lhuciverjobs-ui

110 mods across 1 repository, 24 stars between them.

lhuciverjobs-ui/fox

Skill Claude CodeCodex

OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.

not rated 24 1mo ago A 45 tokens

open-redirect

74

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Open redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users to attacker-controlled destinations.

not rated 24 1mo ago C 33 tokens

path-traversal-lfi

75

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Path traversal and LFI playbook. Use when file paths, download endpoints, include operations, archive extraction, or wrapper behavior may expose filesystem control.

not rated 24 1mo ago C 37 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Advanced prototype pollution playbook — server-side RCE, client-side gadgets, filter bypasses, and detection techniques. Companion to ../prototype-pollution/ for basics. Use when you've confirmed pollution and need to escalate to code execution or find framework-specific gadgets.

not rated 24 1mo ago A 59 tokens

prototype-pollution

77

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Prototype pollution testing for JavaScript stacks. Use when user input is merged into objects (query parsers, JSON bodies, deep assign), when configuring libraries via untrusted keys, or when hunting RCE gadgets via polluted Object.prototype in Node or the browser.

not rated 24 1mo ago A 56 tokens

race-condition

78

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Race condition and TOCTOU testing for web apps. Use when testing one-time operations, concurrent HTTP abuse, rate-limit bypass, Turbo Intruder gates, HTTP/2 single-packet attacks, and CWE-362-style synchronization gaps.

not rated 24 1mo ago A 50 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fingerprinting technology, and building a structured testing plan for a new target.

not rated 24 1mo ago C 37 tokens

recon-for-sec

80

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Entry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.

not rated 24 1mo ago A 41 tokens

request-smuggling

81

lhuciverjobs-ui/fox

Skill Claude CodeCodex

HTTP request smuggling and desynchronization testing. Use when front proxies, CDNs, or load balancers disagree with the origin on message framing (Content-Length vs Transfer-Encoding), on HTTP/2→HTTP/1 translation, or when exploring client-side desync via browser fetch pipelines.

not rated 24 1mo ago B 62 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

One-liner reverse shell cheatsheet for 20+ languages and tools. Copy-paste ready payloads with ATTACKER/PORT placeholders.

not rated 24 1mo ago A 35 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to recover plaintext by exploiting weak keys, small exponents, shared factors, or padding oracles.

not rated 24 1mo ago A 53 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

not rated 24 1mo ago A 44 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Sandbox escape playbook. Use when breaking out of Python sandbox, Lua sandbox, seccomp filter, chroot jail, container/Docker, browser sandbox, or namespace isolation to achieve unrestricted code execution or file access.

not rated 24 1mo ago E 49 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack patterns.

not rated 24 1mo ago A 46 tokens

sqli-sql-injection

87

lhuciverjobs-ui/fox

Skill Claude CodeCodex

SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.

not rated 24 1mo ago A 39 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.

not rated 24 1mo ago E 45 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

SSTI playbook. Use when template expressions, server-side rendering, preview features, or templating engines may evaluate attacker-controlled content.

not rated 24 1mo ago B 36 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Stack overflow and ROP playbook. Use when exploiting buffer overflows to hijack control flow via return address overwrite, ROP chains, ret2libc, ret2csu, ret2dlresolve, or SROP on Linux userland binaries.

not rated 24 1mo ago A 59 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Steganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audio (spectrogram, DTMF), files (polyglots, appended data, ADS), and text (whitespace, zero-width, homoglyphs) for hidden data.

not rated 24 1mo ago A 70 tokens

subdomain-takeover

92

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned cloud resources, expired third-party services, or unclaimed SaaS tenants that an attacker can register to serve content under the victim's domain.

not rated 24 1mo ago A 61 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Symbolic execution and constraint solving playbook. Use when solving CTF reversing challenges, recovering keys, bypassing checks, or automating binary analysis with angr, Z3, or Unicorn Engine.

not rated 24 1mo ago A 45 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Symmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-and-paste, bit flipping), stream cipher key reuse, or meet-in-the-middle attacks.

not rated 24 1mo ago A 47 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Traffic analysis and PCAP forensics playbook. Use when analyzing network captures including Wireshark filters, protocol analysis (HTTP/DNS/FTP/SMTP/USB/WiFi), data extraction, covert channel detection, PCAP repair, TLS decryption, and tshark command-line analysis.

not rated 24 1mo ago D 64 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.

not rated 24 1mo ago B 59 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: