github.com/PurpleAILAB/Decepticon
| Skill | Added | Review |
|---|---|---|
seven-question-gate packages/decepticon/decepticon/skills/plugins/verifier/seven-question-gate/SKILL.md 7-question gate run before promoting a finding to FINDING + opening a report. Kills weak/non-impactful findings before they reach the report stage and damage validity ratio. | 58 58 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a04f96b | |
sidewinder-rattlesnake packages/decepticon/decepticon/skills/shared/adversary-emulation/sidewinder/SKILL.md Adversary-emulation profile for SideWinder (G0121 / Rattlesnake / T-APT-04 / Razor Tiger), India's suspected state-sponsored cyber-espionage actor. | 55 55 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
signature-replay packages/decepticon/decepticon/skills/standard/contracts/signature-replay/SKILL.md Signature replay attacks — missing nonces, missing chain ID, ecrecover zero address, signature malleability, cross-chain replay. | 66 66 Impact — No eval scenarios have been run Securityby Medium Suggest reviewing before use Version: a04f96b | |
smuggling packages/decepticon/decepticon/skills/standard/exploit/web/smuggling/SKILL.md HTTP Request Smuggling (HRS) — front-end / back-end parser disagreement attacks that desync the proxy stack. Covers CL.TE, TE.CL, TE.TE, CL.0, HTTP/2 downgrade (h2.cl, h2.te), pipelining, and connection-state pinning. Includes a confirm-desync gate, header obfuscation catalog, and minimal raw-socket Python harnesses (no smuggler.py available in sandbox). | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
sqli packages/decepticon/decepticon/skills/standard/exploit/web/sqli/SKILL.md SQL Injection — automated and manual exploitation of unsanitized SQL queries. Covers Union-based, Error-based, Blind (Boolean/Time-based), and Stacked queries. Includes sqlmap automation with WAF bypass tamper scripts. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
sql-injection packages/decepticon/decepticon/skills/standard/analyst/sql-injection/SKILL.md Hunt SQL injection (CWE-89) via source-level taint tracking. Covers string concat, format-string, ORM raw queries, second-order injection, and NoSQL injection in MongoDB/DynamoDB. | 69 69 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
ssrf packages/decepticon/decepticon/skills/standard/analyst/ssrf/SKILL.md Hunt Server-Side Request Forgery (CWE-918) through taint analysis from user-controlled URLs to HTTP client sinks. Covers cloud metadata pivoting, DNS rebinding, gopher smuggling, and the IMDSv1 → IAM role chain that turns SSRF into RCE. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
ssti packages/decepticon/decepticon/skills/standard/analyst/ssti/SKILL.md Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
stealth-infra packages/decepticon/decepticon/skills/shared/stealth-infra/SKILL.md Anti-bot evasion, proxy rotation, credential retrieval from password managers, and stealth HTTP tooling for covert web operations. | 52 52 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
structured-questions packages/decepticon/decepticon/skills/standard/soundwave/structured-questions/SKILL.md How to use ask_user_question — the single operator-input channel for every interview question, including free-form fields via allow_other=true. | 59 59 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: a04f96b | |
sub-ghz packages/decepticon/decepticon/skills/standard/iot/sub-ghz/SKILL.md Sub-GHz RF capture and replay for 433/868/915 MHz ISM-band targets (garage doors, car keys, alarm sensors, weather stations). Covers fixed-code replay with HackRF/Flipper Zero/RTL-SDR, rolling-code analysis with rfcat, signal visualization with inspectrum and Universal Radio Hacker, and encoding/modulation identification. | 68 68 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
supply-chain packages/decepticon/decepticon/skills/standard/analyst/supply-chain/SKILL.md Hunt LLM supply-chain compromise (OWASP LLM03:2025) — malicious or backdoored models, datasets, adapters, plugins, MCP servers, and tokenizer / framework dependencies that ship inside an AI-integrated product. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
supply-chain-overview packages/decepticon/decepticon/skills/standard/supply-chain/SKILL.md Use when the engagement scope includes supply-chain attack simulation — typosquatted package publication, dependency confusion, GitHub Actions secret mining, internal mirror poisoning, OAuth-app impersonation, or vendor portal credential abuse. | 59 59 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
supplychain-overview packages/decepticon/decepticon/skills/standard/exploit/supplychain/SKILL.md Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
system-prompt-leakage packages/decepticon/decepticon/skills/standard/analyst/system-prompt-leakage/SKILL.md Hunt LLM system-prompt leakage (OWASP LLM07:2025) — exfiltration of the privileged system prompt revealing internal rules, secrets baked in, tool inventory, and business logic that should not be client-visible. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
terraform-state-leak packages/decepticon/decepticon/skills/standard/cloud/terraform-state-leak/SKILL.md Exploit exposed Terraform state files — secrets, cloud creds, RDS passwords, IAM keys, and infrastructure topology in plain JSON. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
threat-profile packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/SKILL.md Threat actor profiling for adversary emulation — APT group research, sophistication tiers, MITRE ATT&CK mapping, initial access vectors, custom archetypes. | 60 60 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: a04f96b | |
ti-anyrun-lookup packages/decepticon/decepticon/skills/standard/analyst/ti-anyrun-lookup/SKILL.md ANY.RUN Threat Intelligence Lookup workflow — query hashes, domains, IPs, and behavioral indicators against ANY.RUN's sandbox corpus. Covers TI Lookup query syntax, search operators, free tier constraints, result correlation with engagement findings, and integration with sandbox analysis. | 63 63 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: a04f96b | |
ti-ioc-extraction packages/decepticon/decepticon/skills/standard/analyst/ti-ioc-extraction/SKILL.md Automated IOC extraction from threat reports, logs, and unstructured text — parse hashes, IPs, domains, URLs, email addresses, and CVEs. Covers regex-based extraction, defanging/refanging, bulk hash lookup, IOC deduplication, YARA rule generation from IOCs, and STIX/TAXII formatting for sharing. | 61 61 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: a04f96b | |
ti-yara-hunting packages/decepticon/decepticon/skills/standard/analyst/ti-yara-hunting/SKILL.md YARA rule writing from behavioral observations and TI report analysis — sample-to-rule conversion, condition optimization, performance tuning, and retrohunting on VirusTotal and ANY.RUN. Covers YARA/YARA-X syntax, yarGen automated generation, and production rule deployment. | 61 61 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: a04f96b |