CtrlK
BlogDocsLog inGet started
Tessl Logo

Decepticon

github.com/PurpleAILAB/Decepticon

SkillAddedReview
trust-boundary-analysis

packages/decepticon/decepticon/skills/standard/analyst/trust-boundary/SKILL.md

Trust boundary mapping and startup sequence audit for developer tools, CLI apps, and plugin systems. Load when the target is a developer tool, CLI, IDE extension, or any application that loads config from the current directory.

69

turla-venomous-bear

packages/decepticon/decepticon/skills/shared/adversary-emulation/turla/SKILL.md

Adversary-emulation profile for Turla (G0010 / Venomous Bear / Secret Blizzard / Waterbug / KRYPTON / Snake), Russia's FSB Center 16 cyber-espionage actor.

55

unbounded-consumption

packages/decepticon/decepticon/skills/standard/analyst/unbounded-consumption/SKILL.md

Hunt LLM unbounded consumption (OWASP LLM10:2025) — denial-of-wallet and denial-of-service against LLM endpoints via unrestricted prompt size, runaway tool loops, expensive model selection, and unauthenticated fan-out.

67

upgradeable-proxy

packages/decepticon/decepticon/skills/standard/contracts/upgradeable-proxy/SKILL.md

Proxy upgrade patterns and their bugs — uninitialized implementation, storage slot collisions, selector clashes, unprotected upgrade auth.

62

vector-and-embedding-weaknesses

packages/decepticon/decepticon/skills/standard/analyst/vector-and-embedding-weaknesses/SKILL.md

Hunt vector / embedding weaknesses (OWASP LLM08:2025) — adversarial inputs against the RAG / similarity layer that cause cross-tenant leak, embedding-inversion privacy loss, semantic confusion, and retriever-driven prompt injection.

64

verb-tampering

packages/decepticon/decepticon/skills/standard/exploit/web/verb-tampering/SKILL.md

HTTP verb/method tampering — auth bypass via HEAD/OPTIONS/arbitrary methods, X-HTTP-Method-Override, TRACE/PUT/DELETE exposure, framework routing flaws.

64

verifier-overview

packages/decepticon/decepticon/skills/plugins/verifier/SKILL.md

Stage 3 triage and verification playbook. Crafts minimal PoCs, runs them with ZFP controls, promotes validated bugs to FINDING nodes with CVSS. Load at verifier-agent startup.

66

volt-typhoon

packages/decepticon/decepticon/skills/shared/adversary-emulation/volt-typhoon/SKILL.md

Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.

56

vulnresearch-orchestrator

packages/decepticon/decepticon/skills/plugins/vulnresearch/SKILL.md

Five-stage modular vulnerability pipeline orchestrator. Delegates scan → detect → verify → patch → exploit through OPPLAN objectives. Load at orchestrator startup.

62

waf-bypass

packages/decepticon/decepticon/skills/standard/exploit/web/waf-bypass/SKILL.md

WAF evasion — payload obfuscation, HTTP-level evasion, origin-IP discovery, rate/anomaly evasion, per-WAF notes (Cloudflare/Akamai/AWS WAF/ModSecurity).

68

web

packages/decepticon/decepticon/skills/standard/exploit/web/SKILL.md

Web application exploitation — the primary category skill for all web-based attacks. This is a routing skill: read this first to identify the attack type, then load the appropriate specialized sub-skill for detailed procedures. Covers 11 technique areas across injection, file access, authentication, and API exploitation.

53

web-api-enumeration

packages/decepticon/decepticon/skills/standard/recon/web-recon/api-enumeration/SKILL.md

REST API discovery, GraphQL detection, parameter fuzzing.

59

web-auth-mapping

packages/decepticon/decepticon/skills/standard/recon/web-recon/auth-mapping/SKILL.md

Authentication surface — login endpoints, JWT/OAuth/SAML/SSO/API-key mechanism identification.

60

web-cache-poisoning

packages/decepticon/decepticon/skills/standard/exploit/web/web-cache-poisoning/SKILL.md

Unkeyed-input cache poisoning — X-Forwarded-Host/Scheme/Port, X-Original-URL, fat-GET, parameter cloaking, oversized-header DoS, and chains to stored-XSS / open redirect via shared caches.

69

web-cms-scanning

packages/decepticon/decepticon/skills/standard/recon/web-recon/cms-scanning/SKILL.md

CMS-specific scans — WordPress (wpscan), Joomla, Drupal version detection.

61

web-cookie-audit

packages/decepticon/decepticon/skills/standard/recon/web-recon/cookie-audit/SKILL.md

Cookie-conditional sink discovery — bisect required cookies per sink, session-write timeline for race-condition challenges.

65

web-discovery

packages/decepticon/decepticon/skills/standard/recon/web-recon/discovery/SKILL.md

Web app discovery — directory/file fuzzing, vhost discovery, JavaScript endpoint extraction.

62

web-recon

packages/decepticon/decepticon/skills/standard/recon/web-recon/SKILL.md

Web application enumeration hub — directory/file fuzzing, vhost discovery, API enumeration, CMS scanning, WAF detection, auth surface mapping, cookie audit.

63

web-subdomain-takeover

packages/decepticon/decepticon/skills/standard/recon/web-recon/subdomain-takeover/SKILL.md

Subdomain takeover via dangling DNS/CNAME — GitHub Pages, Heroku, Azure, Fastly, Shopify, Netlify, Surge, Tumblr, Beanstalk, Zendesk, etc.

60

web-waf-detection

packages/decepticon/decepticon/skills/standard/recon/web-recon/waf-detection/SKILL.md

Web Application Firewall fingerprinting — Cloudflare, AWS WAF, Akamai, Imperva, etc.

67