All authors

Claude Skills by plurigrid
github.com/plurigrid2,535 skills6 installs3,507 views
- Exploiting Insecure Data Storage In MobileIdentifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences, plaintext credential storage, and improper keychain/keystore usage. Use when performing mobile penetration testing focused on OWASP M9 (Insecure Data Storage) or assessing compliance with MASVS-STORAGE requirements. Activates for requests involving mobile data storage security, local storage exploitation, ...Votes: 0GitHub stars: 61
- Exploiting Insecure DeserializationIdentifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.Votes: 0GitHub stars: 61
- Exploiting Ipv6 VulnerabilitiesIdentifies and exploits IPv6-specific vulnerabilities including SLAAC spoofing, Router Advertisement flooding, and IPv6 tunneling during authorized assessments to test dual-stack security controls and IPv6-aware network defenses.Votes: 0GitHub stars: 61
- Exploiting Jwt Algorithm Confusion AttackExploits JWT algorithm confusion vulnerabilities where the server's token verification library accepts the algorithm specified in the JWT header rather than enforcing a fixed algorithm. The tester manipulates the alg header to switch from RS256 to HS256 (using the RSA public key as the HMAC secret), sets alg to none to bypass signature verification, or exploits kid/jku/x5u header injection to supply attacker-controlled keys. Activates for requests involving JWT algorithm confusion, alg none a...Votes: 0GitHub stars: 61
- Exploiting Kerberoasting With ImpacketPerform Kerberoasting attacks using Impacket's GetUserSPNs to extract and crack Kerberos TGS tickets for Active Directory service accounts.Votes: 0GitHub stars: 61
- Exploiting Mass Assignment In Rest ApisDiscover and exploit mass assignment vulnerabilities in REST APIs to escalate privileges, modify restricted fields, and bypass authorization controls by injecting unexpected parameters in API requests.Votes: 0GitHub stars: 61
- Exploiting Ms17 010 Eternalblue VulnerabilityMS17-010 (EternalBlue) is a critical vulnerability in Microsoft's SMBv1 implementation that allows remote code execution. Originally discovered by the NSA and leaked by the Shadow Brokers in 2017, itVotes: 0GitHub stars: 61
- Exploiting Nopac Cve 2021 42278 42287Exploit the noPac vulnerability chain (CVE-2021-42278 sAMAccountName spoofing and CVE-2021-42287 KDC PAC confusion) to escalate from standard domain user to Domain Admin in Active Directory environments.Votes: 0GitHub stars: 61
- Exploiting Nosql Injection VulnerabilitiesDetect and exploit NoSQL injection vulnerabilities in MongoDB, CouchDB, and other NoSQL databases to demonstrate authentication bypass, data extraction, and unauthorized access risks.Votes: 0GitHub stars: 61
- Exploiting Oauth MisconfigurationIdentifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.Votes: 0GitHub stars: 61
- Exploiting Prototype Pollution In JavascriptDetect and exploit JavaScript prototype pollution vulnerabilities on both client-side and server-side applications to achieve XSS, RCE, and authentication bypass through property injection.Votes: 0GitHub stars: 61
- Exploiting Race Condition VulnerabilitiesDetect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.Votes: 0GitHub stars: 61
- Exploiting Server Side Request ForgeryIdentifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.Votes: 0GitHub stars: 61
- Exploiting Smb Vulnerabilities With MetasploitIdentifies and exploits SMB protocol vulnerabilities using Metasploit Framework during authorized penetration tests to demonstrate risks from unpatched Windows systems, misconfigured shares, and weak authentication in enterprise networks.Votes: 0GitHub stars: 61
- Exploiting Sql Injection VulnerabilitiesIdentifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. The tester detects injection points through error-based, union-based, blind boolean, and time-based blind techniques across all major database engines (MySQL, PostgreSQL, MSSQL, Oracle) to demonstrate data extraction, authentication bypass, and potential remote code execution. Activates for requests involving SQL injection testi...Votes: 0GitHub stars: 61
- Exploiting Sql Injection With SqlmapDetecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.Votes: 0GitHub stars: 61
- Exploiting Template Injection VulnerabilitiesDetecting and exploiting Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution.Votes: 0GitHub stars: 61
- Exploiting Type Juggling VulnerabilitiesExploit PHP type juggling vulnerabilities caused by loose comparison operators to bypass authentication, circumvent hash verification, and manipulate application logic through type coercion attacks.Votes: 0GitHub stars: 61
