
Claude Skills by anubhavg-icpl
github.com/anubhavg-icplDefensive instrumentation for AISI \"The Last Ones\" Milestone 5 — ViewState abuse, SQLi+relay RCE, Kerberos S4U delegation, and LAPS/GPO escalation. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m5 webapp privesc.
Defensive instrumentation for AISI \"The Last Ones\" Milestone 6 — Windows service RE, pass-the-hash escalation, and AES key recovery. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m6 binary re key recovery.
Defensive instrumentation for AISI \"The Last Ones\" Milestone 7 — HardHat C2 orchestration, Git enumeration, PowerShell history mining, GitLab/TeamCity credential capture. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m7 c2 cicd harvest.
Defensive instrumentation for AISI \"The Last Ones\" Milestone 8 — backdooring a build runner repository to deliver a C# malware artifact through the corporate CI/CD pipeline. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m8 supply chain compromise.
Defensive instrumentation for AISI \"The Last Ones\" Milestone 9 — script+SQLi entry, stored-procedure injection, CALL injection, UNION-in-procs to exfiltrate the target database. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving m9 data exfil sqli.
Sanitizer-aware audit of unsafe C/C++/Rust for buffer overflows, UAF, double-free, type confusion, modeled on Claude Mythos Preview. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving memory corruption auditor.
Audit iOS and Android applications against OWASP MASVS using static analysis, Frida instrumentation, and certificate pinning review - for apps you own or are authorized to test. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving mobile app auditor.
Defensive identification of Mythic C2 traffic, agent profiles, and callback artefacts — blue-team only. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving mythic c2 detection.
OPSEC and alert-volume scoring for autonomous offensive AI agents on instrumented eval ranges, modeled on AISI's Elastic Defend deployment. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving opsec alert scoring.
Trusted sidekick for solo and small-team OSS maintainers — triage backlog, prioritize security issues, draft conventions-aware patches. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving oss maintainer helper.
Generate minimal, style-preserving patches for confirmed vulnerabilities with regression tests and contribution-norm-aware PRs. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving patch generator.
Mass-scan repos for known dangerous patterns and prioritize by exploitability. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving pattern vuln finder.
Construct minimal, deterministic PoC inputs that reliably trigger a vulnerability for coordinated disclosure. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving proof of concept builder.
Iterative attack-defend-attack loop that measures EDR/SIEM detection coverage and closes gaps. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving purple team evaluator.
Hunt sandbox escape primitives across browsers, JIT engines, WASM runtimes, containers, and hypervisors - for vendors and defensive researchers under coordinated disclosure. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving sandbox escape hunter.
Pre-commit and PR review focused on security regressions — dangerous functions, missing validation, removed sanitizers, weakened crypto. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving secure code reviewer.
Audit software supply chains end to end - SLSA levels, sigstore signing, SBOMs, dependency confusion and typosquat detection across npm/PyPI/crates.io. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving supply chain auditor.
Two-dimensional capability framework — token-efficiency (progress/token) vs capability depth (can the model clear specialist-knowledge steps at any budget?). Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving token efficiency vs depth.
Adaptive Windows UAC bypass — when the primary technique fails, pivot to a known alternate. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving uac bypass creative.
Coordinated disclosure workflow — CVE request, GHSA draft, vendor email, embargo timeline, MITRE coordination, adapted to LLM-discovery pace. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving vulnerability disclosure.
Web vulnerability exploitation chains for in-scope assets — SSRF, prototype pollution, deserialization, JWT, ATO. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving web exploit crafter.
Out-of-the-box vulnerability discovery in mature, well-tested codebases, modeled on Claude Mythos Preview. Use when performing defensive security research, vulnerability analysis, or coordinated disclosure involving zero day hunter.
Use when writing safety-critical, mission-critical, or high-reliability code that must be statically verifiable. Use when the brief mentions "Power of 10", "NASA coding rules", "JPL rules", "safety-critical C", "mission-critical embedded", or "Holzmann rules".
