en un clic
ExploitHunter.app
ExploitHunter.app contient 15 skills collectées depuis justsml, avec une couverture métier par dépôt et des pages de détail sur le site.
Skills dans ce dépôt
Plan and use user-consented local camera and microphone observations for an explicitly authorized physical target. Use when a capture can establish a bounded physical-state observation such as whether a test fixture changed state, an instrument reading changed, or equipment noise changed relatively.
Use when a network probe, DNS lookup, HTTP fetch, or nmap scan reports the target host or the internet is unreachable. Stops further probing and reports a target-readiness blocker with useful diagnostics.
Safely develop, verify, and document proof-of-concept exploits and payloads for authorized targets inside isolated Workspace Containers. Use when a Hypothesis is well-founded and the user has explicit authorization to test it, needs a minimal PoC, wants to verify impact, or needs to produce reproducible exploit Evidence for a report.
Turn a specific vulnerability, patch, CVE, Version Diff, or Changelog Claim into a proactive security exploration plan. Use when the user wants research angles, lateral target discovery, patch/CVE strategy, new surface discovery, or hypothesis generation from vulnerability intelligence.
Use when explicitly authorized lab traffic must be captured, searched, or exported from the project's mitmproxy-backed Docker lab recorder.
Passive, citation-grounded review of security-relevant specifications, protocols, standards, APIs, and implementations. Use when a reviewer must trace external preconditions and invariants into source code without treating a cited claim as proof of a vulnerability.
Scientific model and eval tuning loop for prompt/skill/system-prompt changes, model configuration, runtime options, and local/Ollama model sizing or environment variables. Use when tuning eval performance, comparing local or remote models, improving tool-use behavior, reducing timeouts/loops, or deciding whether an eval optimization is worth keeping.
Plan vulnerability research using conventional bug-hunting and pentest stage names, specialty playbooks, and a research-hypothesis-experiment loop. Use when designing a bug bounty workflow, selecting tools and strategies, building a decision tree, or turning a target/scope into a staged hunting plan.
Use common CLI, Kali, and shell tools to inspect web Targets, captured assets, logs, HAR/PCAP files, packages, and generated artifacts, then turn observations into Evidence, Security Signals, and ranked Hypotheses. Use when the user asks for web bug-hunting inspection, digital records, URL maps, crawling, endpoint discovery, JS bundle/package analysis, light forensics, or command-line investigation workflows.
Authorized testing of LLM applications, agents, chatbots, RAG systems, guardrails, and tool-using model workflows. Use for LLM mode selection, jailbreak and prompt-injection assessment, guardrail bypass review, tool misuse, tool or system prompt disclosure, data exfiltration paths, model refusal/stop detection, bypass hypotheses, and hardening guidance.
Passive code-review lane for authorized repositories, local checkouts, uploaded source archives, and diffs. Use when the security research agent needs deterministic candidate discovery before expensive AI investigation, scoped PR-style review, append-only evidence records, or independent revalidation of code findings.
Passive, pattern-calibrated risk discovery for authorized security research over an open-source project, repository URL, dependency, release, or local checkout. Use when the security research agent needs to find highest-risk areas, map attack surface, identify likely bug-hunting targets, prioritize security review, inspect structural/logical/security-critical code, compare vulnerable versus patched versions, reason from broad high-severity vulnerability families, or remember areas of interest for later attack-chain research.
Analyze suspicious SMS/email messages, phishing links, redirects, domains, payloads, malware indicators, and suspected C2 infrastructure safely. Use when the user provides spam, smishing/phishing content, raw .eml headers, URLs, QR links, attachments, hashes, strange payloads, redirect chains, DNS/WHOIS/RDAP questions, C2 clues, exploit-chain questions, or asks what defenses to apply.
Select established CTF and security-research tools for authorized artifact triage, web inspection, reversing, crypto, forensics, networking, and exploit validation. Use when a user provides a CTF-style tool catalog, asks which tools to use, or needs safe usage instructions for common offensive/security tools.
Plan and run safe reverse engineering, decompilation, disassembly, instrumentation, and post-processing workflows for binaries, firmware, mobile apps, WebAssembly, JavaScript bundles, and .NET assemblies. Use when the user asks for reversing strategy, decompiler selection, binary analysis, malware-style triage, Wakaru, Ghidra, IDA, RetDec, radare2, Rizin, Frida, angr, YARA, or command scripts that capture analysis stats.