
Claude Skills by oyi77
github.com/oyi77Use when this skill covers implementing secure remote access to OT/ICS
Use when this skill covers security hardening for serverless compute
Use when secure AI agents against prompt injection, jailbreaking, data
Automated smart contract vulnerability scanning and exploit development
Use when social engineering and phishing for authorized security assessments.
'Use when structured SRC bug bounty hunting for security response centers:
Use when software supply chain attack testing — dependency confusion,
'Use when tests Android inter-process communication (IPC) through intents
Use when tests API authentication mechanisms for weaknesses including
Use when tests REST and GraphQL APIs for Broken Object Level Authorization
Use when tests APIs for mass assignment (auto-binding) vulnerabilities
Use when systematically assessing REST and GraphQL API endpoints against
Use when identifying and exploiting Cross-Origin Resource Sharing misconfigurations
Use when systematically testing web applications for broken access control
Use when identifying flaws in application business logic that allow price
Use when test web application email functionality for SMTP header injection
Use when test web applications for HTTP Host header injection vulnerabilities
Use when test JWT implementations for critical vulnerabilities including
Use when identify and test open redirect vulnerabilities in web applications
Use when identifying sensitive data exposure vulnerabilities including
Use when test web applications for XML injection vulnerabilities including
Use when identifying and validating cross-site scripting vulnerabilities
Use when tests web applications for Cross-Site Scripting (XSS) vulnerabilities
Use when discovering and exploiting XML External Entity injection vulnerabilities
Use when assessing JSON Web Token implementations for cryptographic weaknesses,
Use when tests authentication and authorization mechanisms in mobile
Use when tests OAuth 2.0 and OpenID Connect implementations for security
Use when test and validate ransomware recovery procedures including backup
Use when tests WebSocket API implementations for security vulnerabilities
Use when investigate token and NFT scams including rug pulls, honeypot
Use when threat actor infrastructure tracking involves monitoring and
'Use when triages security alerts in Splunk Enterprise Security by classifying
Use when classify and prioritize security incidents using structured
Use when performs initial triage of security incidents to determine severity,
Use when triage and prioritize vulnerabilities using CISA's Stakeholder-Specific
Use when validating backup integrity through cryptographic hash verification,
Use when aI-powered vulnerability scanning with intelligent payload generation.
Use when profile and cluster blockchain wallet addresses to identify
Use when smart contract and DeFi security auditing for maximum bounty
Use when monetize bug bounty findings through writeups, tools, and consulting.
Use when apache Airflow workflow orchestration — DAGs, operators, sensors,
Use when full-stack data analysis pipeline — clean, detect anomalies,
Use when dagster data orchestration — software-defined assets, ops, jobs,
Use when dbt data transformation — models, tests, macros, sources, snapshots,
Use when prefect workflow orchestration — flows, tasks, deployments,
Use when apache Spark distributed processing — DataFrames, SQL, streaming,
Use when temporal durable workflows — workflow/activity definitions,
'Use when skill: agent-arena-skill. See SKILL.md body for details. Use
Use when generating daily plans with task priorities, tracking shipped
Use when aI-powered quality engineering with flaky test detection, mutation