ctf-solver
An expert-level CTF solver agent that automates reconnaissance, vulnerability analysis, and exploit generation for web, pwn, crypto, reverse, and forensic challenges.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
99 skills found
An expert-level CTF solver agent that automates reconnaissance, vulnerability analysis, and exploit generation for web, pwn, crypto, reverse, and forensic challenges.
A professional bug bounty reporting agent that enforces impact-first writing, CVSS 3.1 scoring, and pre-submit validation for platforms like HackerOne, Bugcrowd, and Intigriti.
Expert-level guidance for ffuf web fuzzing, enabling automated discovery of hidden directories, files, parameters, and vulnerabilities during penetration testing.
Automated security skill for identifying and validating XSS vulnerabilities, including Reflected, Stored, and DOM-based attacks across various contexts.
Perform automated security audits, bug detection, and code quality assessments on local branch diffs using a structured, checklist-driven verification process.
Automated detection of IDOR vulnerabilities using a three-phase subagent workflow to verify authorization and ownership checks on sensitive endpoints.
Map the attack surface of smart contract codebases by identifying and categorizing state-changing entry points.
Analyze source code for security vulnerabilities based on OWASP Top 10 guidelines and suggest remediation strategies.
Perform comprehensive code reviews with a focus on security vulnerabilities, performance optimization, maintainability, and code correctness.
A suite of professional tools for auditing, evaluating, chunking, and scaffolding production-ready RAG pipelines within Claude Code.
Comprehensive secure coding guidelines for 15+ languages, covering OWASP Top 10, infrastructure security, and best practices to identify vulnerabilities in code, configurations, and cloud setups.
Comprehensive security audit and hardening for AI agents: credential scanning, PII protection, prompt injection defense, and workspace config optimization.