mit einem Klick
MaxTAC
MaxTAC enthält 45 gesammelte Skills von philo-groves, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.
Skills in diesem Repository
Use this skill when MaxTAC Source should use the plugin-bundled codebase-memory-mcp MCP integration or CLI fallback for repository indexing, architecture overview, structural search, call-path tracing, diff impact mapping, ADR lookup, or code graph evidence before SAST triage, CFG work, OpenGrep authoring, or source scans.
Use this skill when MaxTAC Android needs a loop that models an Android app's user-facing resources and systematically walks activities, deep links, forms, WebViews, share targets, notifications, and other user-facing inputs for security auditing while respecting scope and safety constraints.
Use this skill when Apple Systems research needs a loop over IPSW or OTA firmware diffs, Apple security advisories, CVEs, build provenance, and binary/source patch archaeology to identify patched Apple components, infer why they changed, and enrich an ASB threat model.
Use this skill when MaxTAC Binary needs a loop to model how a binary was compiled and loaded, preserve reverse-engineering provenance, prioritize executable functions by reachability or call frequency, systematically decompile or parse functions and data structures, and produce durable functionality and security evidence.
Use this skill when MaxTAC research needs a durable security model, invariant dictionary, invariant receipts with proof obligations and refutation conditions, architecture understanding, first-order-logic-style assertions, unknown tracking, contradiction tracking, or model-backed auditor handoffs across source, web, cloud, binary, supply-chain, Android, Apple, or Microsoft targets.
Use this skill when MaxTAC research needs goal-bounded auditor subagents, verifier debate subagents, specialist bug-class review, mitigation review, or independent votes on a vulnerability hypothesis or PoV.
Use this skill when starting, organizing, or continuing an authorized MaxTAC vulnerability research session with standard directories, phases, domain loop state, closure profiles, thin closure decisions, adversarial false-negative review, subsystem notes, validation, proof, and reporting flow.
Use this skill when MaxTAC Source needs a loop to deeply audit every security-relevant function, field, route, handler, or generated code item in a bounded code subsystem, with invariant modeling, sensitivity prioritization, item-level evidence, and auditable closure.
Use this skill when MaxTAC Source needs a loop that models security invariants for a code subsystem, maps guards, sinks, entrypoints, callers, and proof obligations in source or decompiler output, then performs targeted audits for invariant violations.
Use this skill when MaxTAC Source needs a loop over source commit history, public CVEs or advisories, vendor releases, and quiet hardening diffs to enrich a code subsystem threat model, identify bug precedent, prioritize risky files or functions, or seed targeted audits.
Use this skill when MaxTAC Web needs a scoped loop that models a sitemap, route or API input inventory, then systematically walks user-controllable web inputs for deep security auditing while respecting authorization, program scope, rate limits, and safety constraints.
Use this skill when MaxTAC research needs canonical machine-readable result contracts, thin closure bundles, false-negative review references, finding schemas, coverage closure records, deterministic report projection, or conversion from primitive/chain ledgers into a sealed review bundle.
Use this skill when MaxTAC research needs a growable faceted knowledge base, canonical research notes, closure notes, false-negative review references, tag and graph based retrieval, anti-tunnel orientation packs, generated research views, import of existing research markdown, or workspace corpus hygiene instead of hand-growing directory hierarchies.
Use this skill when MaxTAC vulnerability research needs finding state tracking, deduplication, promotion, de-escalation, report linkage, or proof status updates.
Use this skill when MaxTAC Source needs a Git-backed diff scan, repository or scoped-path source review, deterministic source worklists, thin exact-path closure, coverage receipts, closure validation, or canonical MaxTAC result-contract output for source security review.
Use this skill when Apple platform vulnerability research needs first-pass target, build, entitlement, sandbox, TCC, IPC, service, driver, WebKit, or mitigation-bypass surface triage.
Use this skill when AWS, Azure, or GCP vulnerability research needs initial account, subscription, project, service, identity, data, runtime, network, or trust-boundary triage.
Use this skill when Windows or Microsoft systems vulnerability research needs first-pass build, identity, token, service, COM/RPC/ALPC, object namespace, driver, sandbox, or mitigation surface triage.
