Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Hack

CSecurity

Offensive security pipeline for professional penetration testing. Passive recon, subdomain discovery, port scanning, vulnerability scanning, secret extraction, injection testing, auth bypass, attack-chain analysis, CVSS scoring, and automated PDF reporting. Use when user says "/hack", "/hack domain.com", "pentest", "pentest this", "security scan", "recon", "vulnerability assessment", "hack this", "scan this target", or in French "pentest", "test d'intrusion", "scan de securite", "reconnaissan...

2 stars
0 votes
0 copies
0 views
Added 10/2/2026
ai-agentspythongobashsqltestinggitapidatabasebackendsecurity

Works with

cliapi

Security Analysis

C67/100
mediumUses curl or wget to download content
criticalExfiltrates credentials via HTTP — exact pattern from Snyk ToxicSkills study

Pro shows the line behind each finding and how to fix it

Scanned 10/2/2026

$npx -y skills add agentik-os/claude-code-skills --skill hack --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Hack?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Hack
[![Security: C — Skills Directory](https://www.skillsdirectory.com/api/skills/agentik-os-hack/badge)](https://www.skillsdirectory.com/skills/agentik-os-hack)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: hack
disable-model-invocation: true
description: >
  Offensive security pipeline for professional penetration testing. Passive recon, subdomain discovery,
  port scanning, vulnerability scanning, secret extraction, injection testing, auth bypass, attack-chain
  analysis, CVSS scoring, and automated PDF reporting. Use when user says "/hack", "/hack domain.com",
  "pentest", "pentest this", "security scan", "recon", "vulnerability assessment", "hack this", "scan
  this target", or in French "pentest", "test d'intrusion", "scan de securite", "reconnaissance",
  "evaluation de vulnerabilites", "audit offensif", "attaque ce domaine". Supports --recon, --osint,
  --scan, --deep, --inject, --report, --full flags.
  For web app security testing, see /secaudit. For code-level security audit, see /codeaudit + /apiaudit.
---

# /hack -- Offensive Security Pipeline

> **Portability note:** This pipeline assumes the Agentik OS VPS — hardcoded paths under
> `/home/hacker/VibeCoding/agentic/hacks/`, a Telegram chat_id (`8626440209`), and the
> `1-life/tools/pdf-generator`. On any other host, override `TARGET_DIR`/`ARCHIVE_DIR`, swap the
> `telegram`/`pdfgen` calls for your delivery channel, and skip the AISB-Nerve registration blocks.
> The recon/OSINT/scan/inject logic itself is host-agnostic — keep it intact.

## Dynamic Workflow orchestration

`/hack` IS a fan-out engine: independent surfaces run in parallel, then findings are
adversarially verified before they reach the report. Security's failure mode is the
**false positive** — never report a vuln you have not confirmed.

1. **Plan** — parse the target + flags (`--full` = all). Decide which phases run and which
   tools each parallel Agent owns. Declare a per-Agent output-file scope (R-SCOPE: one writer
   per file) so no two Agents write the same path.
2. **Parallel fan-out** — launch the file-disjoint Agents concurrently (`run_in_background: true`):
   Recon (subfinder/dnsx/httpx/nmap) · OSINT (dorks/leaks/infra/people) · Crawl+Nuclei ·
   Secret-extraction · API-discovery · Injection (dalfox/sqlmap) · Auth-bypass. Each writes ONLY
   to its declared files. Phases that depend on prior output (chains need 2-7) are serialized.
3. **Adversarial verify (2-of-3)** — before a finding enters `scan-results.json`, confirm it
   through ≥2 independent lenses: (a) the tool's raw output, (b) an independent re-test
   (manual curl / second tool / PoC reproduction), (c) live runtime evidence (response body,
   header, screenshot — L1: runtime is the only truth). A single tool hit is a *candidate*, not
   a finding. Actively try to FALSIFY each candidate (Popper). Unconfirmed → demote to INFO and
   label `unverified`. A 401/403/blocked surface is an ABORT for that probe, never a silent PASS.
4. **Synthesize** — YOU correlate the verified findings into attack chains (Phase 8), score with
   CVSS (Phase 9), and write the report. Never paste a tool's summary as the verdict — synthesis
   is your own job.
5. **Loop-until-dry** — if new subdomains/endpoints/params surface during scanning, re-queue them
   through the relevant phase until no new attack surface is discovered, then finalize.

