Skip to main content

EntroVyx/hermes-agent-offsec

SkillsMP는 EntroVyx/hermes-agent-offsec에서 146개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
146
GitHub 스타
4
GitHub 포크
2

이 저장소의 skills

수집된 skill 146개 중 40개를 표시합니다.

직업 분류
기타 컴퓨터 관련 직업
설명

Project self-knowledge for Hermes Agent Offsec. Use when the user asks about this fork, its CLI, configuration, update flow, providers, skills, modes, troubleshooting, or how it differs from the original Hermes Agent.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

WordPress XML-RPC triage: method enum, multicall abuse, pingback SSRF, and upload-chain validation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning, vuln hunting (30+ classes), A-to-B chaining, AI/LLM testing, bypass tables, language-specific grep,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Master bug bounty orchestrator — full pipeline: recon, pre-hunt learning, vulnerability hunting (30+ classes), A-to-B chaining, AI/LLM testing (ASI01-ASI10), language-specific grep, bypass tables, and reporting (7-question gate, CVSS 3.1, human-tone…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Join a Google Meet call, transcribe live captions, optionally speak in realtime, and do the followup work afterwards. Use when the user asks the agent to sit in on a meeting, take notes, summarize, respond in-call, or action items from it.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attack SAML SSO via XSW, signature strip, metadata extract.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Chain multiple vulns into critical impact attack paths.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Execute optimal kill chains for WordPress full compromise.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Exploit Flask/Werkzeug debugger exposure — traceback disclosure, SECRET extraction, console RCE (if enabled), server path disclosure, and Python stack trace information gathering

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Escape Docker containers to host root via 5 techniques.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Public-artifact-first methodology for turning exposed client assets, archived content, public API material, support content, and metadata into high-signal attack-surface maps. Use when starting recon, when a target looks thin from the homepage, or when you…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Visible exploit-chain builder. Use when a primitive appears and the operator needs to convert it into a reportable high-impact chain.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Catalog: 25 attacks, 18 WP, 8 CORS to match findings.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Client-runtime and bundle analysis methodology for converting front-end assets into route maps, auth assumptions, object graphs, and manual test queues. Use when JavaScript, source maps, or mobile-facing assets are available.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Methodology for turning exposed cloud, identity, storage, and backend-service clues into a structured capability assessment and manual validation plan. Use when recon reveals hosted data services, identity platforms, storage endpoints, or public backend…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Continuous recon and campaign-memory methodology for tracking deltas in attack surface, deduplicating noisy signals, and turning change events into prioritized manual testing queues. Use during long hunts or repeated target coverage.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attack-mode entry point for crown-jewel hunting. Use at the beginning of an authorized bug bounty or pentest session to choose the highest-impact objective before recon or exploitation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Manual workflow attack mode for authorized bug bounty and pentest work. Use as /deep-hunt <workflow> to attack one business workflow deeply instead of scanning endpoints shallowly.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Offensive chain builder. Use when you have one or more weak findings and want to score, prioritize, and compose them into a critical or high-impact exploit path.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

High-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Manual testing trees for difficult bug bounty and pentest work. Use after mapping a workflow and before freeform poking so the agent systematically explores actor, state, transport, and secondary-object branches.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Master workflow for offensive campaigns. Use when starting a target, scoping a hunt, or deciding how to split work across reconnaissance, manual testing, chain building, and reporting.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

7-phase pentest pipeline from passive recon to exploitation.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Service-first infrastructure triage methodology for turning discovered ports and banners into attack-surface meaning, weak-boundary hypotheses, and follow-up validation plans. Use when network services, certificates, reverse DNS, or exposed management…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

4-phase pipeline for max findings per minute across batches.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Import HAR exports or raw Burp/Caido HTTP requests into an offensive request map. Use as /request-import <path> to extract endpoints, methods, parameters, cookies, auth hints, and deep-hunt candidates.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Pick sectors, compile targets, batch recon for campaigns.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

How to split offensive campaigns across specialist subagents without duplicating work. Use when a target is large enough that one linear agent loop wastes time.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Create and maintain a persistent target dossier for authorized offsec campaigns. Use as /target-dossier <target> to initialize or update .offsec/campaigns/<target>/TARGET.md.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Persistent target-memory workflow for offsec campaigns. Use when you need structured memory for actors, objects, state transitions, secrets, hypotheses, and chain candidates on a real target.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit no-auth APIs for data theft and CRUD via probes.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Poison CDN cache or deceive when X-Cache header is detected.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Sector-specific recon for carpet cleaning company websites — steam cleaning, stain removal, upholstery cleaning, flood restoration. Typically WordPress on shared hosting with service booking forms, emergency water damage response, and seasonal special offers.…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit WP CORS credential reflection for data theft.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

DMARC/SPF/DKIM check, email spoofing, SMTP test, and security header analysis

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Mine error_log for creds, paths, SQL when leak hunt finds.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exchange/OWA NTLM AD leak, spray attack when mail subdomain.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Exploit Firebase/Supabase for data via JS config leak probe.

원문 언어: 영어

업데이트
수집된 skill 146개 중 40개를 표시합니다.