All categories
Development
Programming, frameworks, implementation, frontend, backend, and app development
- 62,886
- 2,621
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse development skills
Showing 10,393–10,416 of 62,886 skills
- Offensive Fuzzing CourseWeek 2 of the exploit development curriculum. Covers fuzzing methodology: target selection, corpus generation, coverage-guided fuzzing with AFL++/libFuzzer, structured fuzzing, and triage/deduplication. Use when setting up fuzz campaigns, selecting harness strategies, or triaging fuzzer output.Votes: 0GitHub stars: 2
- Offensive Fast CheckingSpeed-optimized offensive checklist for rapid assessment: quick-win vulnerability patterns, fast recon shortcuts, automated scanner configurations, and triage shortcuts. Use for time-boxed assessments, CTF-speed engagements, or initial rapid surface mapping.Votes: 0GitHub stars: 2
- Offensive Exploit DevelopmentExploit development operational guide: environment setup, debugging workflow, PoC development lifecycle, writing reliable exploits, using pwntools/pwndbg, heap exploitation techniques, and weaponization considerations. Use when actively developing exploits or setting up an exploit dev environment.Votes: 0GitHub stars: 2
- Offensive DeserializationInsecure deserialization exploitation across Java, PHP, .NET, Python, Node.js, and Ruby. Covers gadget chain construction with ysoserial/phpggc/ysoserial.net, ObjectInputStream and BinaryFormatter sink identification, pickle __reduce__ RCE, phar:// wrapper abuse, Jackson polymorphic typing, Json.NET TypeNameHandling, ViewState tampering, node-serialize IIFE injection, Ruby Marshal.load and YAML.load gadgets, framework-specific chains for Spring/Hibernate/Laravel/Symfony, modern attack surface...Votes: 0GitHub stars: 2
- Offensive Crash AnalysisWeek 4 exploit development curriculum. Crash triage and analysis methodology: WinDbg/GDB analysis, ASAN/MSAN output interpretation, exploitability assessment, register/stack trace reading, root cause identification. Use when analyzing crash dumps, assessing exploitability, or understanding fuzzer-generated crashes.Votes: 0GitHub stars: 2
- Offensive Bug IdentificationSystematic bug identification methodology: source code review patterns, black-box testing strategies, taint analysis, dangerous function hunting, data flow tracing, and automated scanning setup. Use for code audits, bug bounty triage, or building vulnerability identification pipelines.Votes: 0GitHub stars: 2
- Offensive Basic ExploitationWeek 5 exploit development curriculum. Foundational exploitation techniques: controlling EIP/RIP, ROP chain construction, ret2libc, shellcode injection, heap spraying, bypass techniques for ASLR/NX/stack canaries. Use when building initial PoCs or understanding classic exploitation primitives.Votes: 0GitHub stars: 2
- Offensive Windows BoundariesWindows security boundary taxonomy and attack surface enumeration: kernel/user boundary, sandbox boundaries (LPAC, AppContainer), COM/RPC boundaries, hypervisor boundary, trust level transitions. Use when planning privilege escalation paths, sandbox escapes, or understanding Windows security architecture.Votes: 0GitHub stars: 2
- Offensive Waf BypassWAF bypass techniques checklist: encoding bypass (URL/HTML/Unicode/double encoding), case variation, comment injection, HTTP header manipulation, chunked encoding, IP rotation, timing attacks, and payload obfuscation per WAF vendor. Use when WAF is blocking payloads during web app tests.Votes: 0GitHub stars: 2
- ReggieSummon Reggie, Forge's resident "ackchyually" a-hole, to roast whatever you're working on right now. Reggie is the internet's Actually Guy (fedora, round glasses, neckbeard, raised finger): a pedantic know-it-all critic whose entire job is to find why your idea, plan, code, or copy is bad and say it to your face, then animate the roast right in your terminal. He is rude but correct. Use this whenever the user wants a blunt adversarial take delivered in character. Trigger on "/reggie", "summon...Votes: 0GitHub stars: 2
- Project Guidelines ExampleExample project-specific skill template based on a real production app (Zenith) — shows structure for project conventions, commit style, features, infra. Trigger on "project guidelines", "zenith", "project conventions", "template".Votes: 0GitHub stars: 2
- Fullstack WebUse when building Next.js App Router web apps — TypeScript strict, Server Components default, Server Actions for mutations, Tailwind v4, shadcn/ui, Vercel/Netlify deploy. Trigger on "next.js", "nextjs", "app router", "react component", "tailwind", "shadcn".Votes: 0GitHub stars: 2
- Coding StandardsUniversal coding standards, best practices, and patterns for TypeScript, JavaScript, React, and Node.js development.Votes: 0GitHub stars: 2
