lhuciverjobs-ui

60 mods across 1 repository, 24 stars between them.

ad-agent

01

lhuciverjobs-ui/fox

Agent

Own the Windows domain — from low-privilege user to Domain Admin.

24 1mo ago A 0 tokens

mobile-agent

02

lhuciverjobs-ui/fox

Agent

Breach mobile applications — Android & iOS — through reverse engineering, traffic interception, and runtime manipulation.

24 1mo ago C 0 tokens

recon-agent

04

lhuciverjobs-ui/fox

Agent

Full-spectrum reconnaissance — find everything about a target before the attack begins.

24 1mo ago C 0 tokens

swarm

05

lhuciverjobs-ui/fox

Agent

Orchestrate parallel attacks across multiple targets, agents, and vectors simultaneously. Swarm mode turns Fox from a solo operator into a coordinated attack force.

24 1mo ago A 0 tokens

web-agent

06

lhuciverjobs-ui/fox

Agent

Breach web applications through every injection and misconfiguration vector.

24 1mo ago A 0 tokens

fox-dorker

07

lhuciverjobs-ui/fox

Skill Claude CodeCodex

This skill should be used when the user asks to 'run dorks', 'dorking', 'Google dork', 'search for vulnerable sites', 'find SQLi sites', 'harvest URLs', 'mass dorking', 'ClownSearcher', 'batch dork', 'list dork', 'inurl:', 'intext:', or needs to automate search engine dorking for target recon. Inspired by…

24 1mo ago A 107 tokens

fox-sqli

08

lhuciverjobs-ui/fox

Skill Claude CodeCodex

This skill should be used when the user asks to "sql inject", "dump database", "sqli", "error based injection", "union select sqli", "enumerate tables", "extract data from sql", "WAF bypass sqli", "DIOS injection", "fox-sqli.py", or needs automated SQL injection with UNION SELECT variants, error-based GROUP BY…

24 1mo ago A 126 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP method tampering, header injection, protocol downgrade, and automated bypass tools.

24 1mo ago A 53 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS reading, GPO abuse, and BloodHound-guided attack paths.

24 1mo ago A 54 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to enrollment, CA officer abuse, and certificate-based persistence.

24 1mo ago A 47 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets, delegation abuse, or pass-the-ticket attacks.

24 1mo ago A 48 tokens

ai-ml-security

13

lhuciverjobs-ui/fox

Skill Claude CodeCodex

AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.

24 1mo ago B 53 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.

24 1mo ago A 53 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.

24 1mo ago A 46 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

24 1mo ago A 41 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

API authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or weak function-level authorization.

24 1mo ago A 36 tokens

api-recon-and-docs

18

lhuciverjobs-ui/fox

Skill Claude CodeCodex

API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.

24 1mo ago A 38 tokens

api-sec

19

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Entry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter workflows before any deeper API topic skill.

24 1mo ago A 36 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Arbitrary write to RCE playbook. Use when you have an arbitrary write primitive (from heap exploitation, format string, or OOB write) and need to convert it into code execution by targeting GOT, hooks, IOFILE vtable, exitfuncs, TLSdtorlist, modprobepath, .finiarray, or C++ vtables.

24 1mo ago B 80 tokens

auth-sec

21

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OAuth, CORS, CSRF, and enterprise SSO weaknesses before any deeper auth topic skill.

24 1mo ago A 46 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

24 1mo ago A 43 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Binary protection bypass playbook. Use when identifying and bypassing ASLR, PIE, NX/DEP, stack canary, RELRO, FORTIFYSOURCE, CET, and MTE protections in ELF binaries to enable exploitation.

24 1mo ago A 52 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Browser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities including JIT type confusion, incorrect bounds elimination, and V8 sandbox bypass to achieve renderer RCE and sandbox escape in Chrome/Chromium.

24 1mo ago A 50 tokens