本文へ移動
cccskills
無料GitHub で公開

amend-skill

Inspects a skill's SKILL.md and its observations/runs.md log, identifies failure patterns, and proposes a targeted amendment to improve the skill. Trigger on: "improve this skill", "fix this skill", "update this skill", "why does X keep failing", "this skill is wrong", "add this to the skill", or automatically when observations/<skill-name>/runs.md contains 3 or more failure entries. Outputs the amendment as a diff the user can review before applying. Records the amendment rationale in observations/<skill-name>/runs.md after user confirmation.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md4.4 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Amend Skill

Purpose

Skills degrade over time as targets change, new bypass techniques emerge, and failure patterns accumulate. This skill closes the feedback loop: it reads execution history, identifies what is systematically failing, and proposes a minimal surgical amendment to the skill.

Trigger Conditions

Activate this skill when:

  • User says "improve this skill", "fix this skill", "update this skill", "amend this skill"
  • User says "why does X keep failing" where X is a skill name
  • User says "add this to the skill" after describing a new technique that worked
  • observations/<skill-name>/runs.md contains 3 or more entries with outcome: fail

Methodology

  1. Identify the target skill — confirm the skill name with the user if ambiguous.
  2. Read the skill — load skills/<bucket>/<category>/<skill-name>/SKILL.md in full.
  3. Read the observations — load observations/<skill-name>/runs.md.
  4. Analyze failure patterns:
    • Which steps consistently fail?
    • Which payloads are blocked or produce wrong output?
    • Which trigger conditions are missing or too broad?
    • Are there new bypass techniques that worked but aren't documented?
    • Is the output format causing downstream confusion?
  5. Formulate a single targeted amendment — one focused change rather than a full rewrite. The amendment should be one of:
    • Tighten trigger: remove or refine a trigger condition that causes false activation
    • Add missing condition: add a step, payload, or bypass that is now needed
    • Reorder steps: move a high-value step earlier to avoid wasted time
    • Fix payload: update an outdated payload that no longer works
    • Change output format: restructure how the skill presents findings
  6. Output the amendment as a unified diff — show old text and proposed new text side by side.
  7. Ask for confirmation — do not apply until the user approves.
  8. Apply and record — edit the SKILL.md, then append to observations/<skill-name>/runs.md:
---
date: YYYY-MM-DD
skill: <skill-name>
task: Amendment applied via amend-skill
outcome: amendment
what_worked: |
  <describe what the amendment changes and why>
what_failed: |
  <describe the failure pattern that motivated the amendment>
errors: |
  N/A
notes: |
  Amendment type: <tighten-trigger | add-condition | reorder-steps | fix-payload | change-output>
  Rationale: <one-sentence reason>
---

Example Interaction

User: "why does sql-injection keep failing on this target?"

Process:

  1. Read skills/owasp-wstg/injection/sql-injection/SKILL.md
  2. Read observations/sql-injection/runs.md — finds 3 fail entries, all noting WAF blocking ' and --
  3. Analysis: Bypass section exists but WAF-specific encoding variants not prominent enough in step 2
  4. Amendment: Move WAF bypass step earlier in Methodology, add a WAF detection pre-step

Output:

-2. Submit `'`, `"`, `;`, `--`, `/* */` individually and observe response differences.
-3. Confirm with boolean pair: append `AND 1=1--` (true) vs `AND 1=2--` (false).
+2. Check for WAF: submit `'` and observe whether the response is a WAF block page (uniform
+   error regardless of input) vs. a database error (input-specific). If WAF present, use
+   encoding variants from the Bypass Techniques section before confirming injection.
+3. Submit `'`, `"`, `;`, `--`, `/* */` individually. If WAF present, substitute with
+   `%27`, `%2D%2D`, and comment fragmentation `UN/**/ION`.
+4. Confirm with boolean pair: `AND 1=1--` vs `AND 1=2--`.

Fix Patterns

This is a meta-skill — it has no fix patterns of its own. Its output is an amendment to another skill's fix patterns.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Exploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely. Techniques include response manipulation, referal spoofing, token reuse, and predictable backup codes.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

Execute AS-REP Roasting to extract and crack the NTLM hashes of Active Directory user accounts that have the "Do not require Kerberos preauthentication" flag explicitly enabled. This attack generates a recoverable Ticket Granting Ticket (TGT) without requiring the attacker to authenticate first.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.

日本語の概要は準備中です。原文の説明を表示しています。

ShulkwiSEC/bb-huge242026年7月11日 更新

ShulkwiSEC のスキルをすべて見る

このスキルの問題を報告する