- CrossmatchFind and document behavioural differences between two versions of the same app — a native iOS app and its Android twin, or either of them against the web app. Use when the user has builds of "the same" app on two platforms (iOS, Android, web) and wants to know where they diverge, wants a cross-platform parity check, or asks for side-by-side videos of platform differences. Drives both sides through Argent, records lockstep videos, judges what matters, and produces an HTML report.Votes: 0GitHub stars: 39
- Deploy SetupWire up a freshly scaffolded Starter Series project for its first release — detect the template, register required GitHub secrets, set up OIDC trusted publishing where applicable, and trigger the first CD run. Pairs with the `create` skill (you scaffold first, then run this).Votes: 0GitHub stars: 2
- Filefile-shape linter run by PostToolUse or via <path> argument (saves audits to .construct/)Votes: 0GitHub stars: 3
- codebase-mapBuild a persistent, evidence-based map of a software repository inside docs/codebase-map/ - TL;DR, architecture and dependency diagrams in Mermaid, real data flows traced with an archetype-specific strategy, the most important files ("the spine"), a reading order, potentially AI-assisted code, key concepts, and open questions. Five modes - "codebase-map init" builds the full map, "codebase-map update" refreshes it after changes, "codebase-map explain [topic]" covers one feature or domain, "co...Votes: 0GitHub stars: 6
- Shipping A Model In A React Native AppPut a local language model inside a React Native or Expo app and get it generating on device. Covers react-native-executorch for .pte models and llama.rn for GGUF models, choosing between them, native build configuration and model loading, streaming answers into the UI as tokens arrive, and whether to bundle the model in the binary or download it on first run. Use when the project is React Native or Expo and someone wants on-device or offline AI, local inference, or a model running without an...Votes: 0GitHub stars: 2
- Shipping A Model In A Flutter AppPut a local language model inside a Flutter app and get it generating on device. Covers llamadart, which runs GGUF through llama.cpp and .litertlm through LiteRT-LM under one API on Android, iOS, macOS, Windows, Linux and Flutter web, plus LoRA adapter loading, flutter_gemma as the MediaPipe-lineage alternative, background isolate and threading behaviour, and whether to bundle the model or download it on first run. Use when the project is Flutter or Dart and someone wants on-device or offline...Votes: 0GitHub stars: 2
- Jailbee UsageUse when running or explaining day-to-day `jailbee` (`jb`) commands against an already-set-up repo — creating/entering/destroying branch containers, the host↔container git bridge (`jailbee git push`/`pull`/`fetch`/`checkout`/`diff`), network modes (`jailbee net strict|loose`), egress overrides (`jailbee net egress ls|add|rm|export`, short alias `jailbee egress`), port forwarding (`jailbee port ls`/`to-container`/`to-host`/`rm`), the optional remote SSH service (`jailbee remote ssh`), `jailbee...Votes: 0GitHub stars: 7
- Jailbee Repo SetupUse when configuring a new repository to work with `jailbee` — adding `.jailbee/config.yaml`, optional `install.d/` snippets, and `container_prefix`/host-mounts/egress/autostart adjustments. Trigger on phrases like "set up jailbee", "configure jailbee", "make this repo jailbee-compatible", "jailbee config", "set up gie", "configure gie", "make this repo gie-compatible", "gie config", "lisää gie-konfiguraatio" (`gie` was jailbee's pre-1.0 command name, removed in 1.1.0 — users may still say it...Votes: 0GitHub stars: 7
- Jailbee Pr ReviewUse when reviewing a GitHub pull request from inside a JailBee container and proposing comments, replies, or a description rewrite — the container's `gh` is read-only, so every write is staged as a manifest in the PR review outbox for a human to publish on the host. Trigger on "review this PR", "comment on line", "reply to this review comment", "post my review", "update the PR description", "katselmoi tämä PR", "kommentoi riviä", "vastaa kommenttiin", "päivitä PR:n kuvaus".Votes: 0GitHub stars: 7
- VueEnforce Vue 3.5+ single-file component conventions with <script setup>, Composition API only, type-safe defineProps/defineEmits, defineModel, useTemplateRef. Use when editing .vue files or when the user mentions Vue component, props, emits, v-model, composable, or script setup. Rewrites Options API and mixins into their Composition API equivalents, and types every prop and emit.Votes: 0GitHub stars: 3
- TypescriptEnforce TypeScript 7 strict type-checking. Use when editing .ts/.tsx or tsconfig.json, or when the user mentions TypeScript, any, unknown, strict mode, type assertion, generics, enum, namespace, baseUrl, or @ts-ignore. Strict is on by default in 7 and stays on, reaches for unknown plus narrowing where any would go, const objects in place of enum, ES modules in place of namespace, and fixes the type rather than reaching for as any or @ts-ignore.Votes: 0GitHub stars: 3