Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use…
Skills in this repository
Wyl-cmd/kxns-cli - Page 3
SkillsMP has collected 97 skills from Wyl-cmd/kxns-cli. Open a skill to review its source and details.
Wyl-cmd/kxns-cliShowing 17 of 97 collected skills.
Exploit public bucket Content-Type override for stored XSS on target origin.
Enumerate Hikvision ISAPI endpoints on SCADA and IoT web interfaces.
Security payloads, bypass tables, wordlists, gf pattern names, attack pattern catalog (P-01 to P-25, WP-01 to WP-18, CORS V1-V8), always-rejected bug list, conditionally-valid-with-chain table, security research context and behavioral rules. Use when you need…
Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends KXNS's capabilities with specialized knowledge, workflows, or tool integrations.
Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass.
Detect and verify subdomain takeover via dangling CNAME to unclaimed services.
Spoof TLS ClientHello and JA4 fingerprints for browser impersonation.
Exploit unauthenticated multi-step API flows without credentials.
Discover hidden virtual hosts via Host header fuzzing and SSL certificate parsing.
Screenshot all live hosts for rapid visual triage and technology fingerprinting.
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain…
Hunt WP plugins via REST, exploit CVEs when version known.
Batch WP recon: users, CORS, XMLRPC, leaks across domains.
XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.
Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail.