
Claude Skills by MustafaKemal0146
github.com/MustafaKemal0146Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.
Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.
Generate XSS payloads and test strategies for authorized web application security testing. Context-aware payload generation.
tespit etme (s) and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception. Uses Ubertooth One and nRF52840
Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and Tespit etme vulnerabilities
Configure AWS Verified Erişim: provide VPN-less zero trust network Erişim: internal applications using identity and device posture verification with Cedar policy language.
Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware
Configure microsegmentation policies to enforce least-privilege workload-to-workload access using tools like VMware NSX, Illumio, and Calico, preventing lateral movement in zero trust architectures.
Configuring Zscaler Private Access (ZPA) to replace traditional VPN with zero trust network access by Dağıt:ing App Connectors, defining application segments, configuring access policies based
Dağıt:ing Cloudflare Access with Cloudflare Tunnel to provide zero trust Erişim: self-hosted and private applications, configuring identity-aware access policies, device posture checks, and
Dağıt:ing Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud
Dağıt: a Software-Defined Perimeter using the CSA v2.0 specification with Single Packet Authorization, mutual TLS, and SDP controller/gateway configuration to enforce zero trust network access.
Dağıt: and configure Tailscale as a WireGuard-based zero trust mesh VPN with identity-aware access controls, ACLs, and exit nodes for secure peer-to-peer connectivity.
Implementing Google's BeyondCorp zero trust access model to eliminate implicit trust from the network perimeter, enforce identity-aware access controls using IAP, Access Context Manager, and
Implement the CISA Zero Trust Maturity Model v2.0 across the five pillars of identity, devices, networks, applications, and data to achieve progressive organizational zero trust maturity.
Implementing device posture assessment as a zero trust access control by integrating endpoint health signals from CrowdStrike ZTA, Microsoft Intune, and Jamf into conditional access policies
Implement continuous identity verification for zero trust using phishing-resistant MFA (FIDO2/WebAuthn), risk-based conditional access, and identity governance aligned with the CISA Zero Trust
Implementing microsegmentation using Akamai Guardicore Segmentation to map application dependencies, create granular network policies, visualize east-west traffic flows, and enforce least-privilege
Implement NextDNS as a zero trust DNS filtering layer with encrypted resolution, threat intelligence blocking, privacy protection, and organizational policy enforcement across all endpoints.
Implementing zero trust access controls for SaaS applications using CASB, SSPM, conditional access policies, OAuth app governance, and session controls to enforce identity verification, device
Implement Zero Trust Network Access using Zscaler Private Access (ZPA) to replace traditional VPN with identity-based, context-aware Erişim: private applications through the Zscaler Zero
Dağıt: Google BeyondCorp Enterprise zero trust access controls using Identity-Aware Proxy (IAP), context-aware access policies, device trust validation, and Access Context Manager to enforce
Implement HashiCorp Boundary for identity-aware zero trust infrastructure access management with dynamic credential brokering, session recording, and Vault integration.
Iterative Python via live Jupyter kernel (hamelnb).
Decomposition playbook + anti-temptation rules for an orchestrator profile routing work through Kanban. The "don't do the work yourself" rule and the basic lifecycle are auto-injected into every kanban worker's system prompt; this skill is the deeper playbook when you're specifically playing the orchestrator role.
Pitfalls, examples, and edge cases for FETIH Kanban workers. The lifecycle itself is auto-injected into every worker's system prompt as KANBAN_GUIDANCE (from agent/prompt_builder.py); this skill is what you load when you want deeper detail on specific scenarios.
Webhook subscriptions: event-driven agent runs.
Exploratory QA of web apps: find bugs, evidence, reports.
Himalaya CLI: IMAP/SMTP email from terminal.
Host modded Minecraft servers (CurseForge, Modrinth).
Play Pokemon via headless emulator + RAM reads.
Inspect codebases w/ pygount: LOC, languages, ratios.
GitHub auth setup: HTTPS tokens, SSH keys, gh CLI login.
Review PRs: diffs, inline comments via gh or REST.
Create, triage, label, assign GitHub issues via gh or REST.
GitHub PR lifecycle: branch, commit, open, CI, merge.
Clone/create/fork repos; manage remotes, releases.
MCP client: connect servers, register tools (stdio/HTTP).
Search/download GIFs from Tenor via curl + jq.
HeartMuLa: Suno-like song generation from lyrics + tags.
Audio spectrograms/features (mel, chroma, MFCC) via CLI.
Spotify: play, search, queue, manage playlists and devices.
YouTube transcripts to summaries, threads, blogs.
lm-eval-harness: benchmark LLMs (MMLU, GSM8K, etc.).
W&B: log ML experiments, sweeps, model registry, dashboards.
HuggingFace hf CLI: search/download/upload models, datasets.
llama.cpp local GGUF inference + HF Hub model discovery.
OBLITERATUS: abliterate LLM refusals (diff-in-means).
vLLM: high-throughput LLM serving, OpenAI API, quantization.
SAM: zero-shot image segmentation via points, boxes, masks.