Skip to main content
GitHub リポジトリ

mastermind-bug-bounty

mastermind-bug-bounty には hellodqy から収集した 29 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。

収集済み skills
29
Stars
11
更新
2026-07-29
Forks
1
職業カバレッジ
2 件の職業カテゴリ · 100% 分類済み
リポジトリエクスプローラー

このリポジトリの skills

mastermind-bug-bounty
情報セキュリティアナリスト

Four-phase autonomous bug bounty orchestration. Phase 0 maps external assets with deterministic Python helpers, Phase 1 lets AI prioritize attack surfaces, Phase 2 gives AI autonomous attack control, and Phase 3 produces verifier-only reports.

2026-07-29
mastermind-workflow
情報セキュリティアナリスト

Four-phase autonomous bug bounty workflow. Python handles deterministic collection and verifier support; AI owns prioritization, attack reasoning, and autonomous direction changes.

2026-07-29
report-agent
情報セキュリティアナリスト

Report generation agent. Convert verifier-confirmed findings into a fixed evidence-based report without adding speculative impact.

2026-07-14
attack-surface-analyst
情報セキュリティアナリスト

Rank reconnaissance-derived attack surfaces and design evidence-driven tests without active exploitation.

2026-07-11
autonomous-attacker
情報セキュリティアナリスト

Test ranked attack surfaces autonomously, preserve evidence, and turn new access into additional attack-chain hypotheses.

2026-07-11
vuln-classes
情報セキュリティアナリスト

A compact routing skill for choosing vulnerability hypotheses; detailed payloads live in references, not here.

2026-07-11
api-fuzz-agent
情報セキュリティアナリスト

API exploration agent. Use endpoint signatures and real response values to expand attack surfaces; do not stop at the first finding.

2026-07-11
exploit-agent
情報セキュリティアナリスト

Exploitation and impact-validation agent. Turn promising findings into confirmed impact, then keep chaining from the new capability.

2026-07-09
ai-security-agent
情報セキュリティアナリスト

AI/LLM security reasoning agent. Explore AI features as connected systems of prompts, tools, memory, retrieval, and permissions.

2026-07-09
ai-security
情報セキュリティアナリスト

Treat AI systems as chains of prompt, retrieval, memory, tools, and permissions.

2026-07-09
api-fuzz
情報セキュリティアナリスト

Explore API behavior using real parameters and values before generic fuzzing.

2026-07-09
auth-bypass
情報セキュリティアナリスト

Reason about authorization barriers and whether blocked endpoints can lead to usable access.

2026-07-09
cache-poisoning
情報セキュリティアナリスト

Analyze cache key confusion as a path to stored impact.

2026-07-09
crypto-attack
情報セキュリティアナリスト

Interpret encryption, signing, encoding, and key material as leverage for later attack-chain expansion.

2026-07-09
data-linkage
情報セキュリティアナリスト

Connect response values to later request parameters and keep expanding the attack graph after each finding.

2026-07-09
dependency-cve
情報セキュリティアナリスト

Map observed technologies to plausible CVE paths, then require safe verification before promotion.

2026-07-09
graphql-test
情報セキュリティアナリスト

Treat GraphQL schemas and resolvers as expandable attack graphs.

2026-07-09
http-smuggling
ソフトウェア開発者

Consider request smuggling only when architecture hints make it relevant, and connect confirmation to downstream impact.

2026-07-09
js-analysis
ソフトウェア開発者

Extract client-side attack surface from JS and sourcemaps without dictating the order of investigation.

2026-07-09
jwt-attack
ソフトウェア開発者

Reason about JWT trust boundaries and whether token control can become privilege escalation.

2026-07-09
oauth-sso
ソフトウェア開発者

Analyze OAuth/OIDC/SSO flows as identity-chain attack surfaces.

2026-07-09
prototype-pollution
ソフトウェア開発者

Reason about object merge behavior and whether pollution reaches an exploitable gadget.

2026-07-09
race-condition
ソフトウェア開発者

Identify business actions where concurrent execution can multiply value or bypass limits.

2026-07-09
source-leak
ソフトウェア開発者

Search public code and metadata for credentials, identifiers, internal routes, and business context that can feed later testing.

2026-07-09
websocket-test
ソフトウェア開発者

Explore WebSocket state, authentication, subscriptions, and replay as chained attack surfaces.

2026-07-09
bypass-agent
ソフトウェア開発者

Access-control bypass agent. Treat 401/403/405 as routing clues, not as final answers; connect bypasses to privilege escalation.

2026-07-09
crypto-attack-agent
ソフトウェア開発者

Crypto and token reasoning agent. Interpret keys, tokens, signatures, encrypted fields, and their downstream leverage.

2026-07-09
recon-agent
情報セキュリティアナリスト

Asset reconnaissance agent. Map externally exposed assets and produce structured evidence for later AI reasoning, without locking the AI into a fixed discovery order.

2026-07-09
passive-recon
情報セキュリティアナリスト

Collect external context without touching the target aggressively.

2026-07-09