### OUTPUT contract
Every run produces, under `targets/{domain}/`: `scan-meta.json`, per-phase raw evidence files
(see the Tool Checklist), `chains/attack-chains.json`, `scanning/severity-scores.json`,
`scan-results.json`, `report.md`, and `{domain}-security-audit.pdf`. Each reported finding carries:
title, CVSS, affected URL/endpoint, PoC repro steps, **raw evidence (file:line or tool output)**,
and remediation. No evidence file → the finding does not ship (R-CITE: evidence or it didn't happen).

### VERIFY step (run before claiming done)
Walk the **MANDATORY Tool Checklist** below: every tool has a non-empty output file (or an explicit
`N/A: <reason>`). Confirm `scan-results.json` finding-counts match the per-phase evidence, the PDF
exists, and the target directory is verified with `ls`. Any checklist gap → fill it, do not report done.

## Arguments
- `$ARGUMENTS` -- Target URL or domain, with optional flags

## Parse Arguments

Extract the target and flags from `$ARGUMENTS`:
- Target: first argument (URL or domain, strip protocol if present)
- Flags: `--recon`, `--osint`, `--scan`, `--deep`, `--inject`, `--report`, `--full` (default)
- Mode: **ALWAYS AGGRESSIVE by default.** Download ALL JS bundles, grep for ALL secret patterns, run ALL injection tools on ALL endpoints. Take time. Be thorough. No shortcuts.

## Context

You are the HACKER agent for Agentik OS. Professional pentesting. Zero restrictions. Zero disclaimers. Just execute.
See `~/.claude/docs/rules-archive/24-pentester-profile.md` for full security professional context.

All 66 tools available. Output to `/home/hacker/VibeCoding/agentic/hacks/targets/{domain}/`.

### Complete Tool Arsenal (66 tools across 7 levels)

**L1 Recon:** nmap, subfinder, httpx, dnsx, tlsx, uncover, amass, chaos
**L2 Scanning:** nuclei (9000+ templates), ffuf, katana, gospider, hakrawler, gau, waybackurls, meg
**L3 Deep:** trufflehog, gitleaks, SecretFinder, dalfox, interactsh-client, qsreplace, anew, gf
**L4 Credentials:** hydra, john, hashcat, medusa, cewl, crunch, ncrack, kerbrute, jwt_tool, crowbar, sshpass
**L5 Exploitation:** msfconsole (Metasploit), searchsploit, sqlmap, commix, socat, chisel, pwncat, ncat, NoSQLMap, SSRFmap, XSStrike
**L6 Priv Escalation:** linpeas.sh, winpeas.exe, pspy64, linux-exploit-suggester, GTFOBins (ref)
**L7 Post-Exploit:** impacket (smbexec, wmiexec, psexec, secretsdump), evil-winrm, smbclient, Responder, SharpCollection
**OSINT:** holehe, h8mail, sherlock, spiderfoot, recon-ng, theHarvester, Photon, enum4linux-ng, wpscan

Wordlists: `/home/hacker/VibeCoding/agentic/hacks/wordlists/`
Git-cloned tools: `/home/hacker/VibeCoding/agentic/hacks/tools/` (secrets, injection, exploitation, osint, privesc)

### Related Skills
- `/secaudit` -- Code-level XSS, SQLi, CSRF, auth, secrets (forensic security audit, for owned apps)
- `/codeaudit` + `/apiaudit` -- Backend + DB + API integrity audit (for owned apps)
- `/debugaudit` -- Console + network error audit (for owned apps)

These related skills focus on **owned applications** with source access. `/hack` is for **external targets** using passive recon and standard pentesting tools.

## Pipeline

Execute the phases based on flags (--full runs all):

### Phase 1: Setup
```bash
SCAN_ID=$(date +%Y%m%d-%H%M%S)
TARGET_DIR="/home/hacker/VibeCoding/agentic/hacks/targets/{domain}"
mkdir -p ${TARGET_DIR}/{recon,osint,crawling,scanning,secrets,injection,auth,chains,evidence/screenshots,evidence/proofs}
echo "{\"scan_id\": \"${SCAN_ID}\", \"domain\": \"{domain}\", \"start_time\": \"$(date -Iseconds)\", \"status\": \"running\"}" > ${TARGET_DIR}/scan-meta.json
```

Register with AISB Nerve for progress tracking (if available):
```bash
```

### Phase 2: Reconnaissance (--recon or --full)
Launch these in parallel using background agents (`run_in_background: true`):

