
Claude Skills by costrict-plugins-repo
github.com/costrict-plugins-repoDetect and exploit blind Server-Side Request Forgery (SSRF) using out-of-band
Assess Bluetooth Low Energy (BLE) device security using Python's bleak asyncio
Monitor for brand impersonation attacks across domains, social media,
Testing web applications for clickjacking vulnerabilities by assessing
Run Cartography to sync AWS, GCP, or Azure resources into a Neo4j graph database,
Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud
Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents
Execute cloud-native incident containment across AWS, Azure, and GCP using platform
'Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs,
'Uses Falco YAML rules for runtime threat detection in containers and
Investigate AWS security incidents using Amazon Detective's behavior graphs,
'Run authorized AWS penetration tests with Pacu, the open-source AWS exploitation
Perform forensic acquisition of cloud storage services including Google
Audits container and pod configuration for escape-enabling misconfiguration using the Kubernetes Python client - privileged flags, dangerous capability grants, host path mounts, shared namespaces, and CVE-2022-0492 style cgroup abuse. Use when sweeping a cluster for workloads that could break out, producing a posture report, or checking configuration before enforcement is switched on. Keywords: privileged, hostPath, hostPID, capabilities, CVE-2022-0492, cgroup, kubernetes python client, postu...
'Harden container images by minimizing attack surface, stripping unnecessary
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed secrets, and licences, generating CycloneDX or SPDX SBOMs. Use when integrating Trivy into CI/CD, deploying the Trivy Kubernetes operator, scanning non-image targets, or triaging results at scale. Keywords: Trivy, trivy k8s, operator, SBOM, CycloneDX, SPDX, misconfig, secret scanning. Do not use for a ...
Analyze Content-Security-Policy headers and bypass them to achieve cross-site
Extract stored credentials from compromised endpoints using the LaZagne
A cryptographic audit systematically reviews an application's use of
Testing web applications for Cross-Site Request Forgery vulnerabilities
Fetch and parse the CISA Known Exploited Vulnerabilities (KEV) catalog,
Dark web monitoring involves systematically scanning Tor hidden services,
'Deploys deception technology including honeypots, honeytokens, and decoy
Test web applications for path traversal and Local/Remote File Inclusion
'Conduct disk forensics investigations using forensic imaging, file system
Execute a phased DMARC rollout by inventorying sending sources, configuring
'Enumerates DNS records, attempts zone transfers, brute-forces subdomains,
'Detects DNS tunneling by computing Shannon entropy of DNS query names,
Runs Docker Bench for Security, the open-source CIS Docker Benchmark audit script, across host configuration, daemon settings, images, and runtime configuration, then interprets pass/fail/warn output and remediates the common failures. Use when auditing Docker hosts for CIS compliance, scheduling recurring container assessments, or validating runtime hardening controls after a change. Keywords: docker-bench-security, CIS Docker Benchmark, audit script, pass fail warn, host configuration, reme...
'Performs runtime dynamic analysis of Android applications using Frida,
'Perform interactive dynamic malware analysis using the ANY.RUN cloud sandbox
'Performs digital forensics investigation on compromised endpoints including
'Performs vulnerability remediation on endpoints by prioritizing CVEs
'Runs entitlement review and access certification campaigns in SailPoint
Conduct a comprehensive external network penetration test to identify
Reduces SIEM false positives through systematic rule tuning, threshold
Recovers files from disk images and unallocated space using Foremost's
'Performs firmware image extraction and analysis using binwalk to identify
'Analyzes firmware images for embedded malware, backdoors, and unauthorized
'Performs coverage-guided fuzzing of compiled binaries with AFL++, instrumenting
Performs authorized GCP security testing using GCPBucketBrute to enumerate
'Performing comprehensive security assessments of Google Cloud Platform
Execute and test GraphQL depth limit attacks using deeply nested recursive
'Performs GraphQL introspection attacks that extract the full API schema
Assessing GraphQL API endpoints for introspection leaks, injection attacks,
Integrates Hardware Security Modules (HSMs) via the PKCS#11 interface
Cracks password hashes with Hashcat, covering hash-type identification,
Executes HTTP Parameter Pollution attacks that inject duplicate request
'Performs ICS/OT asset discovery with Claroty xDome, combining passive
Tracks IOCs through discovery, enrichment/validation (VirusTotal, Shodan,