Use when a task requires SSH or SCP/SFTP behavior, a remote server, server alias/IP/hostname/user@host, bastion or jump-host access, remote command execution, upload/download, server transfer, deployment, tunnels, port forwarding, or remote internal services; Chinese triggers include 服务器, 远程, 连接, 登录, 上传, 下载, 部署, 跳板机, 隧道. DO NOT use for local shell commands, localhost/current-machine work, local Docker, browser downloads, Git remotes, or direct non-SSH database access.
日本語の概要は準備中です。原文の説明を表示しています。
badseal/ssh-skill☆ 5382026年8月24日 更新
Hunts for lateral movement via remote service creation, admin share writes, and remote WMI process creation by correlating Windows logon, service install, and process-creation events. Activates for requests to hunt lateral movement, detect PsExec/WMIexec activity, or find remote execution over SMB and WMI.
日本語の概要は準備中です。原文の説明を表示しています。
meltedinhex/analyst-ai-pack☆ 212026年7月7日 更新
Provides guidance for interpreting and manipulating neural network internals using nnsight with optional NDIF remote execution. Use when needing to run interpretability experiments on massive models (70B+) without local GPU resources, or when working with any PyTorch architecture.
日本語の概要は準備中です。原文の説明を表示しています。
davila7/claude-code-templates☆ 3.3万2026年10月11日 更新
Guide safe use of code_execution_remote for shell-backed execution on the connected A0 CLI host. Use when the user asks for their computer, local terminal, CLI host, remote shell, not Docker, or host-side Python/Node/terminal commands.
日本語の概要は準備中です。原文の説明を表示しています。
agent0ai/agent-zero☆ 1.9万2026年10月10日 更新
Provides guidance for interpreting and manipulating neural network internals using nnsight with optional NDIF remote execution. Use when needing to run interpretability experiments on massive models (70B+) without local GPU resources, or when working with any PyTorch architecture.
日本語の概要は準備中です。原文の説明を表示しています。
Orchestra-Research/AI-Research-SKILLs☆ 1.3万2026年6月16日 更新
リモート環境やDockerで、導入・連携・実操作のテストを進めるスキル。コードの信頼性に応じた環境の選択から、障害調査と実行後の後片付けまで扱います。
- クリーン環境でのパッケージ導入テスト
- 実サービスとの連携を検証したいとき
- macOS・Windows・WSL2の動作確認
openclaw/openclaw☆ 39.2万2026年10月11日 更新
Provides guidance for interpreting and manipulating neural network internals using nnsight with optional NDIF remote execution. Use when needing to run interpretability experiments on massive models (70B+) without local GPU resources, or when working with any PyTorch architecture.
日本語の概要は準備中です。原文の説明を表示しています。
huang-sh/DeepScience☆ 42026年7月15日 更新
MS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, it
日本語の概要は準備中です。原文の説明を表示しています。
aniket2348823/Vul-Agent☆ 22026年6月9日 更新
Node.jsの処理を途中で止め、変数や実行経路を調べるスキル。非同期処理の停止、不安定なテスト、メモリ増加、CPU負荷の原因調査に使えます。
- 非同期処理が止まる原因を調べたいとき
- 時々失敗するテストを調べたいとき
- 起動時や子プロセスの不具合調査
openclaw/openclaw☆ 39.2万2026年10月11日 更新
Pythonの実行を途中で止めて変数や処理の流れを調べ、例外発生時の状態や稼働中のプロセスも確認しながら、不具合の原因を追うスキル。
- 失敗するPythonテストの変数確認
- 予想外の状態変化を追いたいとき
- 例外発生時の状態を調べたいとき
openclaw/openclaw☆ 39.2万2026年10月11日 更新
Pythonの実行を途中で止め、変数や処理の流れを調べて不具合の原因を探ります。pdbとdebugpyを使い分け、失敗したテストや稼働中のプロセスも調査します。
- 失敗したテストの変数を調べたいとき
- 関数内のコレクションの変化を追う
- 例外発生地点の変数の確認
NousResearch/hermes-agent☆ 25.3万2026年10月11日 更新
Node.jsの処理を途中で止め、変数や関数の呼び出し経路から不具合を調べるスキル。端末でのステップ実行、状態収集の自動化、性能調査を支援します。
- Node.jsテストの途中の状態確認
- 関数の呼び出し経路と変数の調査
- 非同期処理の停止箇所を調べたいとき
NousResearch/hermes-agent☆ 25.3万2026年10月11日 更新
