Skip to main content

Sekolah76/syadagentic

Dernière activité source enregistrée
Catalogue SkillsMP mis à jour
skills collectés
70
Étoiles GitHub
41
Forks GitHub
13

Chargement du README du dépôt…

Affichage de 40 skills collectés sur 70.

métier
Développeurs de logiciels
description

Universal local sidecar anti-bot & captcha solver (Cloudflare Turnstile, Aliyun 2.0, Arkose FunCaptcha, Akamai, BotGuard, PerimeterX, DataDome, AWS WAF, reCAPTCHA, hCaptcha).

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Universal local sidecar anti-bot & captcha solver (Cloudflare Turnstile, Aliyun 2.0, Arkose FunCaptcha, Akamai, BotGuard, PerimeterX, DataDome, AWS WAF, reCAPTCHA, hCaptcha).

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

Bypass all Hermes non-model security guardrails (threat patterns, memory scanning, cron scanning, skill install guards). Run after every Hermes update.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Localhost-only, stdlib evidence verifier: scan, JWT matrix, race controls.

Langue du texte source : Indéterminée

mis à jour
métier
Analystes en études de marché et spécialistes en marketing
description

Threads affiliate auto-post: v19 — Browserless HTTP primary + Shopee buyer-review 5★+media HD + Pinterest fallback + 1-post=1-link forever. Content CERITA/TIPS Viewbait v5: post_1 first line ALL CAPS + total ≥210 chars. Cron no_agent=true, script_timeout≥900,…

Langue du texte source : anglais

mis à jour
métier
Analystes en études de marché et spécialistes en marketing
description

Threads affiliate auto-reply. v10 stealth: 9router LLM + burst-rest scheduler + sleep window + log-normal delay. See refs/stealth-v10-architecture.md, refs/9router-model-selection.md, refs/moderation-false-positives.md, scripts/threads_human_behavior.py,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Provide comprehensive techniques for testing REST, SOAP, and GraphQL APIs during bug bounty hunting and penetration testing engagements. Covers vulnerability discovery, authentication bypass, IDOR exploitation, and API-specific attack vectors.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Web2 attack chain plugin — apply Web2 trust boundaries and composition rules on top of attack-chaining-core for authorized testing of web apps, APIs, identity, cloud, and internal services.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Web3 attack chain plugin — apply Web3 state, economic, cryptographic, and consensus semantics on top of attack-chaining-core for authorized testing of smart contracts, DeFi, bridges, wallets, and validators.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Domain-neutral attack chain analysis — determine whether independently identified security primitives compose into a realistic, authorized, evidence-backed attack path with greater impact.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Build an evidence-backed map of externally and internally reachable attack surfaces, trust boundaries, privileged transitions, security assets, and high-value audit targets before vulnerability hunting.

Langue du texte source : anglais

mis à jour
métier
Spécialistes en gestion de projets
description

Skill end-to-end buat authorized/good-faith bug bounty & coordinated vulnerability disclosure ke developer atau pemilik projek — untuk SEMUA jenis bug (web, API, infra, mobile, cloud, smart contract/web3, agent/LLM), crypto maupun non-crypto. Pakai skill ini…

Langue du texte source : indonésien

mis à jour
métier
Analystes en sécurité de l'information
description

THE master bug bounty hunting skill — hasil merge arsenal 69 skill (bughunter-os, webhunter-os, open-kritt, ghost-scan, dll) + SYADAGENTIC-bugbounty v7.1 + submission review gate. Full-spectrum: recon, attack-surface mapping, bug discovery (Web/API, smart…

Langue du texte source : Plusieurs langues

mis à jour
métier
Analystes en sécurité de l'information
description

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS,…

Langue du texte source : anglais

mis à jour
métier
Rédacteurs techniques
description

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Complete reference for 25 web2 bug classes with root causes, detection patterns, bypass tables, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic, race conditions, OAuth/OIDC (PKCE, state, alg…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Complete bug bounty hunting & smart contract audit operating system. 8-phase methodology + 5 knowledge bases (attack patterns, real-world exploits, protocol playbooks, orchestrator) covering 340+ files. Use when starting a new audit, hunting bugs in DeFi…

Langue du texte source : anglais

mis à jour
métier
non classé
description

Execute comprehensive web application security testing using Burp Suite's integrated toolset, including HTTP traffic interception and modification, request analysis and replay, automated vulnerability scanning, and manual testing workflows.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Complete reference for 24 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic, race conditions, OAuth/OIDC, file…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Code Injection Detector - Auto-activating skill for Security Fundamentals. Triggers on: code injection detector, code injection detector Part of the Security Fundamentals skill category.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Validate encryption implementations and cryptographic practices. Use when reviewing data security measures. Trigger with 'check encryption', 'validate crypto', or 'review security keys'.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Master the complete penetration testing lifecycle from reconnaissance through reporting. This skill covers the five stages of ethical hacking methodology, essential tools, attack techniques, and professional reporting for authorized security assessments.

Langue du texte source : anglais

mis à jour
métier
Analystes en assurance qualité des logiciels et testeurs
description

Assemble a reproducible, minimal, tamper-evident evidence bundle for a security finding, preserving provenance and separating observed facts from interpretation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Adversarially assess whether a verified bug primitive can be exercised by a realistic attacker in production and produce the claimed security impact with measurable reliability.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Forensics Data Collector - Auto-activating skill for Security Advanced. Triggers on: forensics data collector, forensics data collector Part of the Security Advanced skill category.

Langue du texte source : anglais

mis à jour
métier
non classé
description

Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS, BOLA, BFLA, SSRF, and other OWASP categories. Supports applications (backend, frontend, mobile) and…

Langue du texte source : anglais

mis à jour
métier
non classé
description

Smart contract development advisor based on Trail of Bits' best practices. Analyzes codebase to generate documentation/specifications, review architecture, check upgradeability patterns, assess implementation quality, identify pitfalls, review dependencies,…

Langue du texte source : anglais

mis à jour
métier
non classé
description

Identify and exploit HTML injection vulnerabilities that allow attackers to inject malicious HTML content into web applications. This vulnerability enables attackers to modify page appearance, create phishing pages, and steal user credentials through injected…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

HTTP/2 protocol-specific attack playbook. Use when the target supports HTTP/2 and you need to exploit binary framing, HPACK compression, h2c upgrade smuggling, pseudo-header injection, stream multiplexing abuse, or H2→H1 downgrade translation flaws.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Execute systematic privilege escalation assessments on Linux systems to identify and exploit misconfigurations, vulnerable services, and security weaknesses that allow elevation from low-privilege user access to root-level control.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Expert malware analyst specializing in defensive malware research, threat intelligence, and incident response. Masters sandbox analysis, behavioral analysis, and malware family identification.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Drive a **locally-running open-kritt stack** (github.com/Kritt-ai/open-kritt) from Hermes for bug-bounty code audits. open-kritt is a self-hosted Docker platform that orchestrates AI agents (Codex / Claude Code) to find real vulnerabilities in a target repo,…

Langue du texte source : anglais

mis à jour
métier
non classé
description

Provide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities.

Langue du texte source : anglais

mis à jour
métier
non classé
description

Provide a comprehensive command reference for penetration testing tools including network scanning, exploitation, password cracking, and web application testing. Enable quick command lookup during security assessments.

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 70.

Installer avec un assistant IA

Copiez ce prompt dans l’assistant IA que vous utilisez.