本文へ移動
cccskills
無料GitHub で公開

exploit-development

Authorized exploit development and vulnerability research skill for lab environments, CTFs, owned software, crash analysis, memory corruption, exploitability assessment, fuzzing results, proof-of-concept design, and remediation. Use for defensive validation and education; avoid real-world weaponization, stealth, persistence, evasion, or unauthorized targets.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md1.6 KB
  • agents/openai.yaml227 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Exploit Development

Authorization Boundary

  • Work only on owned code, lab targets, CTFs, or explicitly authorized research.
  • Keep proof of concept minimal: demonstrate the bug and impact without persistence, evasion, automated exploitation at scale, or post-exploitation.
  • Prefer root-cause analysis, exploitability classification, mitigations, and regression tests.

Workflow

  1. Establish target version, build flags, architecture, mitigations, input vector, and crash artifact.
  2. Reproduce deterministically in an isolated lab with symbols and sanitizer output when possible.
  3. Triage root cause: bounds, lifetime, type confusion, race, injection, logic flaw, or unsafe parser behavior.
  4. Assess exploitability at a high level: control of instruction pointer, write primitive, info leak, sandbox, and mitigations.
  5. Provide a safe PoC or pseudocode only as needed to validate impact, then produce patch guidance and tests.

Defensive Outputs

  • Crash summary with environment and reproduction constraints.
  • Root-cause explanation tied to source or disassembly.
  • Severity rationale and affected versions.
  • Patch strategy, hardening recommendations, and regression/fuzz tests.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

AI and LLM red-teaming skill for evaluating prompt injection, jailbreak, data exfiltration, tool abuse, agent hijack, RAG poisoning, model denial of service, and unsafe tool-use chains in Gemini, Claude, GPT, and open-weight models. Use to build evaluation harnesses, attack corpora, defensive guardrails, and red-team reports for AI systems you own or are authorized to test.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

API security automation skill for REST, GraphQL, gRPC, and WebSocket APIs. Covers OpenAPI/AsyncAPI ingestion, authenticated fuzzing, OWASP API Top 10 (BOLA, BFLA, mass assignment, SSRF), schema diffing, GraphQL introspection abuse, JWT and OAuth misuse, rate-limit and replay testing. Use to automate API assessments with safe, scoped, evidence-backed findings.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Assembly programming and low-level debugging skill for reading, writing, explaining, optimizing, and reviewing assembly across x86, x86-64, ARM, AArch64, RISC-V, calling conventions, ABI boundaries, inline assembly, disassembly, stack frames, registers, and binary-level behavior. Use for .s/.asm files, compiler output, reverse-engineering snippets, low-level performance, and crash analysis.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Bug bounty workflow skill for program scope mapping, recon-to-report automation, deduplication against prior submissions, and high-signal reporting on HackerOne, Bugcrowd, Intigriti, YesWeHack, and self-hosted programs. Use to organize bounty work end to end while staying inside program rules.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Assistant-behavior design skill for approximating a Claude-like analytical, careful, conversational style without claiming to be Claude or Anthropic. Use when the user asks to duplicate, emulate, adapt, or recreate a Claude-style "mythos" or persona for prompts, agent specs, writing style, reasoning discipline, safety posture, or UX behavior.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Cloud security posture skill for AWS, Azure, GCP, and multi-cloud. Covers IAM least-privilege, key and secret hygiene, network exposure, data protection, logging coverage, IaC scanning (Terraform, CloudFormation, Bicep, Pulumi), CSPM remediation, and landing-zone hardening. Use for misconfig discovery, IaC review, and automated drift-and-fix workflows on cloud accounts you own.

日本語の概要は準備中です。原文の説明を表示しています。

Garyson26/Trident-SecOps-Skills192026年9月30日 更新

Garyson26 のスキルをすべて見る

このスキルの問題を報告する