Skip to main content

Skills in this repository

Wyl-cmd/kxns-cli - Page 2

SkillsMP has collected 97 skills from Wyl-cmd/kxns-cli. Open a skill to review its source and details.

Wyl-cmd/kxns-cli

Showing 40 of 97 collected skills.

occupation
Information Security Analysts
description

Hunt LDAP Injection and XPath Injection — authentication bypass, blind char-by-char attribute exfiltration, AD user/group enumeration, XML-store XPath bypass. Covers the LDAP special-character set (* ( ) \ NUL /), search-filter-context vs DN-injection,…

updated
occupation
Information Security Analysts
description

Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal — /etc/passwd read, log poisoning → RCE, PHP filter-chain RCE (no upload needed), php:// / data:// / zip:// / phar:// wrappers, RFI via allow_url_include, directory traversal…

updated
occupation
Information Security Analysts
description

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection…

updated
occupation
Information Security Analysts
description

Hunt mass assignment via sensitive field injection and ORM framework exploitation.

updated
occupation
Information Security Analysts
description

Hunt Model Context Protocol (MCP) vulnerabilities in AI-tool integration systems.

updated
occupation
Information Security Analysts
description

Hunt NestJS-specific vulnerabilities: guard bypass, decorator gaps, and microservice auth drift.

updated
occupation
Information Security Analysts
description

Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange. Anonymous NTLM Type-2 challenge capture leaks NetBIOS domain, internal DNS forest, computer name, AD timestamp via AV_PAIRS structure. Default Windows-installer…

updated
occupation
Information Security Analysts
description

Hunting skill for oauth vulnerabilities. Built from 19 public bug bounty reports. Use when hunting oauth on any target.

updated
occupation
Information Security Analysts
description

Hunt Open Redirect — all types including low-impact, chained to OAuth token theft → ATO, phishing chains. URL parameter manipulation, JavaScript redirect, meta refresh, header injection. Use when hunting redirect bugs or building ATO chains.

updated
occupation
Information Security Analysts
description

Hunt client-side and server-side prototype pollution for XSS, auth bypass, and RCE.

updated
occupation
Information Security Analysts
description

Hunting skill for race condition vulnerabilities. Built from 12 public bug bounty reports including modern HTTP/2 single-packet attack cases (James Kettle DEF CON 2023 "Smashing the State Machine"; RyotaK / Flatt Security 10,000-request first-sequence-sync…

updated
occupation
Information Security Analysts
description

Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by relocating signed element, comment injection in NameID (admin@target.com<!--evil-->@attacker.com → some parsers see admin@target.com),…

updated
occupation
Information Security Analysts
description

Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms — anonymous endpoint enumeration, version disclosure, legacy SOAP login bypass (Authentication.asmx), ToolShell precondition chain (CVE-2025-53770), SafeControl reflection…

updated
occupation
Information Security Analysts
description

Hunt source code and build artifact leakage — JavaScript source maps (.js.map) reconstructing TypeScript/ES6 source, Swagger/OpenAPI JSON endpoint discovery, .env/.git exposure, webpack chunks with hardcoded secrets, robots.txt/security.txt recon, build-info…

updated
occupation
Information Security Analysts
description

Hunting skill for sqli vulnerabilities. Built from 12 public bug bounty reports including modern NoSQL injection (Rocket.Chat CVE-2021-22911 MongoDB $regex, Mongoose ORM CVE-2024-53900 $where bypass), modern ORM raw-fragment SQLi (Django CVE-2024-42005,…

updated
occupation
Information Security Analysts
description

Hunting skill for ssrf vulnerabilities. Built from 15 public bug bounty reports including AWS metadata SSRF (HackerOne $25k Analytics PDF, Shopify Exchange $25k, Capital One 106M-record breach, Dropbox/HelloSign $4,913), GCP metadata SSRF (Snapchat $4k),…

updated
occupation
Information Security Analysts
description

Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly and dollar-curly math expressions evaluated server-side. Once…

