Discover and install skills to enhance your AI agent's capabilities.
| Name | Contains | Score |
|---|---|---|
Drakkar-Software/OctoBot Use this skill for objectively evaluating bull vs bear arguments, weighing evidence quality, and providing balanced risk assessments for trading decisions. | Skills | |
PurpleAILAB/Decepticon Detect and neutralize anti-debug / anti-VM checks — IsDebuggerPresent, ptrace, NtGlobalFlag, timing, hardware-breakpoint detection. | Skills | |
OpenCTI-Platform/opencti Use when: scaffolding a creation form drawer with Formik validation and a Relay mutation for a new entity | Skills | |
PurpleAILAB/Decepticon Authentication surface — login endpoints, JWT/OAuth/SAML/SSO/API-key mechanism identification. | Skills | |
PurpleAILAB/Decepticon Recon output formatting — report structure, CVSS v4.0 scoring (primary), MITRE ATT&CK mapping, finding prioritization, Markdown output, detection gap tracking, handoff checklists. | Skills | |
nearai/ironclaw Helps users delegate tasks, break them into steps, set deadlines, and track progress via routines and memory. | Skills | |
nearai/ironclaw Compose and deliver summaries of open commitments, deadlines, pending signals, and resolution suggestions. | Skills | |
vercel-labs/json-render Core package for defining schemas, catalogs, and AI prompt generation for json-render. Use when working with @json-render/core, defining schemas, creating catalogs, or building JSON specs for UI/video generation. | Skills | |
PurpleAILAB/Decepticon Sliver C2 framework operations — server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles. | Skills | |
PurpleAILAB/Decepticon Domain fronting and CDN abuse for C2 concealment — CloudFront, Azure CDN, Fastly setup, TLS SNI vs Host header technique, CDN-based redirectors, and integration with Cobalt Strike and Sliver. | Skills | |
BabylonJS/Babylon.js Monitor one or more GitHub PRs and maintain a live status table showing title, link, check status, resolved/total comments, and reviewer approval. Shows a Windows dialog when a PR is ready to merge. Input: a comma-separated list of PR numbers, "mine", or "all". | Skills | |
PurpleAILAB/Decepticon Android APK pentest workflow — apktool/jadx static, Frida dynamic instrumentation, SSL pinning bypass, root detection bypass, intent fuzzing, keystore extraction. | Skills | |
PurpleAILAB/Decepticon ROS2/DDS network attack: unauthenticated topic enumeration, message injection, and telemetry interception against robotic platforms and autonomous systems. | Skills | |
oven-sh/bun Verify a Bun runtime change by driving the debug binary end-to-end. | Skills | |
PurpleAILAB/Decepticon Unkeyed-input cache poisoning — X-Forwarded-Host/Scheme/Port, X-Original-URL, fat-GET, parameter cloaking, oversized-header DoS, and chains to stored-XSS / open redirect via shared caches. | Skills | |
PurpleAILAB/Decepticon SQL Injection — automated and manual exploitation of unsanitized SQL queries. Covers Union-based, Error-based, Blind (Boolean/Time-based), and Stacked queries. Includes sqlmap automation with WAF bypass tamper scripts. | Skills | |
PurpleAILAB/Decepticon 2FA / OTP logic flaws — response & status tampering, brute force, OTP reuse, backup-code abuse, race conditions, missing-2FA on flows, remember-me bypass, password-reset skips 2FA. | Skills | |
PurpleAILAB/Decepticon Insecure Direct Object References (IDOR) — authorization bypass through predictable object references (sequential IDs, UUIDs, filenames, encoded IDs). Covers horizontal/vertical privilege escalation, ID enumeration, HTTP method tampering, and JWT sub claim manipulation. | Skills | |
PurpleAILAB/Decepticon EtherNet/IP + CIP (TCP 44818 / UDP 2222) attack playbook — List Identity broadcast, pylogix tag-database dump, tag read/write on Allen-Bradley ControlLogix/CompactLogix, CIP Forward Open, PLC mode change (Stop/Run), and historical Rockwell auth-bypass CVEs. North American ICS dominant protocol. | Skills | |
PurpleAILAB/Decepticon Trust boundary mapping and startup sequence audit for developer tools, CLI apps, and plugin systems. Load when the target is a developer tool, CLI, IDE extension, or any application that loads config from the current directory. | Skills |
Can't find what you're looking for? Evaluate a missing skill.