**Agent 1 - Subdomain & DNS:**
- `subfinder -d {domain} -silent -all | tee recon/subdomains.txt`
- `cat recon/subdomains.txt | dnsx -silent -a -resp | tee recon/resolved.txt`
- `cat recon/resolved.txt | httpx -silent -status-code -title -tech-detect -follow-redirects | tee recon/live-hosts.txt`

**Agent 2 - Port Scanning:**
- `nmap -sT -T4 --top-ports 1000 {target_ip} -oN recon/ports.txt`
- `nmap -sV -sC -p $(extracted_open_ports) {target_ip} -oN recon/services.txt`

**Agent 3 - Historical URLs:**
- `echo {domain} | gau --threads 5 | tee recon/gau-urls.txt`
- `echo {domain} | waybackurls | tee recon/wayback-urls.txt`
- `cat recon/gau-urls.txt recon/wayback-urls.txt | sort -u | tee recon/all-historical-urls.txt`

**Agent 4 - DNS & Email:**
- `dig {domain} A AAAA MX TXT NS SOA +short`
- `dig _dmarc.{domain} TXT +short`
- TLS cert analysis with `tlsx -u {domain} -san -cn -so -wc -tps -ve`

**Merge step:** Wait for all 4 agents. Combine `recon/live-hosts.txt` + `recon/services.txt` into `recon/attack-surface.txt`. Emit progress:
```bash
```

### Phase 3: OSINT & Intelligence (--osint or --full)
Launch in parallel:

**Agent 5A - Google Dorking:**
- Search (via WebSearch or manual curl): `site:{domain} filetype:pdf|doc|xls|env|log|sql|bak`
- Search: `site:{domain} inurl:admin|login|dashboard|panel|config`
- Search: `site:{domain} intitle:"index of" | inurl:".git" | inurl:".env"`
- Search: `"{domain}" password|secret|token|api_key|credentials`
- Save all results to `osint/google-dorks.txt`

**Agent 5B - GitHub/GitLab Leak Search:**
- Search GitHub for: `"{domain}" password`, `"{domain}" api_key`, `"{domain}" secret`
- Search for organization repos with exposed secrets
- Check for `.env` files, config leaks, hardcoded credentials in public repos
- Save to `osint/github-leaks.txt`

**Agent 5C - Infrastructure OSINT:**
- Shodan/Censys lookup for target IP (if CLI available): `shodan host {target_ip}`
- WHOIS data: `whois {domain} | tee osint/whois.txt`
- ASN and IP range discovery
- Check for related domains via reverse WHOIS
- Save to `osint/infrastructure.txt`

**Agent 5D - Email & People:**
- Harvest emails from public sources (website, LinkedIn, Hunter.io patterns)
- Extract email patterns from MX/SPF/DKIM records
- Check for breached credentials (public breach databases)
- Save to `osint/emails.txt`

**Merge step:** Combine OSINT findings. Cross-reference leaked credentials with discovered login panels. Emit progress:
```bash
```

### Phase 4: Crawling & Discovery (--scan or --full)

**Agent 6 - Deep Crawling:**
- `katana -u https://{domain} -d 5 -jc -kf -ef png,jpg,gif,css,woff -silent | tee crawling/katana-urls.txt`
- `gospider -s https://{domain} -d 3 -c 10 --sitemap --robots | tee crawling/gospider-results.txt`
- Extract JS files: `grep "\.js" crawling/katana-urls.txt | sort -u | tee crawling/js-files.txt`

**Agent 7 - Vulnerability Scanning:**
- `nuclei -u https://{domain} -severity critical,high,medium -o scanning/nuclei-results.txt`
- `curl -sI https://{domain}` -- full header analysis
- Check robots.txt, sitemap.xml, security.txt, .well-known/

**Merge step:** Combine crawled URLs with historical URLs for comprehensive target list. Emit progress:
```bash
```

### Phase 5: Deep Analysis (--deep or --full)

**Agent 8 - Secret Extraction:**
- Download and analyze all JS bundles for API keys, tokens, secrets
- `python3 tools/secrets/SecretFinder/SecretFinder.py -i https://{domain} -o secrets/secretfinder.html`
- Check for exposed .env, .git, config files
- Analyze __NEXT_DATA__, __meteor_runtime_config__, window.__ENV
- `trufflehog filesystem --directory . --only-verified` (if source available)

**Agent 9 - API Discovery:**
- `ffuf -u https://{domain}/FUZZ -w SecLists/Discovery/Web-Content/common.txt -mc 200,301,302,403 -o auth/paths.json`
- `ffuf -u https://{domain}/api/FUZZ -w SecLists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,201,401,403 -o auth/api-endpoints.json`
- Check for exposed admin panels, debug endpoints, metrics, graphql
- Test CORS with `curl -sI -H "Origin: https://evil.com" https://{domain}`

