github.com/PurpleAILAB/Decepticon
| Skill | Added | Review |
|---|---|---|
entra-conditional-access-bypass packages/decepticon/decepticon/skills/standard/cloud/entra-conditional-access-bypass/SKILL.md Entra Conditional Access bypass — discover policy gaps, exploit legacy-auth protocols (IMAP/POP/SMTP-AUTH/EWS), spoof device/platform/UA/location conditions, abuse service-principals + app-based auth excluded from CA, and break-glass account misuse. | 65 65 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
k8s-rbac-abuse packages/decepticon/decepticon/skills/standard/cloud/container/k8s-rbac-abuse/SKILL.md Kubernetes RBAC privilege escalation paths — ClusterRole/Role enumeration via `kubectl auth can-i --list`, abuse of pods/exec, pods/portforward, secrets get, escalate verb, bind verb, impersonate verb, system:masters group abuse, ServiceAccount token theft and reuse. | 68 68 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
k8s-pod-escape packages/decepticon/decepticon/skills/standard/cloud/container/k8s-pod-escape/SKILL.md Kubernetes pod escape to node — privileged container abuse, hostPath mount escape, hostPID/hostIPC, capability misuse (SYS_ADMIN, SYS_PTRACE), runC CVE chains. Pivots from RCE-in-pod to full node compromise. | 65 65 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
docker-socket-mount packages/decepticon/decepticon/skills/standard/cloud/container/docker-socket-mount/SKILL.md Docker / containerd socket mounted into a container → host RCE. Common in CI runners, GitOps controllers (ArgoCD, Flux), and 'Docker-in-Docker' setups. Single-command escape via `docker run --rm --privileged -v /:/host alpine chroot /host`. | 65 65 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
container-cve packages/decepticon/decepticon/skills/standard/cloud/container/container-cve/SKILL.md High-impact container-runtime CVE catalog — runC Leaky Vessels (CVE-2024-21626/-23651/-23652/-23653), CVE-2022-0185 (FUSE/legacy-fs), CVE-2019-5736 (runC binary replace), CRI-O Dirty COW analogs, Kubernetes API server CVE-2019-11247 (custom-resource RBAC bypass). Fingerprint → match → exploit. | 65 65 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
container-overview packages/decepticon/decepticon/skills/standard/cloud/container/SKILL.md Container / Kubernetes attack category — pod escape, RBAC abuse, runtime CVE exploitation, socket-mount escape. Routing skill: identify the surface (pod-internal RCE vs API-level vs build-pipeline), then load the matching sub-skill. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
azure-managed-identity packages/decepticon/decepticon/skills/standard/cloud/azure-managed-identity/SKILL.md Azure Managed Identity abuse — IMDS at 169.254.169.254 from compromised VM / App Service / Function, token exchange for Graph/ARM/KeyVault, federated workload identity abuse, hybrid AAD Connect MSOL credential extraction. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aws-iam-passrole-chain packages/decepticon/decepticon/skills/standard/cloud/aws-iam-passrole-chain/SKILL.md AWS IAM privilege escalation via `iam:PassRole` chains — Lambda/Glue/Sagemaker/EC2/ECS PassRole to a higher-priv role, AssumeRole chains across accounts, sts:GetCallerIdentity recon, account hijack via legacy root-mfa-bypass. | 67 67 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
aws-iam-enum packages/decepticon/decepticon/skills/standard/cloud/aws-iam-enum/SKILL.md Enumerate AWS IAM policies, detect privilege escalation paths per Rhino Security Labs canonical 21 primitives. | 55 55 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
cloud-overview packages/decepticon/decepticon/skills/standard/cloud/SKILL.md Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
xxe packages/decepticon/decepticon/skills/standard/analyst/xxe/SKILL.md Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls. | 57 57 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
vector-and-embedding-weaknesses packages/decepticon/decepticon/skills/standard/analyst/vector-and-embedding-weaknesses/SKILL.md Hunt vector / embedding weaknesses (OWASP LLM08:2025) — adversarial inputs against the RAG / similarity layer that cause cross-tenant leak, embedding-inversion privacy loss, semantic confusion, and retriever-driven prompt injection. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
unbounded-consumption packages/decepticon/decepticon/skills/standard/analyst/unbounded-consumption/SKILL.md Hunt LLM unbounded consumption (OWASP LLM10:2025) — denial-of-wallet and denial-of-service against LLM endpoints via unrestricted prompt size, runaway tool loops, expensive model selection, and unauthenticated fan-out. | 67 67 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
