ワンクリックで
thefounds
thefounds には osloxdao から収集した 29 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。
このリポジトリの skills
Download all JS/WASM/CSS assets from a target URL using cloudscraper. Saves to output/[domain]/. Called by crypto-recon-orchestrator.
Specialist for EVM blockchain cryptography — EIP-712, personal_sign, ABI encoding, keccak256, ethers.js/wagmi/viem/web3.js. EVM chains only (Ethereum, Polygon, BSC, Arbitrum, etc.). For non-EVM use crypto-recon-web3-solana, crypto-recon-web3-cosmos, or crypto-recon-web3-starknet.
Verifies reconstructed APK signing logic against live app traffic. Uses HAR test vectors or ADB+mitmproxy. Extends crypto-recon-debugging for Android context.
Specialist for finding ALL cryptography in decompiled Android APK — Java source (jadx) and Smali bytecode (apktool). Covers OkHttp interceptors, Retrofit, HMAC, AES, MD5, custom signing, ProGuard-obfuscated code.
Master orchestrator for Android APK reverse engineering. Fully autonomous — decompiles APK, spawns 11 parallel specialists, collects findings, writes report, reconstructs Python code. No intermediate stops. Accepts .apk/.apkm/.xapk + optional HAR.
Builds a complete, clean, standalone Python script for a full API flow (login, register, place bet, etc). Accepts input from reconstruct_*.py files AND from APK flow mappers (Retrofit catalog, auth chain trace, API endpoint list). Called automatically after analysis — no user prompting needed. Uses superpowers executing-plans and verification-before-completion.
Verifies reconstructed crypto/signing is correct by testing against live API. Finds exactly what's wrong when signature fails. Extends superpowers systematic-debugging with HTTP-level validation.
Specialist agent for handling minified, obfuscated, and webpack-bundled JavaScript before crypto analysis. Runs between download and analysis phases. Part of crypto-recon pipeline.
Scans downloaded JS files to determine if target is Web2, Web3, or Hybrid. Routes to appropriate specialist set. Must run before analysis specialists. Called by thefound and crypto-recon-orchestrator.
Specialist agent for detecting ALL encoding, obfuscation, and data transformation schemes in downloaded JS files. Part of crypto-recon pipeline.
Reads and analyzes HAR (HTTP Archive) files from browser DevTools intercept. Extracts real API endpoints, actual signatures, request/response structure, and auth tokens. Natural entry point before crypto-recon-building — provides real data instead of guesses.
Specialist agent for detecting ALL key derivation functions in downloaded JS files. Part of crypto-recon pipeline.
Specialist agent for detecting ALL MAC (Message Authentication Code) functions in downloaded JS files. Part of crypto-recon pipeline.
Entry point for all web crypto reverse engineering. Use when user provides any URL and wants to find, map, or reconstruct cryptography from a web application.
Comprehensive API penetration testing specialist. Runs AFTER flow script is built. Spawns parallel test agents for auth bypass, header manipulation, injection (SQLi/RCE/SSTI), IDOR, SSRF, mass assignment, business logic, and rate limiting. Generates full vuln report. Requires authorized target only.
Use BEFORE starting any crypto recon analysis. Creates a structured investigation plan — what to find, which endpoints matter, what success looks like. Extends superpowers writing-plans for crypto domain.
Generates clean Python reconstruction of discovered crypto/signing logic. Called automatically by orchestrator — no user selection needed. Auto-picks the highest-priority finding (signing > HMAC > AES > other). Part of crypto-recon pipeline.
Final report writer for crypto-recon pipeline. Compiles all specialist findings into a structured markdown report saved to output/[domain]/final/[domain].md
Specialist agent for detecting ALL API request signing patterns in downloaded JS files. Highest value target. Part of crypto-recon pipeline.
Specialist for Cosmos/IBC and Polkadot/Substrate cryptography in JS bundles. Covers CosmJS, Keplr, Amino/Protobuf encoding, Sr25519/Ed25519, SCALE encoding, and all ecosystem wallets.
Specialist for Ed25519-based blockchain cryptography in JS bundles — Solana, Aptos, Sui, NEAR, TON, Algorand, Cardano. Covers transaction signing, instruction encoding, Borsh/BCS serialization, and all wallet SDKs.
Specialist for StarkNet and ZK-based chain cryptography — Pedersen hash, Poseidon hash, Stark curve, Cairo felt252 types, SNARK-based signing, and all StarkNet SDKs. Fundamentally different from all other chains.
Master entry point for the full crypto recon pipeline. Handles URLs (web) and APK files (.apk/.apkm/.xapk). Drives the entire pipeline automatically from goal to working Python code — no intermediate stops.
Specialist agent for detecting ALL asymmetric/public-key cryptography in downloaded JS files. Part of crypto-recon pipeline.
Specialist agent for finding custom, obfuscated, or non-standard cryptography in downloaded JS files. Last line of defense for hidden crypto. Part of crypto-recon pipeline.
Specialist agent for detecting ALL hash/digest functions in downloaded JS files. Part of crypto-recon pipeline.
Specialist agent for detecting JWT, OAuth, session tokens, and all token-based authentication patterns in downloaded JS files. Part of crypto-recon pipeline.
Specialist agent for identifying ALL cryptography libraries loaded or used in downloaded JS files. Maps the crypto ecosystem of the target app. Part of crypto-recon pipeline.
Specialist agent for detecting ALL symmetric encryption/decryption in downloaded JS files. Part of crypto-recon pipeline.