Use this skill when starting static surface triage for source code or existing decompiler output to map trust boundaries, dangerous code areas, entrypoints, sinks, invariants, and route hypotheses to auditors, OpenGrep, or control-flow graph analysis.
Use this skill when supply-chain research needs initial routing across dependency, package-manager, build, CI/CD, artifact provenance, signing, registry, container artifact, release-pipeline, compromise-hunting, or OSS proof-gating workflows.
Use this skill when web application or API vulnerability research needs route, session, tenant, authorization, request-flow, browser-state, or business-logic surface triage.
Use this skill when AWS, Azure, or GCP vulnerability research involves storage, databases, snapshots, backups, logs, keys, signed access, data-plane permissions, or cross-account data exposure.
Use this skill when AWS, Azure, or GCP vulnerability research depends on IAM, RBAC, trust policy, federation, service identity, impersonation, delegated deployment authority, or privilege-boundary proof.
Use this skill when AWS, Azure, or GCP vulnerability research involves compute, serverless, containers, metadata services, workload identity, managed Kubernetes, network perimeters, or runtime-to-cloud privilege paths.
Use this skill when SAST needs static control-flow or call-graph evidence for reachability, guard dominance, path feasibility, callbacks, lock order, cleanup paths, state transitions, or source-to-sink paths in source code or existing decompiler output.
Use this skill when SAST needs OpenGrep rule authoring, static vulnerability search, taint or pattern matching, result interpretation, or packaging evidence for MaxTAC analysis.
Use this skill when MaxTAC needs to import, normalize, and statically triage external security findings such as SARIF, GitHub code scanning or Dependabot exports, CVE/GHSA advisories, scanner JSON, bug bounty reports, Jira or Linear ticket text, or freeform vulnerability claims against a repository.
Use this skill when MaxTAC Supply Chains needs advanced CI/CD, workflow, runner, cache, OIDC, release, publishing, signing, artifact promotion, or deployment takeover analysis.
Use this skill when MaxTAC Supply Chains needs SOTA compromise hunting for suspicious packages, dependencies, release assets, containers, maintainer accounts, registry events, build tools, or artifact provenance anomalies.
Use this skill when MaxTAC Supply Chains needs OSS, dependency, package, or supply-chain finding proof gating before reporting, including OSS-style scope, dependency-owner, and real-world impact checks.
Use this skill when MaxTAC Supply Chains needs source-to-package, source-to-release, source-to-container, build provenance, signature, SLSA, SBOM, or artifact integrity diffing for supply-chain compromise research.
Use this skill when an Apple Security Bounty chain needs a Commpage or TCC proof workflow and a verifiable proof packet for a target-flag claim.
Use this skill when Apple vulnerability research needs advanced IPSW or OTA provenance, patch diffing, kernelcache or dyld analysis, and firmware-derived ASB evidence.
Use this skill when Apple exploit research has a proven primitive and needs mitigation-bypass direction, controls, and proof artifacts for ASB-quality evidence.
Use this skill when Android research needs authorized ADB, logcat, JDWP, Frida, component launch, content-provider probing, appops, dumpsys, or runtime evidence capture.
Use this skill when Android reverse engineering needs JADX for APK, DEX, JAR, AAR, AAB, smali, resource decoding, deobfuscation, mappings, GUI search, smali debugging, API automation, or plugin workflows.
Use this skill when binary or systems dynamic analysis requires debugger, instrumentation, crash replay, or runtime tooling such as Radare2 DBG, LLDB, GDB, x64dbg, WinDbg, or Frida.
Use this skill when binary or systems dynamic testing needs fuzzing for parsers, native libraries, kernels, protocols, managed runtimes, coverage-guided engines, grammar fuzzers, or harness selection.
Use this skill when binary reverse engineering needs radare2 for binary analysis, expression or string search, binary diffing, debugging, ESIL emulation, or hex utilities.
Use this skill when web or API dynamic testing needs stateful request fuzzing, schema-backed fuzzing, parameter fuzzing, captured HTTP replay, or logic-oracle evidence.