updated
occupation
Information Security Analysts
description

Complete subdomain hunting — enumeration (crt.sh, subfinder, DNS brute force, permutation, TLD expansion, CT monitoring), staging/dev discovery (WordPress install takeover, security gap analysis, internal subdomain leaks via crt.sh), and takeover exploitation…

updated
occupation
Information Security Analysts
description

Hunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing/weak Origin validation on the WS handshake, no per-message authentication, message tampering, socket.io namespace/room authorization bypass, and handshake-layer Upgrade…

updated
occupation
Information Security Analysts
description

Hunt WordPress-specific vulnerabilities — REST API user enumeration, XMLRPC brute force + SSRF + upload, CORS credential reflect on WP REST API, open registration, cross-subdirectory plugin discovery, Yoast sitemap email disclosure, Application Passwords…

updated
occupation
Information Security Analysts
description

Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target.

updated
occupation
Information Security Analysts
description

Hunting skill for xxe vulnerabilities. Built from 10 public bug bounty reports including SVG-upload XXE, Office-doc (PPTX/DOCX) XXE, SOAP XXE, SAML AssertionConsumer XXE, blind OOB XXE via DTD callback, parameter-entity XXE, XXE-to-LFI, XXE-to-SSRF, and…

updated
occupation
Information Security Analysts
description

Entry P1 category router + expert playbook for injection testing. Covers command injection (OS shell metacharacters, blind/OOB, filter bypass, WAF bypass, reverse shells, PHP disable_functions bypass, component-level sinks), expression language injection…

updated
occupation
Information Security Analysts
description

Attack cameras via RTSP, ONVIF, Axis config when 554 open.

updated
occupation
Information Security Analysts
description

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

updated
occupation
Information Security Analysts
description

Decode, forge, brute JWTs when Bearer auth header is seen.

updated
occupation
Software Developers
description

Answer KXNS CLI usage, configuration, and troubleshooting questions. Use when user asks about KXNS CLI installation, setup, configuration, slash commands, keyboard shortcuts, MCP integration, providers, environment variables, how something works internally,…

updated
occupation
Information Security Analysts
description

LLM prompt injection / system prompt extraction — 40+ technique catalog against hardened GPT-4o-class deployments. Covers direct/indirect/agentic attacks, encoding bypasses, delimiter smuggling, boolean extraction, positional enumeration, RAG poisoning,…

updated
occupation
Information Security Analysts
description

Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vectors (with hardening status), Smart Lockout math, Conditional Access bypass options, ROPC + SAML SSO browser flow, Burp/Playwright templates.…

updated
occupation
Information Security Analysts
description

Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a…

updated
occupation
Information Security Analysts
description

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep —…

updated
occupation
Information Security Analysts
description

Okta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analysis (factors enumeration, push-notification fatigue, SMS bypass), password spray with lockout discipline, Okta-specific phishing primitives…

updated
occupation
Information Security Analysts
description

Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.

updated
occupation
Information Security Analysts
description

7-phase pentest pipeline from passive recon to exploitation.

updated
occupation
Information Security Analysts
description

Chain phpinfo to RCE via exec check when info.php exposed.

updated
occupation
Information Security Analysts
description

Port scan /8-/24 with Masscan+RustScan and nmap banners.

updated
occupation
Information Security Analysts
description

Nmap scan for MySQL, Redis, FTP, SSH, internal API services.

updated
occupation
Information Security Analysts
description

Entry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, building endpoint inventory, choosing the first high-value security testing path, and planning industry-sector recon campaigns.

Source text: Mixed languages

updated
occupation
Information Security Analysts
description

Sector-specific recon for small business service provider websites — plumbers, HVAC, electricians, landscapers, roofers, painters, cleaners, contractors. Typically WordPress, Wix, Squarespace, or custom PHP on shared hosting with minimal security. These sites…

updated
occupation
Information Security Analysts
description

Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the…

updated
Showing 40 of 97 collected skills.