46 skill packages

The workflow
catalog.

Each of the 46 skill packages carries its scripts, payloads, runbooks, evidence rules, and reporting guidance. The harness dispatches a package; the package contains the method.

Recon & Planning

01

recon

Subdomains, live hosts, crawling, JS recon, asset inventory

20

domain-model

Target archetype classification and attack surface mapping

22

coverage

Coverage ledger and gap reporting across standards

23

technique-kb

Technique catalog with preconditions, signals, safety

24

planner

Domain-driven ranked test plan generator

30

asset-graph

Persistent SQLite asset graph with hotlist + delta

29

traffic-corpus

HAR/Burp/mitmproxy import, route normalization

39

campaign

Autonomous campaign from a target URL

Web Vulnerabilities

02

xss

Reflected, stored, DOM, blind XSS, CSP checks

03

sqli

Error, blind, time-based, union, NoSQL injection

04

ssrf

Direct, blind, parser-bypass, cloud metadata

05

rce

Command injection, SSTI, LFI/RFI

08

file-upload

Extension, content-type, polyglot, SVG bypass

09

cors-csrf

CORS, CSRF, SameSite, origin behavior

10

race-condition

Concurrent requests, TOCTOU, timing windows

19

http-protocol

Request smuggling, cache poisoning, parser diffs

15

nuclei-scanner

Scope-aware nuclei template execution

Auth, API & Business Logic

06

auth

JWT, OAuth, session, MFA, password reset

07

api

REST, GraphQL, BOLA/IDOR, mass assignment

28

persona

Attacker/victim/admin persona management

31

cross-account

Cross-persona replay for BOLA/IDOR

32

business-logic

Workflow state machine testing

34

impact-verifier

Candidate → bounty-grade verification gate

Cloud · Mobile · Browser · AI

11

cloud

S3, buckets, IAM, metadata checks

12

mobile

APK analysis, deeplinks, cert pinning

18

modern-browser

WebGPU, WASM, XS-Leaks, isolation

17

ai-llm

Prompt injection, tool abuse, exfiltration

35

agent-safety

Guardrails against prompt injection in target

33

oob-infra

Interactsh OOB callback infrastructure

Specialized Audits

40

cicd-security

Workflow injection, runner poisoning, OIDC theft

41

graphql-audit

Introspection, batching DoS, aliasing IDOR

42

web3-audit

DeFi accounting, reentrancy, oracle, flash loans

43

meme-coin-audit

Rug-pull, SPL freeze/mint authority, LP drain

45

identity-domain

NTLM leaks, ADCS/ADFS, Entra tenant recon

14

privesc

Linux, Docker, SUID, capabilities, cron

46

binary-analysis

PE triage, x64dbg MCP dynamic analysis

Research & Reporting

13

osint

Email, username, GitHub, Google dorks

37

vuln-intel

CVE tracking, disclosed reports, PoCs

21

standard-catalog

WSTG, ASVS, API Top 10, VRT, CWE mappings

16

reporting

Evidence manifests, CVSS, batch export

36

program-memory

Per-program knowledge persistence

38

scope-manager

Scope validation and guardrails

44

triage-validation

7-question gate before submission

Toolkit Improvement

26

evaluation-harness

Vulnerable fixtures, precision/recall/F1

27

skill-scientist

Hypothesize, run, review, propose improvements

25

auto-research

Public knowledge import and deduplication

Read the docs → · Install →