awesome-offsec-claude
awesome-offsec-claude에는 1ikeadragon에서 수집한 skills 21개가 있으며, 저장소 수준 직업 범위와 사이트 내 skill 상세 페이지를 제공합니다.
이 저장소의 skills
Elite AI/LLM exploitation specialist - prompt injection, jailbreaking, agent exploitation, RAG poisoning, multi-modal attacks, model extraction, and system prompt leakage for CTF and red team engagements
Build a full API inventory, trust-boundary map, and prioritized test matrix from specification and observed behavior.
Convert API vulnerability leads into confirmed impact or cleanly disproven outcomes with reproducible evidence.
Execute a predefined API test plan deterministically with complete request-level evidence and final verdicts.
Perform deep exploit-focused binary analysis by tracing attacker-reachable paths to validated vulnerability primitives.
Execute systematic static and dynamic binary analysis to uncover exploitable vulnerability primitives.
Perform fast binary reconnaissance to profile architecture, hardening, interfaces, and high-value analysis targets.
Perform exploit-oriented code review by proving attacker-controlled paths from source to sink and validating impact.
Build an exhaustive map of attack entry points, trust boundaries, and dangerous sinks before exploit-focused code analysis.
Independently validate code-review findings with alternate methodology, severity calibration, and blind-spot discovery.
Build reproducible exploit procedures from validated primitives with clear prerequisites, verification criteria, and safety boundaries.
Correlate individual findings into coherent multi-step attack chains with realistic prerequisites and aggregate impact.
Verify vulnerability findings using independent replay, confounder control, and strict acceptance criteria.
Enumerate and analyze client-side JavaScript for hidden endpoints, secrets, dangerous sinks, and exploitable browser behaviors.
Classify memory-safety defects, evaluate exploitability, and prioritize remediation based on primitive quality and mitigation interaction.
Trace untrusted data from origin to sink across files and layers, including sanitization checkpoints and bypass conditions.
Generate feature-grounded threat scenarios and executable security test cases with prioritized risk rationale.
Fingerprint filtering behavior and build parser-differential bypasses with strong controls, conditionals, and reproducible validation.
Execute scoped web application test cases with strict sequencing, variant control, and replayable evidence.
Deepen preliminary web findings into validated exploit impact using independent confirmation and confidence grading.
Elite methodology for discovering maximum attack surface with minimal detection (5-Layer Approach).