All authors
26zl avatar

Claude Skills by 26zl

github.com/26zl
531 skillsA× 450B× 53C× 8D× 13F× 76 installs915 views
Performing Fuzzing With AflplusplusA

'Perform coverage-guided fuzzing of compiled binaries using AFL++ (American

securitygotesting
0
65
Performing Gcp Penetration Testing With GcpbucketbruteA

Perform GCP security testing using GCPBucketBrute for storage bucket

securitypythongo
0
65
Performing Graphql Introspection AttackA

'Performs GraphQL introspection attacks to extract the full API schema

securitypythongo
0
65
Performing Hardware Security Module IntegrationA

Integrate Hardware Security Modules (HSMs) using PKCS#11 interface for

securitypythongo
0
65
Performing Hash Cracking With HashcatB

Hash cracking is an essential skill for penetration testers and security

securitypythontesting
0
65
Performing Http Parameter Pollution AttackA

Execute HTTP Parameter Pollution attacks to bypass input validation,

securitypythonrust
0
65
Performing Ics Asset Discovery With ClarotyA

'Perform comprehensive ICS/OT asset discovery using Claroty xDome platform,

securitypythongo
0
65
Performing Indicator Lifecycle ManagementA

Indicator lifecycle management tracks IOCs from initial discovery through

securitypythonrust
0
65
Performing Initial Access With Evilginx3A

Perform authorized initial access using EvilGinx3 adversary-in-the-middle

securitypythongo
0
65
Performing Insider Threat InvestigationA

'Investigates insider threat incidents involving employees, contractors,

securityrustgo
0
65
Performing Jwt None Algorithm AttackA

Execute and test the JWT none algorithm attack to bypass signature verification

securitypythongo
0
65
Performing Kerberoasting AttackA

Kerberoasting is a post-exploitation technique that targets service accounts

securitypythonshell
0
65
Sap Erp Security AssessmentA

Use for SAP and ERP security assessments, S/4HANA, NetWeaver, ABAP, HANA DB, RFC trust, SAP Gateway, ICM, transports, default users, authorization roles, SoD, patching, and business-critical ERP control review.

ai-agentsrustrails
0
65
Semgrep Rule CreatorA

Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static analysis detections.

ai-agentspythonrust
0
65
Add ToolA

Use when adding a new cybersecurity tool to this installer. Walks through editing the right module file, adding to tools_config.json, running validators, and syncing MCP server data if needed. Triggers on phrases like "add tool", "add <toolname>", "register a new tool", "include X in the installer".

ai-agentspythongo
0
65
Ai Llm Security ReviewA

Use for AI/LLM security assessments, prompt injection, RAG security, agent/tool permissioning, model supply chain, LLM red teaming, AI governance, eval design, data leakage, jailbreak testing, and secure AI application review.

ai-agentsrustgo
0
65
Ai Threat TestingA

Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.

securitytestingdebugging
0
65
Analyzing Android Malware With ApktoolA

Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source

ai-agentspythonjava
0
65
Analyzing Cobalt Strike Beacon ConfigurationA

Extract and analyze Cobalt Strike beacon configuration from PE files and memory dumps to identify C2 infrastructure,

securitypythonshell
0
65
Analyzing Disk Image With AutopsyA

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and

ai-agentsgojava
0
65
Analyzing Email Headers For Phishing InvestigationC

Parse and analyze email headers to trace the origin of phishing emails, verify sender authenticity, and identify

ai-agentsjavascriptpython
0
65
Analyzing Ethereum Smart Contract VulnerabilitiesA

Perform static and symbolic analysis of Solidity smart contracts using Slither and Mythril to detect reentrancy,

securitypythonsecurity
0
65
Analyzing Ios App Security With ObjectionA

'Performs runtime mobile security exploration of iOS applications using Objection, a Frida-powered toolkit that

securityjavascriptpython
0
65
Analyzing Macro Malware In Office DocumentsA

'Analyzes malicious VBA macros embedded in Microsoft Office documents (Word, Excel, PowerPoint) to identify download

ai-agentspythongo
0
65
Analyzing Malicious Pdf With PeepdfA

Perform static analysis of malicious PDF documents using peepdf, pdfid, and pdf-parser to extract embedded JavaScript,

ai-agentsjavascriptpython
0
65
Analyzing Mft For Deleted File RecoveryA

Analyze the NTFS Master File Table ($MFT) to recover metadata and content of deleted files by examining MFT record

ai-agentspythonshell
0
65
Analyzing Network Packets With ScapyA

Craft, send, sniff, and dissect network packets using Scapy for protocol analysis, network reconnaissance, and

ai-agentspythontesting
0
65
Analyzing Network Traffic With WiresharkA

'Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns,

ai-agentsbashsecurity
0
65
Blockchain SecurityA

Smart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testing smart contract security.

