akashrpatil/awesome-offensive-security-skills
Plugin Claude Code
191 battle-tested offensive security skills for AI agents — Bug Hunting, Pentesting, Red Teaming, AI Red Teaming, Incident Response.
akashrpatil/awesome-offensive-security-skills
Plugin Claude Code
191 battle-tested offensive security skills for AI agents — Bug Hunting, Pentesting, Red Teaming, AI Red Teaming, Incident Response.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with variance analysis, or optimize a skill's description for better triggering accuracy.
akashrpatil/awesome-offensive-security-skills
Agent
Analyze blind comparison results to understand WHY the winner won and generate improvement suggestions.
akashrpatil/awesome-offensive-security-skills
Agent
Compare two outputs WITHOUT knowing which skill produced them.
akashrpatil/awesome-offensive-security-skills
Agent
Evaluate expectations against an execution transcript and outputs.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Identify and simulate Data Poisoning attacks aimed at degrading or skewing an AI model's accuracy. This skill focuses on Adversarial Machine Learning concepts where attackers inject malicious or mislabelled data points into training or fine-tuning datasets (e.g., feedback loops) to bias the AI.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Test AI agent systems for tool abuse, unauthorized actions, privilege escalation through tool chaining, and safety bypass via agentic workflows. Use this skill when assessing autonomous AI agents that use tool-calling (function calling, plugins, actions) to interact with external systems. Covers multi-step attack…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Test Model Context Protocol (MCP) servers and tool-calling systems for security vulnerabilities including tool injection, parameter manipulation, privilege escalation, and data exfiltration through AI agent tool interfaces. Use this skill when assessing MCP server implementations, AI agent tool integrations, or any…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Analyze and detect synthetic media, including deepfake videos, AI-generated images, and cloned voice audio. Use this skill when investigating potential disinformation campaigns, verifying the authenticity of digital evidence, or assessing social engineering attacks leveraging synthetic media (e.g., vishing with voice…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Test Large Language Models for direct prompt injection vulnerabilities where user input overrides system instructions, extracts system prompts, bypasses safety filters, or causes unauthorized actions. Use this skill when assessing chatbots, AI assistants, LLM-powered tools, or any application that processes natural…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Test for indirect prompt injection vulnerabilities where malicious instructions are injected through external data sources (websites, emails, documents, database records) that the LLM processes. Use this skill when assessing LLM-integrated applications that process user-generated content, retrieve web pages, parse…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Systematically bypass LLM safety filters and content moderation systems using advanced jailbreaking techniques. Use this skill when testing AI systems for safety alignment robustness, evaluating content moderation effectiveness, or conducting authorized AI red team assessments. Covers role-play attacks, few-shot…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Simulate supply chain and adversarial machine learning attacks by injecting poisoned data or targeted backdoors into training and fine-tuning datasets. Use this skill when assessing the integrity controls of MLOps pipelines or evaluating the resilience of AI models against highly targeted, stealthy manipulation…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Test Retrieval-Augmented Generation (RAG) systems for data poisoning, prompt injection via retrieved documents, and data exfiltration through manipulated context windows. Use this skill when assessing RAG-based chatbots, knowledge bases, enterprise AI assistants, or any system that augments LLM responses with external…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Exploit AI assistants equipped with web-browsing capabilities or internal API plugins to perform Server-Side Request Forgery (SSRF). This skill details injecting prompts that force the LLM to request sensitive internal endpoints, such as underlying cloud metadata services or internal networks.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Execute and analyze AI Data Poisoning attacks. By subtly injecting malicious or targeted misinformation into an LLM's training or fine-tuning dataset, an attacker can covertly manipulate the model's future outputs, implant backdoors, or enforce biases without altering the model architecture.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Bypass AI safety filters by encoding malicious prompts using ciphers and obfuscation techniques (e.g., Base64, ROT13, Leetspeak, Morse code). This skill exploits the gap where the LLM can decode the request, but intermediate keyword-based safety classifiers cannot.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Execute sophisticated Prompt Injection and Jailbreak techniques against Large Language Models (LLMs) to bypass safety filters, extract system prompts, and manipulate the AI's output to perform malicious or disallowed actions.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Advanced techniques for bypassing LLM safety filters, instruction tuning, and system prompt restrictions using specialized linguistic constructs, hypothetical scenarios, and persona adoption.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Systematically extract hidden system prompts, core directives, and invisible context intentionally concealed within Large Language Model (LLM) applications. This skill utilizes targeted linguistic engineering and boundary manipulation to bypass prompt opacity.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Execute sophisticated Data Extraction and Privacy Leakage attacks explicitly against Large Language Models (LLMs) to natively force the neural network entirely into organically regurgitating exact, verbatim strings of Highly Confidential Personally Identifiable Information (PII), proprietary source code, or…
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Exploit an application's absolute trust in its underlying LLM (Overreliance). Use this skill to induce critical "hallucinations" (confident falsehoods) that cause downstream logical systems or automated agents tracking the LLM's output to make destructive actions or grant unauthorized access.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Exploit AI applications using Indirect Prompt Injection. This skill focuses on hiding malicious instructions within data sources (web pages, documents, emails) that the LLM processes, causing the AI to execute unintended actions or leak data without direct user interaction.
akashrpatil/awesome-offensive-security-skills
Skill Claude CodeCodex
Extract sensitive training data (PII, API keys, intellectual property, or code) directly from a deployed Large Language Model (LLM). This AI Red Teaming skill focuses on forcing models to regurgitate memorized, unredacted data from their massive internet-scraped datasets through repetition attacks, prefix…