Skip to main content

이 저장소의 skills

H-mmer/pentest-agents - 3페이지

SkillsMP는 H-mmer/pentest-agents에서 162개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

H-mmer/pentest-agents

수집된 skill 162개 중 40개를 표시합니다.

직업 분류
정보 보안 분석가
설명

LLM and Agentic AI vulnerability specialist. Covers OWASP LLM Top 10 v2025 (LLM01-LLM10) and OWASP Agentic AI Top 10 (AA-01..AA-10). Dispatcher passes subtype — 'prompt-injection', 'indirect-injection', 'tool-abuse', 'rag-poisoning', 'vector-idor', 'mcp',…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Continuous monitoring agent for authorized bug bounty programs. Modes: 'baseline' captures initial state, 'check' detects changes, 'scope' re-syncs platform scope. Runs in background.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Custom nuclei template builder. Use when you've found a pattern that should be checked across multiple targets or when existing templates miss a specific vulnerability. Provide the vulnerability details and detection logic.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

OAuth 2.0 / 2.1, OpenID Connect (OIDC), SAML SSO, and JWT specialist. Dispatcher passes subtype — 'oauth', 'oidc', 'saml', or 'jwt' — in the task; falls back to inference. Use for redirect_uri / returnTo flaws, state/nonce/PKCE bypass, alg confusion…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Open Redirect specialist (H1 #38). Use for testing URL redirect parameters, login/logout flows, OAuth callbacks, and any endpoint that redirects based on user input.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Bug bounty PoC and report builder. Use after confirming a vulnerability to create minimal reproduction steps, self-contained HTML demonstration pages, curl-based reproduction scripts, and platform-ready report drafts for HackerOne/Bugcrowd/Intigriti.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Privilege Escalation specialist (H1 #26). Use for testing vertical and horizontal privilege escalation, role manipulation, admin endpoint access, and permission boundary violations.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Report quality scorer. Use BEFORE submitting any report to validate completeness, clarity, title strength, CVSS accuracy, PoC quality, and overall report grade. Provide the draft report path or content.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Race Condition specialist (H1 #29). Use for testing TOCTOU flaws, double-spend, parallel request abuse on balance operations, coupon redemption, and any non-idempotent state changes.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Remote Code Execution specialist (H1 #70). Use for testing command injection, template injection (SSTI), deserialization, expression language injection, and any vector that achieves server-side code execution.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Attack surface ranker. Takes recon output + brain data, produces P1/P2/Kill prioritized attack plan with concrete curl commands for each P1 target. Use after recon to decide what to test first.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Reconnaissance agent for target enumeration. Use for subdomain discovery, port scanning, service fingerprinting, tech stack identification, and OSINT gathering. Specify scope and depth: 'passive' for DNS/cert/OSINT only, 'active' for port scans and probing,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Security report generation agent. Use for compiling findings into formal penetration test reports, executive summaries, technical write-ups, and bug bounty submissions. Provide the findings directory or list of vulnerabilities to document.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Maps dangerous operations in a source file: memory ops, type casts, arithmetic near trust boundaries, free/dealloc patterns. Pattern matching task — list what you see, don't speculate. Use via /sast command.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Adversarial validator for SAST findings. Your ONLY job is to DISPROVE the candidate. Find every reason it's not exploitable. If you can't disprove it, it survives. Use via /sast command.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Maps entry points where untrusted data enters a source file. Lists every function that receives external input with data type, size constraints, and initial validation. Use via /sast command.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Builds working exploits from confirmed SAST findings. Takes a confirmed crash, develops it into a full exploit. Tier 1 (DoS) → Tier 5 (code execution). Use via /sast command after PoC confirmation.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Source file attack surface ranker. Reads a repository, scores every source file 1-5 by exploitability. Outputs ranked JSON for per-file hunting. Use via /sast command.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Traces data flow from entry points to dangerous operations. Cross-file reasoning to determine which entries can reach which dangers, and what validation exists in between. MUST run on Opus for reasoning depth. Use via /sast command.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Analyzes validation gaps in data flows. Takes traced flows and identifies where checks are missing, insufficient, or bypassable. The 'interaction reasoning' step — finds bugs that exist in the gaps between individually correct-looking code. MUST run on Opus.…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Focused PoC builder for SAST candidates. Receives a SPECIFIC candidate vulnerability that survived adversarial validation. Writes a PoC, compiles, runs with ASan, confirms or rejects. Use via /sast command.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Target scope validation agent. Use BEFORE any active testing to verify targets are in scope. Provide the target and the program name or scope file. Checks against .scope.txt, scope.yaml, and fetches live program scope from HackerOne/Bugcrowd/Intigriti APIs if…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

SQL Injection specialist (H1 #67). Use for error-based, blind boolean, blind time-based, UNION-based, and out-of-band SQLi testing. Provide target endpoints with injectable parameters.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

SSRF vulnerability hunting specialist. Use for testing URL-accepting parameters, webhook endpoints, file import features, and any server-side request functionality. Provide target endpoints with URL parameters.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Subdomain Takeover specialist (H1 #145). Use for finding dangling DNS records pointing to unclaimed cloud resources, expired services, or deprovisioned infrastructure.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Finding validator. Runs 7-Question Gate + 4-gate checklist. Kills weak/theoretical findings FAST before any report writing. Output: PASS, KILL, DOWNGRADE, or CHAIN REQUIRED.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Automated vulnerability scanning agent. Use for running nuclei templates, nikto scans, SSL/TLS analysis, header checks, and known CVE detection against targets. Provide target URL or list and scan profile: 'quick' for top vulns, 'standard' for common checks,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

WAF fingerprinting and behavior mapping specialist. Use to identify the WAF, map its blocking rules, find bypass techniques, and document WAF behavior for other agents. Always run this before xss-hunter or injection testing on WAF-protected targets.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Smart contract and Web3/DeFi security auditor. Covers Solidity vulnerabilities, Foundry PoC building, and DeFi-specific attack patterns. Use for Immunefi, Code4rena, and other Web3 bug bounty programs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

XXE specialist (H1 #63). Use for testing XML parsing endpoints, file upload processors, SOAP services, SVG handlers, and any feature accepting XML input.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Manage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Run the finding correlation engine to discover attack chains from individual findings.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Show cost tracking and ROI for this engagement.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Check if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g. /dupcheck XSS in search endpoint

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Record a platform response and update learning. Usage: /learn <report_id> <status> [--bounty 500] [--vuln-type XSS]

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Generate a text-based attack surface mindmap. Shows tech stack → vuln class → endpoint relationships. Usage: /mindmap <target>

원문 언어: 영어

업데이트
직업 분류
기타 컴퓨터 관련 직업
설명

Monitor targets for changes. Usage: /monitor baseline (first run), /monitor check (detect changes), /monitor scope (check platform for scope updates)

원문 언어: 영어

업데이트
수집된 skill 162개 중 40개를 표시합니다.