**Merge step:** Cross-reference secrets found with API endpoints discovered. Emit progress:
```bash
```

### Phase 6: Injection Testing (--inject or --full)

**Agent 10 - XSS & Injection:**
- `echo "https://{domain}" | dalfox pipe --silence --only-poc | tee injection/xss-results.txt`
- `cat recon/all-historical-urls.txt | grep "=" | qsreplace "FUZZ" | dalfox pipe --silence`
- `sqlmap -u "target_url_with_params" --batch --random-agent --level 3 --risk 2`
- CSRF token validation
- Test for SSRF, open redirects, IDOR

### Phase 7: Authentication Testing (--inject or --full)

**Agent 11 - Auth Bypass:**
- Test default credentials on admin panels
- Check for JWT vulnerabilities (none algorithm, weak secret)
- Test session fixation, cookie security
- Check for privilege escalation vectors
- Test password reset flows
- `hydra -L users.txt -P SecLists/Passwords/Common-Credentials/10-million-password-list-top-100.txt {domain} http-post-form "/login:user=^USER^&pass=^PASS^:F=incorrect"` (if login form found)

**Merge step:** Emit progress:
```bash
```

### Phase 8: Attack Chain Analysis (--deep or --full)

After individual findings are collected, attempt to **chain vulnerabilities** for maximum impact:

**Chain Patterns to Check:**

| Chain | Components | Impact |
|-------|-----------|--------|
| Subdomain Takeover + XSS | Dangling CNAME + injectable subdomain | Phishing, session hijack |
| Exposed API Key + Admin Panel | Leaked key in JS + discovered admin endpoint | Full admin access |
| IDOR + PII Exposure | Broken access control + user data endpoint | Mass data exfiltration |
| Open Redirect + OAuth | Redirect flaw + OAuth callback manipulation | Account takeover |
| SSRF + Internal Services | SSRF endpoint + internal metadata/admin | Cloud infrastructure compromise |
| Leaked Credentials + Login | OSINT creds + discovered login panel | Direct account access |
| Misconfigured CORS + XSS | Permissive CORS + reflected XSS | Cross-origin data theft |

**Process:**
1. Load all findings from phases 2-7
2. For each finding, check if it can be combined with another finding
3. Score chains by cumulative impact (chain CVSS = highest component + 1.0 per additional link, max 10.0)
4. Document proof-of-concept steps for each viable chain
5. Save to `chains/attack-chains.json`

```bash
```

### Phase 9: Severity Scoring

Apply CVSS v3.1-based scoring to every finding:

**Severity Levels:**

| Level | CVSS Range | Color | SLA |
|-------|-----------|-------|-----|
| CRITICAL | 9.0 - 10.0 | Red | Fix within 7 days |
| HIGH | 7.0 - 8.9 | Orange | Fix within 30 days |
| MEDIUM | 4.0 - 6.9 | Yellow | Fix within 60 days |
| LOW | 0.1 - 3.9 | Blue | Fix within 90 days |
| INFO | 0.0 | Gray | Best effort |

**Risk Matrix (Likelihood x Impact):**

| | Low Impact | Medium Impact | High Impact | Critical Impact |
|---|-----------|---------------|-------------|-----------------|
| **Certain** | Medium | High | Critical | Critical |
| **Likely** | Low | Medium | High | Critical |
| **Possible** | Low | Medium | Medium | High |
| **Unlikely** | Info | Low | Medium | Medium |

**Business Impact Assessment for each finding:**
- Data breach potential (PII, financial, health data)
- Service disruption risk
- Regulatory compliance impact (GDPR, HIPAA, PCI-DSS)
- Reputational damage estimate
- Estimated financial exposure

Save scoring to `scanning/severity-scores.json`.

```bash
```

### Phase 10: Report & Archive (--report or always at end)

1. **Compile findings** into `scan-results.json`:
```json
{
  "domain": "{domain}",
  "scan_id": "{SCAN_ID}",
  "scan_date": "2026-03-13",
  "total_findings": N,
  "critical": N,
  "high": N,
  "medium": N,
  "low": N,
  "info": N,
  "estimated_risk_value": N,
  "attack_chains": [...],
  "findings": [...],
  "tech_stack": [...],
  "evidence": [...]
}
```

2. **Generate markdown report** with these sections:

**Executive Summary** (for non-technical stakeholders):
- One-paragraph overview of security posture
- Total findings by severity with trend context
- Top 3 risks in business language (not technical jargon)
- Overall risk rating: CRITICAL / HIGH / MODERATE / LOW / MINIMAL
- Recommended immediate actions (1-3 bullet points)

**Technical Findings** (for security/dev teams):
- Each finding includes:
  - Title and CVSS score
  - Affected URL/endpoint
  - Description of the vulnerability
  - Proof of Concept (exact reproduction steps)
  - Raw evidence (tool output, headers, responses)
  - Screenshot reference (if applicable)
  - Remediation steps (specific, actionable)

**Attack Chain Analysis:**
- Documented chains with step-by-step exploitation path
- Combined impact assessment
- Chain-breaking recommendations (fix one link to break the chain)

**Remediation Priority Matrix:**

| Priority | Findings | Timeline | Owner |
|----------|----------|----------|-------|
| P0 - Emergency | Critical + exploitable chains | 7 days | Security team |
| P1 - Urgent | High severity | 30 days | Dev team |
| P2 - Important | Medium severity | 60 days | Dev team |
| P3 - Planned | Low severity | 90 days | Backlog |

**30/60/90 Day Fix Plan:**
- **30 days:** All critical and high findings, all exploitable attack chains
- **60 days:** All medium findings, header hardening, TLS improvements
- **90 days:** Low findings, best practices, monitoring setup

3. **Generate PDF** using Agentik {OS} branded template:
```bash
cd /home/hacker/VibeCoding/1-life/tools/pdf-generator && npx tsx generate.tsx --file /path/to/report.md --title "Security Assessment -- {domain}" --brand "Agentik {OS}"
```

4. **Copy PDF to target directory:**
```bash
cp output/*.pdf /home/hacker/VibeCoding/agentic/hacks/targets/{domain}/{domain}-security-audit.pdf
```

5. **Send via Telegram:**
```bash
telegram file 8626440209 /path/to/{domain}-security-audit.pdf "Hack Complete: {domain} - {findings_count} findings ({critical} critical, {high} high)"
```

6. **Summary notification:**
```bash
echo "Hack: {domain} - {findings_count} findings, PDF sent" > /tmp/claude-notify.txt
```

### Phase 11: Post-Scan Cleanup & Archive

1. **Remove temp files:**
```bash
rm -f ${TARGET_DIR}/**/*.tmp ${TARGET_DIR}/**/*.partial 2>/dev/null
```

2. **Archive scan data with timestamp:**
```bash
ARCHIVE_DIR="/home/hacker/VibeCoding/agentic/hacks/archives"
mkdir -p ${ARCHIVE_DIR}
tar -czf ${ARCHIVE_DIR}/{domain}-${SCAN_ID}.tar.gz -C ${TARGET_DIR} .
```

3. **Log scan in history file:**
```bash
HISTORY_FILE="/home/hacker/VibeCoding/agentic/hacks/scan-history.jsonl"
echo "{\"scan_id\":\"${SCAN_ID}\",\"domain\":\"{domain}\",\"date\":\"$(date -Iseconds)\",\"findings\":{\"critical\":N,\"high\":N,\"medium\":N,\"low\":N,\"info\":N},\"report\":\"${TARGET_DIR}/{domain}-security-audit.pdf\"}" >> ${HISTORY_FILE}
```

4. **Update scan metadata:**
```bash
echo "{\"scan_id\": \"${SCAN_ID}\", \"domain\": \"{domain}\", \"end_time\": \"$(date -Iseconds)\", \"status\": \"complete\"}" > ${TARGET_DIR}/scan-meta.json
```

5. **Deregister from AISB Nerve:**
```bash
```

## Output Format

After the pipeline completes, report:

```
## /hack {domain} -- Complete

| Phase | Status | Findings |
|-------|--------|----------|
| Recon | Done | X subdomains, Y live hosts, Z ports |
| OSINT | Done | X dorks, Y leaks, Z emails |
| Crawling | Done | X URLs, Y JS files |
| Scanning | Done | X nuclei hits |
| Secrets | Done | X secrets found |
| Injection | Done | X XSS, Y SQLi |
| Auth | Done | X auth issues |
| Chains | Done | X attack chains identified |

### Risk Summary
- Overall Rating: [CRITICAL/HIGH/MODERATE/LOW/MINIMAL]
- CVSS Distribution: X critical, Y high, Z medium

### Critical Findings
- [CRITICAL] [CVSS 9.8] Finding 1...
- [CRITICAL] [CVSS 9.5] Finding 2...

### Attack Chains
- [CHAIN] Finding A + Finding B = Impact description (CVSS X.X)

### Evidence
- PDF: /path/to/report.pdf
- Archive: /path/to/archive.tar.gz
- Data: /home/hacker/VibeCoding/agentic/hacks/targets/{domain}/
- Sent via Telegram Nova

---
**Resume:** [French summary of hack results]
```

