All authors

Claude Skills by H-mmer
github.com/H-mmer182 skills2 installs158 views
- Agent Sast Danger MapperMaps dangerous operations in a source file: memory ops, type casts, arithmetic near trust boundaries, free/dealloc patterns. Pattern matching task — list what you see, don't speculate. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Devils AdvocateAdversarial validator for SAST findings. Your ONLY job is to DISPROVE the candidate. Find every reason it's not exploitable. If you can't disprove it, it survives. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Entry MapperMaps entry points where untrusted data enters a source file. Lists every function that receives external input with data type, size constraints, and initial validation. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Exploit BuilderBuilds working exploits from confirmed SAST findings. Takes a confirmed crash, develops it into a full exploit. Tier 1 (DoS) → Tier 5 (code execution). Use via /sast command after PoC confirmation.Votes: 0GitHub stars: 815
- Agent Sast File RankerSource file attack surface ranker. Reads a repository, scores every source file 1-5 by exploitability. Outputs ranked JSON for per-file hunting. Use via /sast command.Votes: 0GitHub stars: 815
- Agent Sast Flow TracerTraces data flow from entry points to dangerous operations. Cross-file reasoning to determine which entries can reach which dangers, and what validation exists in between. MUST run on Opus for reasoning depth. Use via /sast command.Votes: 0GitHub stars: 815
- Cmd AnalyzeAnalyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>Votes: 0GitHub stars: 815
- Cmd AutopilotAutonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying questions, no auxiliary-agent substitution. Usage: /autopilot target.com [--interactive|--autonomous] [--20m-off] [--resume]Votes: 0GitHub stars: 815
- Cmd BrainManage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.Votes: 0GitHub stars: 815
- Cmd ChainBuild deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)Votes: 0GitHub stars: 815
- Cmd CorrelateRun the finding correlation engine to discover attack chains from individual findings.Votes: 0GitHub stars: 815
- Cmd CostShow cost tracking and ROI for this engagement.Votes: 0GitHub stars: 815
- Cmd DupcheckCheck if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g. /dupcheck XSS in search endpointVotes: 0GitHub stars: 815
- Cmd FullscanFull security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.Votes: 0GitHub stars: 815
- Cmd HuntActive vulnerability hunting on a target. Loads scope, reads brain, detects tech stack, runs targeted tests with concrete payloads. Usage: /hunt target.com [--vuln-class idor|xss|ssrf|sqli|ssti|oauth|rce|race|graphql|upload|business-logic|llm-ai]Votes: 0GitHub stars: 815
- Cmd LearnRecord a platform response and update learning. Usage: /learn <report_id> <status> [--bounty 500] [--vuln-type XSS]Votes: 0GitHub stars: 815
- Cmd MindmapGenerate a text-based attack surface mindmap. Shows tech stack → vuln class → endpoint relationships. Usage: /mindmap <target>Votes: 0GitHub stars: 815
- Cmd MonitorMonitor targets for changes. Usage: /monitor baseline (first run), /monitor check (detect changes), /monitor scope (check platform for scope updates)Votes: 0GitHub stars: 815
- Cmd NewCreate a new engagement workspace. Usage: /new <platform> <program> [--type web-app|api|mobile|smart-contract]Votes: 0GitHub stars: 815
- Cmd PipelinePrepare the battlefield — recon, scanning, and surface ranking. Stops before hunting. Run /hunt or /autopilot after. Usage: /pipeline or /pipeline <target>Votes: 0GitHub stars: 815
- Cmd QualityScore a report draft before submission. Usage: /quality <draft-path-or-finding-description>Votes: 0GitHub stars: 815
- Cmd QuickscanRun a quick security scan on a target. Consults the Brain first, validates scope, runs passive recon + vuln scan in parallel.Votes: 0GitHub stars: 815
- Cmd RememberLog a finding or pattern to persistent brain memory. Auto-fills from session context. Usage: /rememberVotes: 0GitHub stars: 815
- Cmd ReportGenerate submission-ready reports for all confirmed findings. Runs dedup, PoC builder, quality check, and report writer. Usage: /report bounty or /report pentestVotes: 0GitHub stars: 815
- Cmd ResumeResume a previous hunt. Shows hunt history, untested endpoints, memory-informed suggestions. Usage: /resume target.comVotes: 0GitHub stars: 815
- Cmd SastSource code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: /sast <repo_path> [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30] [--skip-static] [--best-of N]Votes: 0GitHub stars: 815
- Cmd StatusShow engagement dashboard with program info, scope, brain state, findings, agent activity, and cost estimate.Votes: 0GitHub stars: 815
- Cmd SubmitDraft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review.Votes: 0GitHub stars: 815
- Cmd SurfaceShow ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.comVotes: 0GitHub stars: 815
- Cmd SyncSync program scope, policy, and hacktivity from a bug bounty platform. Usage: /sync hackerone tesla or /sync bugcrowd uberVotes: 0GitHub stars: 815
- Cmd TriageBatch-validate ALL findings through the 7-Question Gate. Kills weak findings in bulk. Usage: /triageVotes: 0GitHub stars: 815
- Cmd ValidateValidate a finding through the 7-Question Gate + 4 gates. Kills weak findings FAST. Usage: /validate <finding description>Votes: 0GitHub stars: 815