本文へ移動
cccskills
無料GitHub で公開

exploit-test

Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path, confirming a patch deployed correctly, or producing a copy-pasteable test command for QA. The skill never executes — the user runs.

インストール方法を見る

含まれるファイル(3)

  • SKILL.md4.6 KB
  • evals/evals.json3.6 KB
  • evals/trigger-eval.json1.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Vulnetix Exploit Test Skill

Use when

  • You just applied a fix and want to validate the exploit path no longer responds.
  • Confirming a patch deployed correctly to staging before promoting to production.
  • Producing a copy-pasteable test command for QA hand-off.
  • Comparing pre-fix vs post-fix behaviour with the same payload.
  • Building authorised proof-of-fix evidence for an audit.

Don't use for

  • Unauthorised testing — the skill explicitly requires user-supplied authorised targets.
  • Live attack simulation — use a dedicated red-team tooling chain.
  • Generating detection rules — use detection-rules.

Conventions

Follows skills/_lib/contract.md. In short: use the vulnetix_* MCP tools when the agent has them and the CLI otherwise — both shape their own output, so there is no jq step any more. Independent calls go out as concurrent Bash tool calls in one message. One trailing suggestion, not a playbook. See the contract for surface selection, output style and memory writes.

Builds a copy-pasteable exploit-validation command. Best used after a fix to confirm the vulnerability path no longer responds. The user runs the command — this skill does not auto-execute.

Step 1: Load capabilities

Read .vulnetix/capabilities.yaml. Specifically binaries.nuclei, binaries.curl, binaries.docker.

Step 2: Fetch exploit content

vulnetix vdb exploits "$ARGUMENTS" -o json
vulnetix vdb ai-assisted-exploits get "$ARGUMENTS" -o json

Capture: PoC URLs, Metasploit module IDs, Nuclei template IDs, AI-assisted demo scripts.

Step 3: Fetch Nuclei template (preferred when binary present)

If binaries.nuclei: true:

vulnetix vdb nuclei get "$ARGUMENTS" --format yaml > .vulnetix/exploit-test/${ARGUMENTS}.yaml

Step 4: Render commands

Pick the highest-fidelity option available. Order:

  1. Nuclei + binary present:

    nuclei -t .vulnetix/exploit-test/${ARGUMENTS}.yaml -u "$TARGET"
    
  2. Metasploit module ID present and binaries.msfconsole (probe inline):

    msfconsole -q -x "use <module>; set RHOSTS <target>; run; exit"
    
  3. AI-assisted Python demo script — write to .vulnetix/exploit-test/${ARGUMENTS}.py. Suggest:

    uv run --with requests .vulnetix/exploit-test/${ARGUMENTS}.py "$TARGET"
    
  4. Curl-based PoC (last resort) — fetched from vdb exploits references.

Always include a --target placeholder if the user did not supply one. Refuse to run against any target without explicit user confirmation.

Step 5: Verdict guidance

After the user runs the command, expected outcomes:

  • Pre-fix: vulnerability triggers (response shape varies by CVE — describe expected indicator)
  • Post-fix: command returns benign / 404 / 400

Memory update

Append event: exploit-test-prepared with the chosen command class to the vuln entry.

Safety

  • Never store credentials or tokens in .vulnetix/exploit-test/.
  • Treat any provided target as authorized testing only — surface a one-line authorization reminder.

Edge cases & gotchas

  • Authorisation is the user's responsibility. The skill surfaces an authorisation reminder; the LLM must NOT proceed if the user has not named an authorised target.
  • Nuclei templates are downloaded into .vulnetix/exploit-test/<VULN_ID>.yaml. Review the template before running — some include intrusive payloads.
  • Metasploit module hints reference module IDs, not module paths. Confirm the module is installed in your local msfconsole before invoking.
  • AI-assisted Python demo scripts run with uv run --with requests — the script files live in .vulnetix/exploit-test/ and should never carry secrets.
  • For some CVEs no Nuclei template exists; the skill falls back to a curl-based PoC pulled from vdb exploits references. Curl PoCs are typically least reliable.
  • After running, the skill reads the user-described result and writes the verification outcome to memory — but only if the user explicitly reports back.

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry image for CVEs.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

dashboard

無料

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break, auditing past decisions, onboarding to a repository with security history, or checking nothing high-severity is open before a release.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use when an upgrade is blocked by transitive constraints, a peer-dep conflict surfaces, or you need to override a vulnerable transitive without bumping the parent.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when weighing two candidates, or when a package looks convenient but unmaintained.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying defences for a CVE without a patch, augmenting SAST with active detection, or feeding the SOC engineering pipeline.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

eol-check

無料

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating a deploy against EOL deps, or producing a remediation roadmap.

日本語の概要は準備中です。原文の説明を表示しています。

Vulnetix/pix-ai-coding-assistant92026年9月28日 更新

Vulnetix のスキルをすべて見る

このスキルの問題を報告する