forefy

30 mods across 1 repository, 133 stars between them.

forefy/.context

Instructions file GitHub Copilot

Instructions for forefy/.context: This repo contains instruction files for using and conducting security reviews, do not confuse this copilot-instructions.md from other copilot-instructions files existing in this workspace.

133 5d ago A 125 tokens original MIT

.context CLAUDE.md

02

forefy/.context

Instructions file

Instructions for forefy/.context: This repo contains instruction files for using and conducting security reviews, do not confuse this CLAUDE.md from other copilot-instructions files existing in this workspace.

133 5d ago A 124 tokens copy · 94% MIT

forefy/.context

Skill Claude CodeCodex

Replay captured requests with swapped identities and bumped object IDs to surface broken access control. Use when testing for IDOR or authz flaws.

133 5d ago A 31 tokens original MIT

cdn-peek

04

forefy/.context

Skill Claude CodeCodex

Uncover the real origin IP behind a CDN or WAF like Cloudflare, using only standard tools. Use to bypass a CDN/WAF or check if an origin leaks.

133 5d ago C 39 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Detect HTTP request smuggling by desynchronising front-end and back-end request parsing, using raw-socket timing and differential probes. Use when testing for HTTP desync (CL.TE, TE.CL).

133 5d ago A 46 tokens original MIT

jwt-attacks

06

forefy/.context

Skill Claude CodeCodex

Forge and re-sign captured JWTs to test signature validation - algorithm confusion (alg:none, RS256 to HS256), key injection, and secret cracking. Use when testing JWT or bearer-token auth.

133 5d ago A 44 tokens original MIT

ssrf-oob

07

forefy/.context

Skill Claude CodeCodex

Prove blind SSRF by injecting an out-of-band callback into URL params and forwarding headers, then watching for the hit. Use when testing for SSRF.

133 5d ago A 37 tokens original MIT

webapp-probe

08

forefy/.context

Skill Claude CodeCodex

Probe a web app for what it exposes or leaks - passively from captured traffic and actively against the target. Use to assess a web app's exposure or review Burp/ZAP history.

133 5d ago C 43 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Expert blockchain forensics assistant for investigators and auditors, including threat recognition, incident scoping, data collection, transaction tracking, chain analysis, attribution, OSINT, advanced demixing, cross-chain tracing, graph clustering, and reporting.

133 5d ago A 51 tokens original MIT

foundry-poc

10

forefy/.context

Skill Claude CodeCodex

Generates a Foundry PoC for smart contracts that scientifically proves the path from no special privileges to funds lost. Focused on proof of concept for EVM using forge test.

133 5d ago A 42 tokens original MIT

safe-hunt

11

forefy/.context

Skill Claude CodeCodex

Sweeps DeFi protocol Safe multisig wallets for governance misconfigurations and security weaknesses. Given a protocol name, Safe address, or "sweep all", fetches live config and tx history from the Safe Transaction Service API, scores each Safe against a finding pattern library, and produces an audit-ready ranked…

133 5d ago A 92 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Comprehensive smart contract security audit framework with multi-expert analysis. Use for full audits of Ethereum / EVM Solidity and Vyper, Solana / SVM Anchor Rust, TON / FunC / Tact, or Sui / Move projects.

133 5d ago A 55 tokens original MIT

cloud-bucket-brute

13

forefy/.context

Skill Claude CodeCodex

Discover publicly readable cloud storage by permuting a company name into likely bucket names and probing AWS S3, Google Cloud, DigitalOcean, Alibaba, Oracle, and Vultr. Use to find exposed buckets.

133 5d ago A 47 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. Use for full infrastructure audits.

133 5d ago A 29 tokens original MIT

dylib-hijack-scan

15

forefy/.context

Skill Claude CodeCodex

Scan macOS for hijackable dynamic libraries, separating exploitable privesc hijacks from harmless ones. Use to check if an app is hijackable.

133 5d ago A 42 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Hunt a live macOS, Linux, or Windows endpoint for malware across process, network, and persistence. Use to scan for threats or check for compromise.

133 5d ago A 37 tokens original MIT

agent-onboarding

17

forefy/.context

Skill Claude CodeCodex

Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md. Use when joining the team on a shared codebase.

133 5d ago A 35 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Takes the active conversation as reference to understand how a skill can be created, with all the lessons learned from the user's needs in the conversation.

133 5d ago A 35 tokens original MIT

git-commit

19

forefy/.context

Skill Claude CodeCodex

Commit to Git safely: runs tests, security-reviews the diff, strips secrets and dead code, and enforces clean messages. Use before any commit or push.

133 5d ago A 37 tokens original MIT

training-guide

20

forefy/.context

Skill Claude CodeCodex

Build an interactive visual course as one self-contained HTML page, one idea per screen. Use to explain or teach a subject visually, step by step.

133 5d ago A 33 tokens original MIT

variant-table

21

forefy/.context

Skill Claude CodeCodex

Lay draft copy out as a table with three distinct rewrites per line and a top pick. Use to compare wording for posts, headlines, CTAs, or microcopy.

133 5d ago A 38 tokens original MIT

audit-scope

22

forefy/.context

Skill Claude CodeCodex

Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. Use when scoping a new engagement.

133 5d ago A 35 tokens original MIT

auditor-quiz

23

forefy/.context

Skill Claude CodeCodex

Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs. Use to test understanding before or during a review.

133 5d ago A 35 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. Use to recon an external attack surface or enumerate subdomains.

133 5d ago A 37 tokens original MIT