Skip to main content
Run any Skill in Manus
with one click
GitHub repository

MaxTAC

MaxTAC contains 45 collected skills from philo-groves, with repository-level occupation coverage and site-owned skill detail pages.

skills collected
45
Stars
12
updated
2026-07-01
Forks
0
Occupation coverage
4 occupation categories · 100% classified
repository explorer

Skills in this repository

maxtac-source-codebase-memory
computer-occupations-all-other

Use this skill when MaxTAC Source should use the plugin-bundled codebase-memory-mcp MCP integration or CLI fallback for repository indexing, architecture overview, structural search, call-path tracing, diff impact mapping, ADR lookup, or code graph evidence before SAST triage, CFG work, OpenGrep authoring, or source scans.

2026-07-01
maxtac-android-input-loop
software-developers

Use this skill when MaxTAC Android needs a loop that models an Android app's user-facing resources and systematically walks activities, deep links, forms, WebViews, share targets, notifications, and other user-facing inputs for security auditing while respecting scope and safety constraints.

2026-07-01
maxtac-asb-ipsw-cve-history-loop
software-developers

Use this skill when Apple Systems research needs a loop over IPSW or OTA firmware diffs, Apple security advisories, CVEs, build provenance, and binary/source patch archaeology to identify patched Apple components, infer why they changed, and enrich an ASB threat model.

2026-07-01
maxtac-binary-decompile-loop
software-developers

Use this skill when MaxTAC Binary needs a loop to model how a binary was compiled and loaded, preserve reverse-engineering provenance, prioritize executable functions by reachability or call frequency, systematically decompile or parse functions and data structures, and produce durable functionality and security evidence.

2026-07-01
maxtac-core-modeling
software-developers

Use this skill when MaxTAC research needs a durable security model, invariant dictionary, invariant receipts with proof obligations and refutation conditions, architecture understanding, first-order-logic-style assertions, unknown tracking, contradiction tracking, or model-backed auditor handoffs across source, web, cloud, binary, supply-chain, Android, Apple, or Microsoft targets.

2026-07-01
maxtac-core-subagents
software-developers

Use this skill when MaxTAC research needs goal-bounded auditor subagents, verifier debate subagents, specialist bug-class review, mitigation review, or independent votes on a vulnerability hypothesis or PoV.

2026-07-01
maxtac-core-workflow
software-developers

Use this skill when starting, organizing, or continuing an authorized MaxTAC vulnerability research session with standard directories, phases, domain loop state, closure profiles, thin closure decisions, adversarial false-negative review, subsystem notes, validation, proof, and reporting flow.

2026-07-01
maxtac-source-deep-scan-loop
software-developers

Use this skill when MaxTAC Source needs a loop to deeply audit every security-relevant function, field, route, handler, or generated code item in a bounded code subsystem, with invariant modeling, sensitivity prioritization, item-level evidence, and auditable closure.

2026-07-01
maxtac-source-invariant-loop
software-developers

Use this skill when MaxTAC Source needs a loop that models security invariants for a code subsystem, maps guards, sinks, entrypoints, callers, and proof obligations in source or decompiler output, then performs targeted audits for invariant violations.

2026-07-01
maxtac-source-patch-history-loop
software-developers

Use this skill when MaxTAC Source needs a loop over source commit history, public CVEs or advisories, vendor releases, and quiet hardening diffs to enrich a code subsystem threat model, identify bug precedent, prioritize risky files or functions, or seed targeted audits.

2026-07-01
maxtac-web-input-loop
software-developers

Use this skill when MaxTAC Web needs a scoped loop that models a sitemap, route or API input inventory, then systematically walks user-controllable web inputs for deep security auditing while respecting authorization, program scope, rate limits, and safety constraints.

2026-07-01
maxtac-core-contracts
software-developers

Use this skill when MaxTAC research needs canonical machine-readable result contracts, thin closure bundles, false-negative review references, finding schemas, coverage closure records, deterministic report projection, or conversion from primitive/chain ledgers into a sealed review bundle.

2026-06-30
maxtac-core-corpus
computer-occupations-all-other

Use this skill when MaxTAC research needs a growable faceted knowledge base, canonical research notes, closure notes, false-negative review references, tag and graph based retrieval, anti-tunnel orientation packs, generated research views, import of existing research markdown, or workspace corpus hygiene instead of hand-growing directory hierarchies.

2026-06-30
maxtac-core-ledger
computer-occupations-all-other

Use this skill when MaxTAC vulnerability research needs finding state tracking, deduplication, promotion, de-escalation, report linkage, or proof status updates.

2026-06-30
maxtac-source-scan
software-quality-assurance-analysts-and-testers

Use this skill when MaxTAC Source needs a Git-backed diff scan, repository or scoped-path source review, deterministic source worklists, thin exact-path closure, coverage receipts, closure validation, or canonical MaxTAC result-contract output for source security review.

2026-06-30
maxtac-apple-surface-triage
information-security-analysts

Use this skill when Apple platform vulnerability research needs first-pass target, build, entitlement, sandbox, TCC, IPC, service, driver, WebKit, or mitigation-bypass surface triage.

2026-06-30
maxtac-cloud-surface-triage
information-security-analysts

Use this skill when AWS, Azure, or GCP vulnerability research needs initial account, subscription, project, service, identity, data, runtime, network, or trust-boundary triage.

2026-06-30
maxtac-windows-surface-triage
information-security-analysts

Use this skill when Windows or Microsoft systems vulnerability research needs first-pass build, identity, token, service, COM/RPC/ALPC, object namespace, driver, sandbox, or mitigation surface triage.

