", "what's twitter saying", "check x for", "x search", "search x", (2) user wants real-time monitoring with "watch", (3) user needs AI-powered analysis with Grok ("analyze", "sentiment"), (4) user needs intelligence reports ("report"), (5) user wants to track followers ("diff"), (6) user needs trending topics ("trends"). Also supports: bookmarks, likes, following (OAuth), x-search, collections, CSV/JSON/JSONL export. Non-goals: Not for posting tweets, not for DMs, not for enterprise features.
日本語の概要は準備中です。原文の説明を表示しています。
johnalbertini14-glitch/openclaw-skills☆ 22026年2月26日 更新
Analyze any codebase's source code in depth and produce structured analysis documents saved as markdown files. Use this skill whenever the user asks to understand how a codebase works — architecture, module design, call flows, data models, design patterns, performance characteristics, or any implementation detail. Trigger on phrases like "analyze the source", "explain this code", "how does X work", "where is Y implemented", "trace the flow of", "what happens when", "read through the code", "code walkthrough", "源码分析", "代码解读", "实现原理", "架构分析", "调用链路", "模块分析", or any code-exploration request. Works with any programming language: TypeScript/JavaScript, Java, Python, Go, Rust, C/C++, and more. Even if the user's question seems simple (e.g., "这个文件是干什么的"), use this skill — a thorough, source-backed analysis document is always more valuable than a surface-level guess.
日本語の概要は準備中です。原文の説明を表示しています。
Scoheart/agentskills☆ 22026年8月4日 更新
Adversarial reviewer for The Federated Harbor whitepaper — the third paper in the Curiositech sequence after Anchor and Bonded Commons. Probes federation-specific threats: trust transitivity, cross-harbor token forgery, federated revocation under partition, cross-harbor Sybil, cross-domain settlement, equivocation, bond-pool draining, cold-start joining, federation-operator Sybil. Use during a versioned red-vs-white round; pairs with federated-harbor-whitehat. NOT for incident response, NOT for the Anchor or Bonded papers (use redteam-review).
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Designs, reconciles, and reviews an end-to-end Drydock program for safely staging agent runtimes: immutable worktree provenance, disposable VM containment, typed effect brokerage, global body accounting, resurrection, subscription-capacity economics, context compaction, operator control, evidence, and promotion. Use when several Drydock contracts must compose into one architecture, implementation hypertree, diagram set, or release plan. NOT for launching Port Daddy, running an untrusted subject, replacing focused containment/resurrection/capacity audits, or treating a design packet as runtime authority.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Refute-before-prove research discipline: automated counterexample sweeps before any formalization, meter-integrity audits for information-bound experiments, mutation-tested model checkers, pre-registered commit-or-cut gates for speculative directions, wrong-turn reporting, and numeric-claim provenance. Use when validating any new theorem, bound, equilibrium, or security claim; when building or trusting a checker, simulator, or experiment; or when deciding whether a speculative research direction lives or dies. NOT for exploratory brainstorming, product prioritization, writing style, or literature review.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Cross-platform desktop development for macOS and Windows -- platform abstractions, UI convention differences, and multi-platform CI/CD. Activate on: cross-platform app, macOS and Windows, platform differences, DMG installer, MSI installer, NSIS installer, Cmd vs Ctrl, platform abstractions, menu bar differences, native conventions. NOT for: mobile apps, web-only apps, Tauri-specific internals (use rust-tauri-development).
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Use when wrangler deploys silently fail or produce wrong artifacts, secrets upload as empty strings, custom domain DNS is not resolving, route assignment broke after rename, observability/tail logs are needed, D1/KV/R2 bindings are missing, OAuth scope errors block a command, cookies on a redirect are not attaching, or the worker exceeds CPU time. Triggers: "Tenant or user not found", "Authentication error" on wrangler d1 push, secret length is 0 after upload, route returns origin not worker, "compatibility_date too old", 1101 errors, custom_domain assignment lost on script rename. NOT for AWS Lambda / Vercel Edge / Deno Deploy (different runtimes), Cloudflare Zero Trust, or R2-specific tuning.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Diagnose when intuitive judgment, agent confidence, or expert routing can be trusted by classifying environment validity, feedback quality, and task-boundary fit. Use for confidence calibration, agent routing, expertise audits, and escalation design. NOT for deterministic implementation tasks, pure syntax debugging, or domains with explicit verifiable answers.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Diagnose when intuitive judgment, agent confidence, or expert routing can be trusted by classifying environment validity, feedback quality, and task-boundary fit. Use for confidence calibration, agent routing, expertise audits, and escalation design. NOT for deterministic implementation tasks, pure syntax debugging, or domains with explicit verifiable answers.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity. Use when designing, configuring, troubleshooting, or reviewing Cloudflare One deployments. Retrieval-first: use current Cloudflare docs/API schemas instead of embedded product docs.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Designs and audits deterministic, authority-filtered partitions of trust-typed context for already admitted bodies or abstract continuation slots. Use when causal context, obligations, disclosure boundaries, vector-space identity, capacity, and omission proofs must survive partitioning. NOT for spawning or admitting agents, choosing worker count, retrieving arbitrary knowledge, writing successor prompts, or granting tools, leases, identity, or effect authority.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/port-daddy☆ 22026年10月8日 更新
Add /compact command for manual context compaction. Solves context rot in long sessions by forwarding the SDK's built-in /compact slash command. Main-group or trusted sender only.
日本語の概要は準備中です。原文の説明を表示しています。
nanocoai/nanoclaw-gmail☆ 22026年4月3日 更新