Comprehensive lateral movement tradecraft for authorized red team engagements covering credential-based movement (pass-the-hash, pass-the-ticket, overpass-the-hash), NTLM relay attacks (ntlmrelayx with PetitPotam, DFSCoerce, PrinterBug coercion), remote execution protocols (WMI, WinRM, DCOM, PsExec and alternatives), RDP session hijacking, and network pivoting through tunneling tools (chisel, ligolo-ng, SSH tunnels, SOCKS proxies). Provides operator-ready command sequences for mimikatz, crackmapexec/netexec, impacket suite, and evil-winrm with emphasis on OPSEC considerations, SMB signing bypass, and detection evasion. Maps to MITRE ATT&CK T1021 (Remote Services), T1550 (Use Alternate Authentication Material), and sub-techniques. Includes defender-perspective detection guidance for blue team awareness and a rapid engagement cheatsheet for common lateral movement scenarios encountered during internal penetration tests and assumed-breach exercises.
日本語の概要は準備中です。原文の説明を表示しています。
SnailSploit/Claude-Red☆ 7,4182026年9月20日 更新
Comprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script console remote code execution, Java remoting deserialization, credential store dumping, shared library injection), GitLab CI exploitation (YAML anchor injection, runner registration token abuse, CI variable extraction, protected branch bypass via merge request pipelines), and Azure DevOps pipeline agent compromise with service connection theft. Includes artifact poisoning techniques across all platforms, tooling guidance for gato and jenkins-attack-framework, and maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). Covers enumeration of pipeline configurations, privilege escalation from contributor to code execution, lateral movement through pipeline trust boundaries, and persistence via modified workflow definitions. Each technique section provides working exploitation code, detection indicators, and defensive countermeasures.
日本語の概要は準備中です。原文の説明を表示しています。
SnailSploit/Claude-Red☆ 7,4182026年9月20日 更新
Detect command injection, eval/exec usage, remote execution, or arbitrary code loading.
日本語の概要は準備中です。原文の説明を表示しています。
Tencent/AI-Infra-Guard☆ 6,8262026年10月9日 更新
Sysinternals DebugView CLI (DbgViewCli) for capturing and analyzing usermode and kernel-mode Windows debug output from the command line. USE FOR: capturing OutputDebugString output, kernel DbgPrint/KdPrint capture, boot-time debug logging, remote debug monitoring, filtering debug output by PID or process name, crash dump analysis, automated debug capture with bounded execution. DO NOT USE FOR: non-Windows platforms, application-level logging frameworks (log4j, serilog), Azure Monitor or cloud telemetry, ETW tracing (use WPR/xperf instead), user-mode crash dumps (use WinDbg). Triggers: "debug output", "DbgView", "DebugView", "kernel debug", "capture debug logs", "boot logging", "OutputDebugString", "DbgPrint", "KdPrint", "remote debug monitor", "debug capture CLI".
日本語の概要は準備中です。原文の説明を表示しています。
microsoft/skills☆ 3,1012026年10月10日 更新
Detect and use Crabbox for repository tests and validation on remote runners. Use when crabbox.yaml or .crabbox.yaml exists, the crabbox CLI is available, or work needs remote compute, a clean or reusable environment, target-platform coverage, or auditable execution evidence.
日本語の概要は準備中です。原文の説明を表示しています。
openclaw/crabbox☆ 1,4562026年10月11日 更新
Detect Remote Code Execution (RCE) vulnerabilities in a codebase using a three-phase approach: recon (find dangerous execution sinks), batched verify (trace user input to sinks in parallel subagents, 3 sinks each), and merge (consolidate batch results). Covers OS command injection, eval-like sinks, and unsafe deserialization. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/rce-results.md. Use when asked to find RCE, command injection, or unsafe deserialization bugs.