trust-boundary-analysis packages/decepticon/decepticon/skills/standard/analyst/trust-boundary/SKILL.md Trust boundary mapping and startup sequence audit for developer tools, CLI apps, and plugin systems. Load when the target is a developer tool, CLI, IDE extension, or any application that loads config from the current directory. | 69 69 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
ti-yara-hunting packages/decepticon/decepticon/skills/standard/analyst/ti-yara-hunting/SKILL.md YARA rule writing from behavioral observations and TI report analysis — sample-to-rule conversion, condition optimization, performance tuning, and retrohunting on VirusTotal and ANY.RUN. Covers YARA/YARA-X syntax, yarGen automated generation, and production rule deployment. | 61 61 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 0cf691e | |
ti-ioc-extraction packages/decepticon/decepticon/skills/standard/analyst/ti-ioc-extraction/SKILL.md Automated IOC extraction from threat reports, logs, and unstructured text — parse hashes, IPs, domains, URLs, email addresses, and CVEs. Covers regex-based extraction, defanging/refanging, bulk hash lookup, IOC deduplication, YARA rule generation from IOCs, and STIX/TAXII formatting for sharing. | 61 61 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 0cf691e | |
ti-anyrun-lookup packages/decepticon/decepticon/skills/standard/analyst/ti-anyrun-lookup/SKILL.md ANY.RUN Threat Intelligence Lookup workflow — query hashes, domains, IPs, and behavioral indicators against ANY.RUN's sandbox corpus. Covers TI Lookup query syntax, search operators, free tier constraints, result correlation with engagement findings, and integration with sandbox analysis. | 63 63 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 0cf691e | |
system-prompt-leakage packages/decepticon/decepticon/skills/standard/analyst/system-prompt-leakage/SKILL.md Hunt LLM system-prompt leakage (OWASP LLM07:2025) — exfiltration of the privileged system prompt revealing internal rules, secrets baked in, tool inventory, and business logic that should not be client-visible. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
supply-chain packages/decepticon/decepticon/skills/standard/analyst/supply-chain/SKILL.md Hunt LLM supply-chain compromise (OWASP LLM03:2025) — malicious or backdoored models, datasets, adapters, plugins, MCP servers, and tokenizer / framework dependencies that ship inside an AI-integrated product. | 62 62 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
ssti packages/decepticon/decepticon/skills/standard/analyst/ssti/SKILL.md Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution. | 63 63 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
ssrf packages/decepticon/decepticon/skills/standard/analyst/ssrf/SKILL.md Hunt Server-Side Request Forgery (CWE-918) through taint analysis from user-controlled URLs to HTTP client sinks. Covers cloud metadata pivoting, DNS rebinding, gopher smuggling, and the IMDSv1 → IAM role chain that turns SSRF into RCE. | 66 66 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
sql-injection packages/decepticon/decepticon/skills/standard/analyst/sql-injection/SKILL.md Hunt SQL injection (CWE-89) via source-level taint tracking. Covers string concat, format-string, ORM raw queries, second-order injection, and NoSQL injection in MongoDB/DynamoDB. | 69 69 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
sensitive-information-disclosure packages/decepticon/decepticon/skills/standard/analyst/sensitive-information-disclosure/SKILL.md Hunt LLM sensitive-information disclosure (OWASP LLM02:2025) — leakage of PII, secrets, internal source, model details, and other-tenant data through model outputs, training-data extraction, or retrieval-side joins. | 61 61 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
redos packages/decepticon/decepticon/skills/standard/analyst/redos/SKILL.md Hunt ReDoS (CWE-1333, Catastrophic Backtracking) — identify regexes with nested quantifiers or overlapping alternation that cause super-linear matching time, trace tainted input paths to regex sinks, demonstrate timing PoC, and validate with response-time delta. Covers PCRE/RE2/V8/Python re engine differences. Triggers on: 'ReDoS', 'regex denial', 'catastrophic backtracking', 'redos', 'regex complexity', 'nested quantifiers', 'regex amplification', 'CWE-1333'. | 73 73 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e | |
prototype-pollution packages/decepticon/decepticon/skills/standard/analyst/prototype-pollution/SKILL.md Hunt JavaScript prototype pollution (CWE-1321) — the 2023-2026 meta-vulnerability that chains into RCE, auth bypass, and SSRF on most Node.js stacks. | 58 58 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 0cf691e |