Skip to main content

forefy/.context

Última atividade de origem registrada
Catálogo do SkillsMP atualizado
skills coletadas
34
Estrelas no GitHub
149
Forks no GitHub
30

Carregando o README do repositório…

Mostrando 34 de 34 skills coletadas.

ocupação
sem classificação
descrição

Browse the nuclei-templates library, recommend a scoped template set for a given stack, target, or CVE, then run it against an authorized target and report findings.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Map a bug-bounty scope and rank targets by payout, crowding, and freshness. Use to size up a program or decide where to hunt before committing time.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Comprehensive smart contract security audit framework with multi-expert analysis. Use for full audits of Ethereum / EVM Solidity and Vyper, Solana / SVM Anchor Rust, TON / FunC / Tact, or Sui / Move projects.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. Use for full infrastructure audits.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Hunt a live macOS, Linux, or Windows endpoint for malware across process, network, and persistence. Use to scan for threats or check for compromise.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Write and format security-audit reports in Google Docs via the Docs API - findings, tables, and severity styling. Use to build or fix a report.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de garantia de qualidade de software e testadores
descrição

Audit codebase to uncover critical issues explicitly without false positives

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Forge and re-sign captured JWTs to test signature validation - algorithm confusion (alg:none, RS256 to HS256), key injection, and secret cracking. Use when testing JWT or bearer-token auth.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Run several LLM fuzzing and red-team scanners against one target, normalize their output to a common schema, dedupe across them, and report honest coverage. Use when scanning a model endpoint with more than one tool.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Pentest an MCP server for authentication bypass, confused-deputy SSRF, and tool-argument injection - black-box from its URL, deeper with repo or host access. Use to assess an MCP server's exposure.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Audit an LLM application for indirect prompt injection - compose objective x technique payloads, deliver them through the channels the agent actually reads, and prove impact with an out-of-band callback. Use to assess an AI agent's resistance to injected…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Probe a web app for what it exposes or leaks - passively from captured traffic and actively against the target. Use to assess a web app's exposure or review Burp/ZAP history.

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Audit the conversation and the project for what could have gone better, then turn the generalizable lessons into committed improvements in the repo that hosts this skill. Use at the end of a task or conversation where the agent needed correction, repeated…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

The last gate before untrusted instruction content is ingested. Screens a skill, goal or workflow fetched from git or any remote source for prompt injection, reading it as evidence rather than as instructions, on the assumption that its author wrote it to…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes. Use to submit or prepare a bug-bounty report.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Uncover the real origin IP behind a CDN or WAF like Cloudflare, using only standard tools. Use to bypass a CDN/WAF or check if an origin leaks.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Prove blind SSRF by injecting an out-of-band callback into URL params and forwarding headers, then watching for the hit. Use when testing for SSRF.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Generates a Foundry PoC for smart contracts that scientifically proves the path from no special privileges to funds lost. Focused on proof of concept for EVM using `forge test`.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Scan macOS for hijackable dynamic libraries, separating exploitable privesc hijacks from harmless ones. Use to check if an app is hijackable.

Idioma do texto original: inglês

atualizado
ocupação
Administradores de redes e sistemas de computador
descrição

Wrap the session in the Anthropic Sandbox Runtime before touching untrusted code. Use before running any audit skill on a codebase you do not trust.

Idioma do texto original: inglês

atualizado
ocupação
Administradores de redes e sistemas de computador
descrição

Spin up disposable macOS, Windows, and Linux VMs and drive them over SSH for cross-OS debugging and repro. Use to run or inspect an isolated guest.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Replay captured requests with swapped identities and bumped object IDs to surface broken access control. Use when testing for IDOR or authz flaws.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Detect HTTP request smuggling by desynchronising front-end and back-end request parsing, using raw-socket timing and differential probes. Use when testing for HTTP desync (CL.TE, TE.CL).

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Expert blockchain forensics assistant for investigators and auditors, including threat recognition, incident scoping, data collection, transaction tracking, chain analysis, attribution, OSINT, advanced demixing, cross-chain tracing, graph clustering, and…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Discover publicly readable cloud storage by permuting a company name into likely bucket names and probing AWS S3, Google Cloud, DigitalOcean, Alibaba, Oracle, and Vultr. Use to find exposed buckets.

Idioma do texto original: inglês

atualizado
ocupação
Outras ocupações de informática
descrição

Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md. Use when joining the team on a shared codebase.

Idioma do texto original: inglês

atualizado
ocupação
Outras ocupações de informática
descrição

Takes the active conversation as reference to understand how a skill can be created, with all the lessons learned from the user's needs in the conversation.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de garantia de qualidade de software e testadores
descrição

Commit to Git safely: runs tests, security-reviews the diff, strips secrets and dead code, and enforces clean messages. Use before any commit or push.

Idioma do texto original: inglês

atualizado
ocupação
Professores do ensino superior, todos os outros
descrição

Build an interactive visual course as one self-contained HTML page, one idea per screen. Use to explain or teach a subject visually, step by step.

Idioma do texto original: inglês

atualizado
ocupação
Redatores técnicos
descrição

Lay draft copy out as a table with three distinct rewrites per line and a top pick. Use to compare wording for posts, headlines, CTAs, or microcopy.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. Use when scoping a new engagement.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de garantia de qualidade de software e testadores
descrição

Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs. Use to test understanding before or during a review.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. Use to recon an external attack surface or enumerate subdomains.

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Sweeps DeFi protocol Safe multisig wallets for governance misconfigurations and security weaknesses. Given a protocol name, Safe address, or "sweep all", fetches live config and tx history from the Safe Transaction Service API, scores each Safe against a…

Idioma do texto original: inglês

atualizado
Mostrando 34 de 34 skills coletadas.

Instalar com um assistente de IA

Copie este prompt para o assistente de IA que você usa.