日本語の概要は準備中です。原文の説明を表示しています。
utkusen/sast-skills☆ 1,3312026年4月8日 更新
Shell and session operations after an attack module already established command execution, a raw shell, webshell channel, container/runner shell, or remote session. This module does not own exploitation and should not pull SSH/WinRM/RDP authentication or vulnerability-to-shell chains out of Web/AD/Cloud/K8s/CI-CD/Service/Phishing. Use it to bootstrap a usable callback from existing command execution, stabilize Linux PTY, upgrade Windows sessions with ConPTY where applicable, manage listeners, recover fragile sessions, and exchange files for continued operations.
日本語の概要は準備中です。原文の説明を表示しています。
pale-knight/redteam-skill☆ 492026年8月23日 更新
Exploit CVE-2023-36884, a critical Remote Code Execution vulnerability in Windows and Office associated with the Storm-0978 APT. This skill covers the weaponization of malicious Word documents to achieve code execution upon opening, bypassing Mark-of-the-Web (MotW) defenses.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Use when applying Cloudflare D1 migrations, fighting Supabase migration history vs SQL execution, choosing direct psql over CLI, designing idempotent migrations, debugging schema drift between local and remote, or recovering after a half-applied migration. Triggers: supabase migration repair instructions appearing, table missing after "applied" status, "Tenant or user not found" when running psql, --remote vs --local D1 confusion, NOT NULL on a populated column, foreign key constraint failures, drift between staging and prod schemas. NOT for Mongo/document migrations, ORM-managed migrations specifically (Prisma/Drizzle have their own conventions), or pure data backfills.
日本語の概要は準備中です。原文の説明を表示しています。
curiositech/windags-skills☆ 132026年10月1日 更新
Fornece orientação para interpretar e manipular internals de redes neurais usando nnsight com execução remota NDIF opcional. Use quando precisar executar experimentos de interpretabilidade em modelos massivos (70B+) sem recursos locais de GPU, ou ao trabalhar com qualquer arquitetura PyTorch.
日本語の概要は準備中です。原文の説明を表示しています。
artubss/SKILLS-CLAUDE-CODE☆ 112026年5月17日 更新
Comprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script console remote code execution, Java remoting deserialization, credential store dumping, shared library injection), GitLab CI exploitation (YAML anchor injection, runner registration token abuse, CI variable extraction, protected branch bypass via merge request pipelines), and Azure DevOps pipeline agent compromise with service connection theft. Includes artifact poisoning techniques across all platforms, tooling guidance for gato and jenkins-attack-framework, and maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). Covers enumeration of pipeline configurations, privilege escalation from contributor to code execution, lateral movement through pipeline trust boundaries, and p...
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新
Comprehensive lateral movement tradecraft for authorized red team engagements covering credential-based movement (pass-the-hash, pass-the-ticket, overpass-the-hash), NTLM relay attacks (ntlmrelayx with PetitPotam, DFSCoerce, PrinterBug coercion), remote execution protocols (WMI, WinRM, DCOM, PsExec and alternatives), RDP session hijacking, and network pivoting through tunneling tools (chisel, ligolo-ng, SSH tunnels, SOCKS proxies). Provides operator-ready command sequences for mimikatz, crackmapexec/netexec, impacket suite, and evil-winrm with emphasis on OPSEC considerations, SMB signing bypass, and detection evasion. Maps to MITRE ATT&CK T1021 (Remote Services), T1550 (Use Alternate Authentication Material), and sub-techniques. Includes defender-perspective detection guidance for blue team awareness and a rapid engagement cheatsheet for common lateral movement scenarios encountered during internal penetration tests and assumed-breach exercises.
日本語の概要は準備中です。原文の説明を表示しています。
ajtazer/heckit☆ 22026年10月7日 更新