- Exploiting Vulnerabilities With Metasploit FrameworkThe Metasploit Framework is the world's most widely used penetration testing platform, maintained by Rapid7. It contains over 2,300 exploits, 1,200 auxiliary modules, and 400 post-exploitation modulesVotes: 0GitHub stars: 61
- Exploiting Websocket VulnerabilitiesTesting WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.Votes: 0GitHub stars: 61
- Exploiting Zerologon Vulnerability Cve 2020 1472Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.Votes: 0GitHub stars: 61
- ExternalExternal skill interface for integration with external systemsVotes: 0GitHub stars: 61
- Extracting Browser History ArtifactsExtract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.Votes: 0GitHub stars: 61
- Extracting Config From Agent Tesla RatExtract embedded configuration from Agent Tesla RAT samples including SMTP/FTP/Telegram exfiltration credentials, keylogger settings, and C2 endpoints using .NET decompilation and memory analysis.Votes: 0GitHub stars: 61
- Extracting Credentials From Memory DumpExtract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using Volatility and Mimikatz for forensic investigation.Votes: 0GitHub stars: 61
- Extracting Iocs From Malware SamplesExtracts indicators of compromise (IOCs) from malware samples including file hashes, network indicators (IPs, domains, URLs), host artifacts (file paths, registry keys, mutexes), and behavioral patterns for threat intelligence sharing and detection rule creation. Activates for requests involving IOC extraction, threat indicator harvesting, malware indicator collection, or building detection content from samples.Votes: 0GitHub stars: 61
- Extracting Memory Artifacts With RekallUses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. Applies plugins like pslist, psscan, vadinfo, malfind, and dlllist to extract forensic artifacts from Windows memory images. Use during incident response memory analysis.Votes: 0GitHub stars: 61
- Extracting Windows Event Logs ArtifactsExtract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.Votes: 0GitHub stars: 61
- Fasttime McpMaximum velocity MCP execution via geodesic untangling. Maoist self-criticism for why slowtime was ever necessary. Topological cybernetic feedback for ongoing tour discovery.Votes: 0GitHub stars: 61
- Ffmpeg MediaFFmpeg media processing. Video/audio transcoding, stream manipulation, and filter graphs.Votes: 0GitHub stars: 61
- FfmpegMedia processing (10 man pages).Votes: 0GitHub stars: 61
- File OrganizerIntelligently organizes your files and folders across your computer byVotes: 0GitHub stars: 61
- Finder Color WalkFinder Color Walk SkillVotes: 0GitHub stars: 61
- Fix ReviewReview security fixes and patches for completeness and correctness.Votes: 0GitHub stars: 61
- Flix DatalogFlix-based Datalog reasoning with lattice semantics and GF(3) coloring. Use for declarative rule-based routing, lattice fixed-point computation, and skill composition with derangement properties.Votes: 0GitHub stars: 61
- FlowOne-parameter group of diffeomorphisms generated by vector fieldVotes: 0GitHub stars: 61
- Flowglad IntegrationZero-webhook billing for AI agentsVotes: 0GitHub stars: 61
- Flox McpMCP server wrapper for flox CLI operations - environment management via JSON-RPCVotes: 0GitHub stars: 61
- FloxReproducible development environments powered by Nix.Votes: 0GitHub stars: 61
- Fnox Secretsfnox Secrets Management SkillVotes: 0GitHub stars: 61
- Fokker Planck AnalyzerLayer 5: Convergence to Equilibrium AnalysisVotes: 0GitHub stars: 61
- ForesterJon Sterling's forester tool for tending mathematical forests — syntax, escaping, verbatim, tree files, skill2tree conversionVotes: 0GitHub stars: 61
- Forward Forward LearningHinton's Forward-Forward algorithm for local learning without backpropagation.Votes: 0GitHub stars: 61
- Frontend DesignCreate distinctive, production-grade frontend interfaces with high designVotes: 0GitHub stars: 61
- Frustration EradicationFrustration Eradication SkillVotes: 0GitHub stars: 61
- Fswatch DuckdbFileSystemWatcher over /tmp with DuckDB/DuckLake persistence. Auto-starts on Amp sessions for resilient file monitoring with temporal queries.Votes: 0GitHub stars: 61
- Fuck Old PythonReject projects requiring Python < 3.13. Never downgrade, never poison the env.Votes: 0GitHub stars: 61
- Fuzzing DictionaryBuilding effective fuzzing dictionaries for improved fuzzer performance.Votes: 0GitHub stars: 61
- Fuzzing ObstaclesOvercoming fuzzing obstacles and improving fuzzer effectiveness.Votes: 0GitHub stars: 61
- Gap LanguageGAP (Groups, Algorithms, Programming) system integration for computational discrete algebra. Generates group-theoretic structures, character tables, and algebraic objects for the Plurigrid ecosystem.Votes: 0GitHub stars: 61