攻击面枚举专员
01Agent
A planning agent for authorized security assessments that organizes reconnaissance results into a map of services, technologies, dependencies, and possible entry points. It does not perform attacks or destructive checks.
Agent
A planning agent for authorized security assessments that organizes reconnaissance results into a map of services, technologies, dependencies, and possible entry points. It does not perform attacks or destructive checks.
Agent
A cleanup and rollback planning agent for authorized security testing. It lists possible test remnants, the order for reversing changes, and evidence that shows cleanup was completed.
Agent
A planning agent for authorized security assessments. It defines the test scope, rules of engagement, success criteria, evidence requirements, and an iterative test plan without carrying out attacks.
Agent
A security-assessment agent that designs minimal, auditable evidence for proving business impact and data reach without exposing real sensitive data.
Agent
A role definition for an information-gathering security subagent. It collects publicly available information about an explicitly identified, authorized target, such as domains, exposed services, technologies, interfaces, and possible leaks.
Agent
A specialist agent for analysing movement between systems inside a private network after an initial access point has been obtained. A private network is an organisation's internal set of connected computers and services.
Agent
A security-testing planning agent focused on reducing noise and disruption while collecting evidence. It requires the target, scope, and testing rules before suggesting actions.
Agent
A planning agent for authorized, non-destructive security testing. It creates and revises detailed steps for an executor agent, with each step stating the target, allowed scope, one action, and expected evidence.
Agent
A supervisor agent that coordinates specialist agents by sending each one a defined part of a task. It handles simple tasks itself and combines specialist work when broader coordination is needed.
Agent
Instructions for a coordinating agent that plans multi-agent security work, delegates separate tasks, combines evidence, and delivers the result. A multi-agent workflow uses several specialized agents on parts of one job.
Agent
An authorized penetration-testing agent for checking whether identified security weaknesses can be verified and used within a defined scope. Penetration testing is a controlled security assessment of a system.
Agent
A security-assessment role for evaluating ways authorized access might persist or remain reusable, while keeping the work low-impact and reversible.
Agent
An authorized security-assessment agent for examining whether a user with limited access might reach higher privileges. Privilege escalation means gaining permissions beyond the current account or session.
Agent
A reconnaissance agent for authorized security assessments. Reconnaissance means collecting information about a specified system, such as domains, services, paths, and other parts of its exposed attack surface.
Agent
A report-writing agent that turns collected security-testing evidence into a structured report. It also gives high-level repair suggestions and checks for verifying those repairs.
Agent
Nástroj na triedenie možných bezpečnostných chýb podľa dostupných dôkazov a návrh bezpečných spôsobov ich overenia.
Skill Claude CodeCodex
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
Skill Claude CodeCodex
内网域攻击:BloodHound,Kerberoast,ADCS ESC1/ESC8,NTLM Relay,Coerce,DACL,DCSync,Zerologon/NoPac/PrintNightmare,mitm6,LLMNR,Linux内网。Use when attacking Active Directory, ADCS, NTLM relay, or internal domain.
Skill Claude CodeCodex
AI/LLM应用攻击:提示注入,Agent工具滥用RCE,RAG投毒,MCP供应链,torch.load pickle RCE。Use when testing LLM apps, agents, RAG, MCP plugins, or AI model file risks.
Skill Claude CodeCodex
侦察/攻击面测绘:被动whois/amass/crt.sh/FOFA/Shodan,主动subfinder/httpx/naabu/katana/nuclei,DNS地域/CDN/Nginx catch-all/宝塔/UniApp指纹。开局第一动作,认知写入项目黑板。Use when starting recon, asset mapping, fingerprinting, or CDN/DNS bypass discovery.
Skill Claude CodeCodex
APK/EXE/二进制:UniApp/DCloud/Flutter逆向,证书固定绕过,导出组件,内存破坏exploit链,IoT固件。Use when reversing APK/EXE, UniApp/Flutter, native .so, or memory-corruption exploits.
Skill Claude CodeCodex
Postupy na kontrolu blockchainov a inteligentných zmlúv, čo sú programy, ktoré automaticky vykonávajú pravidlá transakcií.
Skill Claude CodeCodex
A method for finding attack chains by combining smaller capabilities such as reading files, writing files, making server requests, or using credentials. It treats a serious outcome as a sequence of separately gained abilities.
Skill Claude CodeCodex
云攻击:元数据API,S3/K8s,AWS/Azure/GCP身份提权,MinIO矩阵,阿里云FC,ChengZi SDK解密。Use when attacking cloud metadata, IAM, K8s, MinIO, Aliyun FC, or cloud post-ex.