con un clic
ExploitHunter.app
ExploitHunter.app contiene 15 skills recopiladas de justsml, con cobertura ocupacional por repositorio y páginas de detalle dentro del sitio.
Skills en este repositorio
Plan and use user-consented local camera and microphone observations for an explicitly authorized physical target. Use when a capture can establish a bounded physical-state observation such as whether a test fixture changed state, an instrument reading changed, or equipment noise changed relatively.
Use when a network probe, DNS lookup, HTTP fetch, or nmap scan reports the target host or the internet is unreachable. Stops further probing and reports a target-readiness blocker with useful diagnostics.
Safely develop, verify, and document proof-of-concept exploits and payloads for authorized targets inside isolated Workspace Containers. Use when a Hypothesis is well-founded and the user has explicit authorization to test it, needs a minimal PoC, wants to verify impact, or needs to produce reproducible exploit Evidence for a report.
Turn a specific vulnerability, patch, CVE, Version Diff, or Changelog Claim into a proactive security exploration plan. Use when the user wants research angles, lateral target discovery, patch/CVE strategy, new surface discovery, or hypothesis generation from vulnerability intelligence.
Use when explicitly authorized lab traffic must be captured, searched, or exported from the project's mitmproxy-backed Docker lab recorder.
Passive, citation-grounded review of security-relevant specifications, protocols, standards, APIs, and implementations. Use when a reviewer must trace external preconditions and invariants into source code without treating a cited claim as proof of a vulnerability.
Scientific model and eval tuning loop for prompt/skill/system-prompt changes, model configuration, runtime options, and local/Ollama model sizing or environment variables. Use when tuning eval performance, comparing local or remote models, improving tool-use behavior, reducing timeouts/loops, or deciding whether an eval optimization is worth keeping.
Plan vulnerability research using conventional bug-hunting and pentest stage names, specialty playbooks, and a research-hypothesis-experiment loop. Use when designing a bug bounty workflow, selecting tools and strategies, building a decision tree, or turning a target/scope into a staged hunting plan.
Use common CLI, Kali, and shell tools to inspect web Targets, captured assets, logs, HAR/PCAP files, packages, and generated artifacts, then turn observations into Evidence, Security Signals, and ranked Hypotheses. Use when the user asks for web bug-hunting inspection, digital records, URL maps, crawling, endpoint discovery, JS bundle/package analysis, light forensics, or command-line investigation workflows.
Authorized testing of LLM applications, agents, chatbots, RAG systems, guardrails, and tool-using model workflows. Use for LLM mode selection, jailbreak and prompt-injection assessment, guardrail bypass review, tool misuse, tool or system prompt disclosure, data exfiltration paths, model refusal/stop detection, bypass hypotheses, and hardening guidance.
Passive code-review lane for authorized repositories, local checkouts, uploaded source archives, and diffs. Use when the security research agent needs deterministic candidate discovery before expensive AI investigation, scoped PR-style review, append-only evidence records, or independent revalidation of code findings.
Passive, pattern-calibrated risk discovery for authorized security research over an open-source project, repository URL, dependency, release, or local checkout. Use when the security research agent needs to find highest-risk areas, map attack surface, identify likely bug-hunting targets, prioritize security review, inspect structural/logical/security-critical code, compare vulnerable versus patched versions, reason from broad high-severity vulnerability families, or remember areas of interest for later attack-chain research.
Analyze suspicious SMS/email messages, phishing links, redirects, domains, payloads, malware indicators, and suspected C2 infrastructure safely. Use when the user provides spam, smishing/phishing content, raw .eml headers, URLs, QR links, attachments, hashes, strange payloads, redirect chains, DNS/WHOIS/RDAP questions, C2 clues, exploit-chain questions, or asks what defenses to apply.
Select established CTF and security-research tools for authorized artifact triage, web inspection, reversing, crypto, forensics, networking, and exploit validation. Use when a user provides a CTF-style tool catalog, asks which tools to use, or needs safe usage instructions for common offensive/security tools.
Plan and run safe reverse engineering, decompilation, disassembly, instrumentation, and post-processing workflows for binaries, firmware, mobile apps, WebAssembly, JavaScript bundles, and .NET assemblies. Use when the user asks for reversing strategy, decompiler selection, binary analysis, malware-style triage, Wakaru, Ghidra, IDA, RetDec, radare2, Rizin, Frida, angr, YARA, or command scripts that capture analysis stats.