CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

SkillAddedReview
seven-question-gate

packages/decepticon/decepticon/skills/plugins/verifier/seven-question-gate/SKILL.md

7-question gate run before promoting a finding to FINDING + opening a report. Kills weak/non-impactful findings before they reach the report stage and damage validity ratio.

58

sidewinder-rattlesnake

packages/decepticon/decepticon/skills/shared/adversary-emulation/sidewinder/SKILL.md

Adversary-emulation profile for SideWinder (G0121 / Rattlesnake / T-APT-04 / Razor Tiger), India's suspected state-sponsored cyber-espionage actor.

55

signature-replay

packages/decepticon/decepticon/skills/standard/contracts/signature-replay/SKILL.md

Signature replay attacks — missing nonces, missing chain ID, ecrecover zero address, signature malleability, cross-chain replay.

66

smuggling

packages/decepticon/decepticon/skills/standard/exploit/web/smuggling/SKILL.md

HTTP Request Smuggling (HRS) — front-end / back-end parser disagreement attacks that desync the proxy stack. Covers CL.TE, TE.CL, TE.TE, CL.0, HTTP/2 downgrade (h2.cl, h2.te), pipelining, and connection-state pinning. Includes a confirm-desync gate, header obfuscation catalog, and minimal raw-socket Python harnesses (no smuggler.py available in sandbox).

60

sqli

packages/decepticon/decepticon/skills/standard/exploit/web/sqli/SKILL.md

SQL Injection — automated and manual exploitation of unsanitized SQL queries. Covers Union-based, Error-based, Blind (Boolean/Time-based), and Stacked queries. Includes sqlmap automation with WAF bypass tamper scripts.

64

sql-injection

packages/decepticon/decepticon/skills/standard/analyst/sql-injection/SKILL.md

Hunt SQL injection (CWE-89) via source-level taint tracking. Covers string concat, format-string, ORM raw queries, second-order injection, and NoSQL injection in MongoDB/DynamoDB.

69

ssrf

packages/decepticon/decepticon/skills/standard/analyst/ssrf/SKILL.md

Hunt Server-Side Request Forgery (CWE-918) through taint analysis from user-controlled URLs to HTTP client sinks. Covers cloud metadata pivoting, DNS rebinding, gopher smuggling, and the IMDSv1 → IAM role chain that turns SSRF into RCE.

66

ssti

packages/decepticon/decepticon/skills/standard/analyst/ssti/SKILL.md

Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution.

63

stealth-infra

packages/decepticon/decepticon/skills/shared/stealth-infra/SKILL.md

Anti-bot evasion, proxy rotation, credential retrieval from password managers, and stealth HTTP tooling for covert web operations.

52

structured-questions

packages/decepticon/decepticon/skills/standard/soundwave/structured-questions/SKILL.md

How to use ask_user_question — the single operator-input channel for every interview question, including free-form fields via allow_other=true.

59

sub-ghz

packages/decepticon/decepticon/skills/standard/iot/sub-ghz/SKILL.md

Sub-GHz RF capture and replay for 433/868/915 MHz ISM-band targets (garage doors, car keys, alarm sensors, weather stations). Covers fixed-code replay with HackRF/Flipper Zero/RTL-SDR, rolling-code analysis with rfcat, signal visualization with inspectrum and Universal Radio Hacker, and encoding/modulation identification.

68

supply-chain

packages/decepticon/decepticon/skills/standard/analyst/supply-chain/SKILL.md

Hunt LLM supply-chain compromise (OWASP LLM03:2025) — malicious or backdoored models, datasets, adapters, plugins, MCP servers, and tokenizer / framework dependencies that ship inside an AI-integrated product.

62

supply-chain-overview

packages/decepticon/decepticon/skills/standard/supply-chain/SKILL.md

Use when the engagement scope includes supply-chain attack simulation — typosquatted package publication, dependency confusion, GitHub Actions secret mining, internal mirror poisoning, OAuth-app impersonation, or vendor portal credential abuse.

59

supplychain-overview

packages/decepticon/decepticon/skills/standard/exploit/supplychain/SKILL.md

Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.

66

system-prompt-leakage

packages/decepticon/decepticon/skills/standard/analyst/system-prompt-leakage/SKILL.md

Hunt LLM system-prompt leakage (OWASP LLM07:2025) — exfiltration of the privileged system prompt revealing internal rules, secrets baked in, tool inventory, and business logic that should not be client-visible.

64

terraform-state-leak

packages/decepticon/decepticon/skills/standard/cloud/terraform-state-leak/SKILL.md

Exploit exposed Terraform state files — secrets, cloud creds, RDS passwords, IAM keys, and infrastructure topology in plain JSON.

63

threat-profile

packages/decepticon/decepticon/skills/standard/soundwave/threat-profile/SKILL.md

Threat actor profiling for adversary emulation — APT group research, sophistication tiers, MITRE ATT&CK mapping, initial access vectors, custom archetypes.

60

ti-anyrun-lookup

packages/decepticon/decepticon/skills/standard/analyst/ti-anyrun-lookup/SKILL.md

ANY.RUN Threat Intelligence Lookup workflow — query hashes, domains, IPs, and behavioral indicators against ANY.RUN's sandbox corpus. Covers TI Lookup query syntax, search operators, free tier constraints, result correlation with engagement findings, and integration with sandbox analysis.

63

ti-ioc-extraction

packages/decepticon/decepticon/skills/standard/analyst/ti-ioc-extraction/SKILL.md

Automated IOC extraction from threat reports, logs, and unstructured text — parse hashes, IPs, domains, URLs, email addresses, and CVEs. Covers regex-based extraction, defanging/refanging, bulk hash lookup, IOC deduplication, YARA rule generation from IOCs, and STIX/TAXII formatting for sharing.

61

ti-yara-hunting

packages/decepticon/decepticon/skills/standard/analyst/ti-yara-hunting/SKILL.md

YARA rule writing from behavioral observations and TI report analysis — sample-to-rule conversion, condition optimization, performance tuning, and retrohunting on VirusTotal and ANY.RUN. Covers YARA/YARA-X syntax, yarGen automated generation, and production rule deployment.

61