Skip to main content
Exécutez n'importe quel Skill dans Manus
en un clic
Dépôt GitHub

ExploitHunter.app

ExploitHunter.app contient 15 skills collectées depuis justsml, avec une couverture métier par dépôt et des pages de détail sur le site.

skills collectés
15
Stars
7
mis à jour
2026-07-22
Forks
0
Couverture métier
4 catégories métier · 100% classifié
explorateur de dépôts

Skills dans ce dépôt

audio-video-capture
Développeurs de logiciels

Plan and use user-consented local camera and microphone observations for an explicitly authorized physical target. Use when a capture can establish a bounded physical-state observation such as whether a test fixture changed state, an instrument reading changed, or equipment noise changed relatively.

2026-07-22
network-reachability
Administrateurs de réseaux et de systèmes informatiques

Use when a network probe, DNS lookup, HTTP fetch, or nmap scan reports the target host or the internet is unreachable. Stops further probing and reports a target-readiness blocker with useful diagnostics.

2026-07-22
exploitation-sandbox
Analystes en sécurité de l'information

Safely develop, verify, and document proof-of-concept exploits and payloads for authorized targets inside isolated Workspace Containers. Use when a Hypothesis is well-founded and the user has explicit authorization to test it, needs a minimal PoC, wants to verify impact, or needs to produce reproducible exploit Evidence for a report.

2026-07-21
proactive-security-strategy
Analystes en sécurité de l'information

Turn a specific vulnerability, patch, CVE, Version Diff, or Changelog Claim into a proactive security exploration plan. Use when the user wants research angles, lateral target discovery, patch/CVE strategy, new surface discovery, or hypothesis generation from vulnerability intelligence.

2026-07-21
network-recording
Développeurs de logiciels

Use when explicitly authorized lab traffic must be captured, searched, or exported from the project's mitmproxy-backed Docker lab recorder.

2026-07-18
spec-implementation-review
Analystes en assurance qualité des logiciels et testeurs

Passive, citation-grounded review of security-relevant specifications, protocols, standards, APIs, and implementations. Use when a reviewer must trace external preconditions and invariants into source code without treating a cited claim as proof of a vulnerability.

2026-07-17
tune-model-evals
Développeurs de logiciels

Scientific model and eval tuning loop for prompt/skill/system-prompt changes, model configuration, runtime options, and local/Ollama model sizing or environment variables. Use when tuning eval performance, comparing local or remote models, improving tool-use behavior, reducing timeouts/loops, or deciding whether an eval optimization is worth keeping.

2026-07-07
bug-hunt-planner
Analystes en sécurité de l'information

Plan vulnerability research using conventional bug-hunting and pentest stage names, specialty playbooks, and a research-hypothesis-experiment loop. Use when designing a bug bounty workflow, selecting tools and strategies, building a decision tree, or turning a target/scope into a staged hunting plan.

2026-07-07
web-inspection-forensics
Analystes en sécurité de l'information

Use common CLI, Kali, and shell tools to inspect web Targets, captured assets, logs, HAR/PCAP files, packages, and generated artifacts, then turn observations into Evidence, Security Signals, and ranked Hypotheses. Use when the user asks for web bug-hunting inspection, digital records, URL maps, crawling, endpoint discovery, JS bundle/package analysis, light forensics, or command-line investigation workflows.

2026-07-07
llm-security-testing
Analystes en sécurité de l'information

Authorized testing of LLM applications, agents, chatbots, RAG systems, guardrails, and tool-using model workflows. Use for LLM mode selection, jailbreak and prompt-injection assessment, guardrail bypass review, tool misuse, tool or system prompt disclosure, data exfiltration paths, model refusal/stop detection, bypass hypotheses, and hardening guidance.

2026-06-28
code-security-review
Analystes en assurance qualité des logiciels et testeurs

Passive code-review lane for authorized repositories, local checkouts, uploaded source archives, and diffs. Use when the security research agent needs deterministic candidate discovery before expensive AI investigation, scoped PR-style review, append-only evidence records, or independent revalidation of code findings.

2026-06-28
risk-discovery
Analystes en sécurité de l'information

Passive, pattern-calibrated risk discovery for authorized security research over an open-source project, repository URL, dependency, release, or local checkout. Use when the security research agent needs to find highest-risk areas, map attack surface, identify likely bug-hunting targets, prioritize security review, inspect structural/logical/security-critical code, compare vulnerable versus patched versions, reason from broad high-severity vulnerability families, or remember areas of interest for later attack-chain research.

2026-06-27
threat-intake-analysis
Analystes en sécurité de l'information

Analyze suspicious SMS/email messages, phishing links, redirects, domains, payloads, malware indicators, and suspected C2 infrastructure safely. Use when the user provides spam, smishing/phishing content, raw .eml headers, URLs, QR links, attachments, hashes, strange payloads, redirect chains, DNS/WHOIS/RDAP questions, C2 clues, exploit-chain questions, or asks what defenses to apply.

2026-06-26
ctf-tool-selection
Analystes en sécurité de l'information

Select established CTF and security-research tools for authorized artifact triage, web inspection, reversing, crypto, forensics, networking, and exploit validation. Use when a user provides a CTF-style tool catalog, asks which tools to use, or needs safe usage instructions for common offensive/security tools.

2026-06-26
reverse-engineering-analysis
Analystes en sécurité de l'information

Plan and run safe reverse engineering, decompilation, disassembly, instrumentation, and post-processing workflows for binaries, firmware, mobile apps, WebAssembly, JavaScript bundles, and .NET assemblies. Use when the user asks for reversing strategy, decompiler selection, binary analysis, malware-style triage, Wakaru, Ghidra, IDA, RetDec, radare2, Rizin, Frida, angr, YARA, or command scripts that capture analysis stats.

2026-06-26