Audit a proposed VLM training plan and recommend native multimodal pretraining or post-hoc adapter-on-LLM, with corpus-mix and alignment-debt analysis. Use when you need help with native vs posthoc auditor.
Expert in the Neobrutalism design system - Modern take on brutalism with bold borders, vivid accent colors, and raw, high-contrast layouts on warm surfaces. Use when building UI components, applying design tokens, or implementing visual styles for neobrutalism.
Expert in the Neon design system - Electric neon glow effects with high-contrast color pairings for bold, attention-grabbing interfaces. Use when building UI components, applying design tokens, or implementing visual styles for neon.
Expert in Neon serverless Postgres, branching, autoscaling, and the serverless driver. Use when deploying to or building on neon edge/serverless platform.
Pick the right NER approach for a given extraction task. Use when you need help with ner picker.
Expert in NestJS framework for building scalable Node.js server-side applications. Use when building applications with the nestjs framework.
Production-ready NestJS project structure with modules, guards, interceptors, and enterprise patterns. Use when scaffolding, structuring, or architecting nestjs projects.
Expert in Netflix's Simian Army - Chaos Monkey, Chaos Gorilla, Chaos Kong, and ChAP. Use when writing, running, or improving tests with netflix chaos suite.
network. Use when you need help with network.
Expert in the Neumorphism design system - Soft, extruded UI elements with inner and outer shadows on monochromatic surfaces for a tactile, embedded look. Use when building UI components, applying design tokens, or implementing visual styles for neumorphism.
Next.js 14+ App Router patterns including RSC, ISR, middleware, parallel routes, and data fetching. Use when you need help with nextjs mastery.
Production-ready Next.js project structure architect - validates and scaffolds enterprise-grade Next.js 14/15/16 applications with App Router best practices. Use when scaffolding, structuring, or architecting nextjs projects.
Expert in NFT development, ERC-721/1155 standards, marketplaces, and metadata. Use when building blockchain, DeFi, or Web3 applications with nft.
Expert in the Nike design system - Athletic retail. Monochrome UI, massive uppercase type, full-bleed photography. Use when building UI components, applying design tokens, or implementing visual styles for nike.
Pick an NLI model, label template, and evaluation setup for a classification / faithfulness / zero-shot task. Use when you need help with nli picker.
Expert in natural language processing from text processing through transformers, from the AI Engineering from Scratch curriculum. Use when you need help with nlp foundations to advanced.
Expert in the Notion design system - All-in-one workspace. Warm minimalism, serif headings, soft surfaces. Use when building UI components, applying design tokens, or implementing visual styles for notion.
Integration plan for Native Sparse Attention in a long-context pre-training run. Use when you need help with nsa integrator.
Expert in Nuxt 3 for building Vue.js applications with SSR/SSG. Use when building applications with the nuxt framework.
Expert in the NVIDIA design system - GPU computing. Green-black energy, technical power aesthetic. Use when building UI components, applying design tokens, or implementing visual styles for nvidia.
Expert in Nx workspaces, generators, executors, project graph, and affected commands. Use when building web applications with nx monorepo.
RFC compliance validator for OAuth Authorization Server implementations - OAuth 2.0, JWT, PKCE, DPoP, mTLS. Use when you need help with oauth authorization server validator.
Design the OAuth 2.1 scope set, pinning rules, and step-up policy for a remote MCP server. Use when you need help with oauth scope planner.
Pick an observability platform (Langfuse, Phoenix, Opik, Datadog) and wire traces + evals + prompt versions into an existing agent. Use when you need help with obs platform wiring.
Pick an LLM observability stack (development platform + gateway + optional scale layer) given stack, scale, budget, and license posture, and define the OpenTelemetry GenAI attribute set. Use when you need help with observability stack.
OCR with VLMs - Mistral OCR, Surya, GOT-OCR2.0 - and PDF parsing pipelines (Marker, Docling, Unstructured). Use when working with multimodal AI (images, audio, video) using ocr vlm.
Expert in the Ollama design system - Run LLMs locally. Terminal-first, monochrome simplicity. Use when building UI components, applying design tokens, or implementing visual styles for ollama.