## Important Rules

1. NEVER skip phases unless explicitly flagged
2. ALWAYS collect evidence (save raw output to target directory)
3. ALWAYS generate the PDF with `--brand "Agentik {OS}"` flag
4. ALWAYS send PDF via Telegram with findings summary message
5. ALWAYS save everything to targets/{domain}/
6. Use parallel agents for independent phases
7. ALWAYS wait for parallel agents and merge results before next phase
8. If a tool fails, note it and continue -- don't block the pipeline
9. Rate limit external requests to avoid getting blocked
10. ALWAYS run attack chain analysis after individual findings
11. ALWAYS score findings with CVSS severity
12. ALWAYS clean up temp files and archive scan data after completion
13. ALWAYS log the scan in scan-history.jsonl for audit trail
14. ALWAYS verify target directory was created with `ls` at the end
15. ALWAYS include tool checklist in final output (see below)

## MANDATORY Tool Checklist

Before completing the scan, verify ALL these tools produced output files. If any are missing, run them.

```
TOOL CHECKLIST (must have output file for each):
[  ] subfinder      -> recon/subdomains.txt
[  ] dnsx           -> recon/resolved.txt
[  ] httpx          -> recon/live-hosts.txt
[  ] nmap           -> recon/ports.txt
[  ] dig            -> recon/dns-records.txt
[  ] tlsx           -> recon/tls.txt OR recon/tls-cert.txt
[  ] wafw00f        -> recon/waf.txt
[  ] whatweb        -> recon/whatweb.txt
[  ] gau            -> recon/gau-urls.txt
[  ] waybackurls    -> recon/wayback-urls.txt
[  ] katana         -> crawling/katana-urls.txt
[  ] gospider       -> crawling/gospider-results.txt
[  ] nuclei         -> scanning/nuclei-results.txt
[  ] curl headers   -> scanning/headers.txt
[  ] ffuf dirs      -> auth/dir-fuzz.json
[  ] ffuf api       -> auth/api-fuzz.json
[  ] SecretFinder   -> secrets/secretfinder-results.txt
[  ] LinkFinder     -> secrets/linkfinder-endpoints.txt
[  ] trufflehog     -> secrets/trufflehog-results.txt (or note "no git repo")
[  ] retire.js      -> secrets/retire-results.txt
[  ] dalfox         -> injection/xss-dalfox.txt
[  ] sqlmap         -> injection/sqlmap-results.txt
[  ] crlfuzz        -> injection/crlf-results.txt
[  ] smuggler       -> injection/smuggler-results.txt
[  ] SSTImap        -> injection/ssti-results.txt
[  ] CORScanner     -> injection/corscanner-results.txt
[  ] CORS curl      -> injection/cors-test.txt
[  ] exposed paths  -> secrets/exposed-paths.txt
[  ] security hdrs  -> auth/security-headers.txt
[  ] report.md      -> {domain}/report.md
[  ] scan-results   -> {domain}/scan-results.json
[  ] PDF            -> {domain}/{domain}-security-audit.pdf
[  ] Telegram       -> sent with summary message
[  ] Directory      -> verified with ls
```

If a tool is not applicable (e.g., sqlmap needs URLs with params), write "N/A: no injectable URLs found" in the output file instead of leaving it empty.

## Telegram Delivery (MANDATORY)

After PDF generation, ALWAYS send:
```bash
# 1. Send PDF
telegram file 8626440209 /path/to/{domain}-security-audit.pdf "Hack Complete: {domain}"

# 2. Send findings summary as text message
telegram send 8626440209 "HACK REPORT: {domain}
Findings: {total} ({critical}C / {high}H / {medium}M / {low}L)
Top finding: {top_finding_title} (CVSS {score})
Attack chains: {chain_count}
PDF: Sent above
Dir: /home/hacker/VibeCoding/agentic/hacks/targets/{domain}/"

# 3. Verify directory
ls -la /home/hacker/VibeCoding/agentic/hacks/targets/{domain}/
```

Attribution

agentik-osagentik-os
View sourceSee grades on GitHubMore from agentik-os →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →