Skip to main content

EntroVyx/hermes-agent-offsec

SkillsMP a collecté 146 skills depuis EntroVyx/hermes-agent-offsec. Ouvrez un skill pour examiner sa source et ses détails.

Dernière activité source enregistrée
Catalogue SkillsMP mis à jour
skills collectés
146
Étoiles GitHub
4
Forks GitHub
2

Affichage de 40 skills collectés sur 146.

métier
Autres occupations informatiques
description

Project self-knowledge for Hermes Agent Offsec. Use when the user asks about this fork, its CLI, configuration, update flow, providers, skills, modes, troubleshooting, or how it differs from the original Hermes Agent.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

WordPress XML-RPC triage: method enum, multicall abuse, pingback SSRF, and upload-chain validation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning, vuln hunting (30+ classes), A-to-B chaining, AI/LLM testing, bypass tables, language-specific grep,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Master bug bounty orchestrator — full pipeline: recon, pre-hunt learning, vulnerability hunting (30+ classes), A-to-B chaining, AI/LLM testing (ASI01-ASI10), language-specific grep, bypass tables, and reporting (7-question gate, CVSS 3.1, human-tone…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Join a Google Meet call, transcribe live captions, optionally speak in realtime, and do the followup work afterwards. Use when the user asks the agent to sit in on a meeting, take notes, summarize, respond in-call, or action items from it.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Attack SAML SSO via XSW, signature strip, metadata extract.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Chain multiple vulns into critical impact attack paths.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Execute optimal kill chains for WordPress full compromise.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Exploit Flask/Werkzeug debugger exposure — traceback disclosure, SECRET extraction, console RCE (if enabled), server path disclosure, and Python stack trace information gathering

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Escape Docker containers to host root via 5 techniques.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Public-artifact-first methodology for turning exposed client assets, archived content, public API material, support content, and metadata into high-signal attack-surface maps. Use when starting recon, when a target looks thin from the homepage, or when you…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Visible exploit-chain builder. Use when a primitive appears and the operator needs to convert it into a reportable high-impact chain.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Catalog: 25 attacks, 18 WP, 8 CORS to match findings.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Client-runtime and bundle analysis methodology for converting front-end assets into route maps, auth assumptions, object graphs, and manual test queues. Use when JavaScript, source maps, or mobile-facing assets are available.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Methodology for turning exposed cloud, identity, storage, and backend-service clues into a structured capability assessment and manual validation plan. Use when recon reveals hosted data services, identity platforms, storage endpoints, or public backend…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Continuous recon and campaign-memory methodology for tracking deltas in attack surface, deduplicating noisy signals, and turning change events into prioritized manual testing queues. Use during long hunts or repeated target coverage.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Attack-mode entry point for crown-jewel hunting. Use at the beginning of an authorized bug bounty or pentest session to choose the highest-impact objective before recon or exploitation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Manual workflow attack mode for authorized bug bounty and pentest work. Use as /deep-hunt <workflow> to attack one business workflow deeply instead of scanning endpoints shallowly.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Offensive chain builder. Use when you have one or more weak findings and want to score, prioritize, and compose them into a critical or high-impact exploit path.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

High-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Manual testing trees for difficult bug bounty and pentest work. Use after mapping a workflow and before freeform poking so the agent systematically explores actor, state, transport, and secondary-object branches.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Master workflow for offensive campaigns. Use when starting a target, scoping a hunt, or deciding how to split work across reconnaissance, manual testing, chain building, and reporting.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

7-phase pentest pipeline from passive recon to exploitation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Service-first infrastructure triage methodology for turning discovered ports and banners into attack-surface meaning, weak-boundary hypotheses, and follow-up validation plans. Use when network services, certificates, reverse DNS, or exposed management…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

4-phase pipeline for max findings per minute across batches.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Import HAR exports or raw Burp/Caido HTTP requests into an offensive request map. Use as /request-import <path> to extract endpoints, methods, parameters, cookies, auth hints, and deep-hunt candidates.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Pick sectors, compile targets, batch recon for campaigns.

Langue du texte source : anglais

mis à jour
métier
Autres occupations informatiques
description

How to split offensive campaigns across specialist subagents without duplicating work. Use when a target is large enough that one linear agent loop wastes time.

Langue du texte source : anglais

mis à jour
métier
Autres occupations informatiques
description

Create and maintain a persistent target dossier for authorized offsec campaigns. Use as /target-dossier <target> to initialize or update .offsec/campaigns/<target>/TARGET.md.

Langue du texte source : anglais

mis à jour
métier
Autres occupations informatiques
description

Persistent target-memory workflow for offsec campaigns. Use when you need structured memory for actors, objects, state transitions, secrets, hypotheses, and chain candidates on a real target.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Exploit no-auth APIs for data theft and CRUD via probes.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Poison CDN cache or deceive when X-Cache header is detected.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Sector-specific recon for carpet cleaning company websites — steam cleaning, stain removal, upholstery cleaning, flood restoration. Typically WordPress on shared hosting with service booking forms, emergency water damage response, and seasonal special offers.…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Exploit WP CORS credential reflection for data theft.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

DMARC/SPF/DKIM check, email spoofing, SMTP test, and security header analysis

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Mine error_log for creds, paths, SQL when leak hunt finds.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Exchange/OWA NTLM AD leak, spray attack when mail subdomain.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Exploit Firebase/Supabase for data via JS config leak probe.

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 146.