2026-06-30
maxtac-sast-surface-triage
software-developers

Use this skill when starting static surface triage for source code or existing decompiler output to map trust boundaries, dangerous code areas, entrypoints, sinks, invariants, and route hypotheses to auditors, OpenGrep, or control-flow graph analysis.

2026-06-30
maxtac-supply-chain-triage
computer-occupations-all-other

Use this skill when supply-chain research needs initial routing across dependency, package-manager, build, CI/CD, artifact provenance, signing, registry, container artifact, release-pipeline, compromise-hunting, or OSS proof-gating workflows.

2026-06-30
maxtac-web-surface-triage
software-developers

Use this skill when web application or API vulnerability research needs route, session, tenant, authorization, request-flow, browser-state, or business-logic surface triage.

2026-06-30
maxtac-cloud-data-exposure
information-security-analysts

Use this skill when AWS, Azure, or GCP vulnerability research involves storage, databases, snapshots, backups, logs, keys, signed access, data-plane permissions, or cross-account data exposure.

2026-06-29
maxtac-cloud-iam-boundary
information-security-analysts

Use this skill when AWS, Azure, or GCP vulnerability research depends on IAM, RBAC, trust policy, federation, service identity, impersonation, delegated deployment authority, or privilege-boundary proof.

2026-06-29
maxtac-cloud-runtime-boundary
information-security-analysts

Use this skill when AWS, Azure, or GCP vulnerability research involves compute, serverless, containers, metadata services, workload identity, managed Kubernetes, network perimeters, or runtime-to-cloud privilege paths.

2026-06-29
maxtac-sast-control-flow-graph
software-developers

Use this skill when SAST needs static control-flow or call-graph evidence for reachability, guard dominance, path feasibility, callbacks, lock order, cleanup paths, state transitions, or source-to-sink paths in source code or existing decompiler output.

2026-06-29
maxtac-sast-opengrep
software-developers

Use this skill when SAST needs OpenGrep rule authoring, static vulnerability search, taint or pattern matching, result interpretation, or packaging evidence for MaxTAC analysis.

2026-06-29
maxtac-source-finding-intake
software-developers

Use this skill when MaxTAC needs to import, normalize, and statically triage external security findings such as SARIF, GitHub code scanning or Dependabot exports, CVE/GHSA advisories, scanner JSON, bug bounty reports, Jira or Linear ticket text, or freeform vulnerability claims against a repository.

2026-06-29
maxtac-supply-chain-cicd-release-takeover
software-developers

Use this skill when MaxTAC Supply Chains needs advanced CI/CD, workflow, runner, cache, OIDC, release, publishing, signing, artifact promotion, or deployment takeover analysis.

2026-06-29
maxtac-supply-chain-compromise-hunt
software-developers

Use this skill when MaxTAC Supply Chains needs SOTA compromise hunting for suspicious packages, dependencies, release assets, containers, maintainer accounts, registry events, build tools, or artifact provenance anomalies.

2026-06-29
maxtac-supply-chain-oss-proof-gate
software-developers

Use this skill when MaxTAC Supply Chains needs OSS, dependency, package, or supply-chain finding proof gating before reporting, including OSS-style scope, dependency-owner, and real-world impact checks.

2026-06-29
maxtac-supply-chain-source-artifact-diff
software-developers

Use this skill when MaxTAC Supply Chains needs source-to-package, source-to-release, source-to-container, build provenance, signature, SLSA, SBOM, or artifact integrity diffing for supply-chain compromise research.

2026-06-29
maxtac-asb-flag-proof
information-security-analysts

Use this skill when an Apple Security Bounty chain needs a Commpage or TCC proof workflow and a verifiable proof packet for a target-flag claim.

2026-06-29
maxtac-asb-ipsw
information-security-analysts

Use this skill when Apple vulnerability research needs advanced IPSW or OTA provenance, patch diffing, kernelcache or dyld analysis, and firmware-derived ASB evidence.

2026-06-29
maxtac-asb-mitigations
information-security-analysts

Use this skill when Apple exploit research has a proven primitive and needs mitigation-bypass direction, controls, and proof artifacts for ASB-quality evidence.

2026-06-29
maxtac-android-runtime-debugging
software-developers

Use this skill when Android research needs authorized ADB, logcat, JDWP, Frida, component launch, content-provider probing, appops, dumpsys, or runtime evidence capture.

2026-06-28
maxtac-re-jadx
software-developers

Use this skill when Android reverse engineering needs JADX for APK, DEX, JAR, AAR, AAB, smali, resource decoding, deobfuscation, mappings, GUI search, smali debugging, API automation, or plugin workflows.

2026-06-28
maxtac-dast-debugger
software-developers

Use this skill when binary or systems dynamic analysis requires debugger, instrumentation, crash replay, or runtime tooling such as Radare2 DBG, LLDB, GDB, x64dbg, WinDbg, or Frida.

2026-06-28
maxtac-dast-fuzzer
software-developers

Use this skill when binary or systems dynamic testing needs fuzzing for parsers, native libraries, kernels, protocols, managed runtimes, coverage-guided engines, grammar fuzzers, or harness selection.

2026-06-28
maxtac-re-radare2
software-developers

Use this skill when binary reverse engineering needs radare2 for binary analysis, expression or string search, binary diffing, debugging, ESIL emulation, or hex utilities.

2026-06-28
maxtac-web-api-fuzzing
software-developers

Use this skill when web or API dynamic testing needs stateful request fuzzing, schema-backed fuzzing, parameter fuzzing, captured HTTP replay, or logic-oracle evidence.

2026-06-28
Showing top 40 of 45 collected skills in this repository.