ai-agentspythonbash
0
65
Bounty ApiA

Use when bug-bountying an API target — REST, GraphQL, gRPC, WebSocket. Covers OWASP API Top 10 (BOLA, BFLA, mass assignment, rate limiting bypass, JWT issues, GraphQL abuse). Triggers on "bounty api", "graphql security", "rest api testing", "api top 10".

securityrustgo
0
65
Bounty MobileA

Use when bug-bountying an Android (APK) or iOS (IPA) app. Covers static + dynamic analysis, Frida hooking, certificate pinning bypass, deep link / intent abuse, IPC, secrets in bundles. Triggers on "bounty mobile", "android app", "ios app", "apk analysis", "frida".

ai-agentsjavascriptrust
0
65
Bounty ReconA

Use at the start of a bug bounty engagement. Provides scope-aware recon methodology — passive enumeration, subdomain discovery, asset attribution, tech stack fingerprinting, content discovery. Respects scope and program rules. Triggers on "bounty recon", "subdomain enum", "attack surface map", "h1 recon", "bug bounty start".

ai-agentsgobash
0
65
Bounty WebB

Use during the testing phase of a web application bug bounty. Provides OWASP-aligned attack catalog, payload sources, and tool ordering for SQLi, XSS, SSRF, SSTI, IDOR, auth, race conditions, file upload, deserialization. Triggers on "bounty web", "test this app", "web app testing", "h1 web target".

securitypythongo
0
65
Building C2 Infrastructure With Sliver FrameworkB

Build and configure a resilient command-and-control infrastructure using BishopFox's Sliver C2 framework with

securitypythongo
0
65
Building Detection Rules With SigmaA

'Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms

ai-agentspythongo
0
65
Building Red Team C2 Infrastructure With HavocA

Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners,

ai-agentspythonrust
0
65
Building Role Mining For Rbac OptimizationA

Apply bottom-up and top-down role mining techniques to discover optimal

ai-agentspythongo
0
65
Building Soc Escalation MatrixA

Build a structured SOC escalation matrix defining severity tiers, response

securitypythontesting
0
65
Building Soc Playbook For RansomwareA

'Builds a structured SOC incident response playbook for ransomware attacks

securityrustgo
0
65
Building Threat Actor Profile From OsintA

Build comprehensive threat actor profiles using open-source intelligence

ai-agentspythonrust
0
65
Building Threat Feed Aggregation With MispA

Deploy MISP (Malware Information Sharing Platform) to aggregate, correlate,

securitypythongo
0
65
Building Threat Hunt Hypothesis FrameworkA

Build a systematic threat hunt hypothesis framework that transforms threat

ai-agentssecurity
0
65
Building Threat Intelligence Enrichment In SplunkA

Build automated threat intelligence enrichment pipelines in Splunk Enterprise

ai-agentspythonrust
0
65
Building Threat Intelligence PlatformA

Building a Threat Intelligence Platform (TIP) involves deploying and

ai-agentspythonrust
0
65
Building Vulnerability Aging And Sla TrackingA

Implement a vulnerability aging dashboard and SLA tracking system to

securitypythonsecurity
0
65
Building Vulnerability Dashboard With DefectdojoA

Deploy DefectDojo as a centralized vulnerability management dashboard

securitypythongo
0
65
Building Vulnerability Exception Tracking SystemA

Build a vulnerability exception and risk acceptance tracking system with

securitypythonrust
0
65
CodeqlA

Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "codeql analysis", "build codeql database", or "find vulnerabilities with codeql". Supports "run all" (security-and-quality + security-experimental suites) and "important only" (high-precision security findings) scan modes. Also handles creating data extension models and processing CodeQL SARIF output.

ai-agentsjavascripttypescript
0
65
Collecting Threat Intelligence With MispA

MISP (Malware Information Sharing Platform) is an open-source threat

securitypythongo
0
65
Collecting Volatile Evidence From Compromised HostB

Collect volatile forensic evidence from a compromised system following

ai-agentsrustgo
0
65