lhuciverjobs-ui

110 mods across 1 repository, 24 stars between them.

type-juggling

97

lhuciverjobs-ui/fox

Skill Claude CodeCodex

PHP type juggling and weak comparison (==) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.

not rated 24 1mo ago A 54 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Custom VM and bytecode reverse engineering playbook. Use when CTF challenges or protected software implement custom virtual machines with proprietary bytecode, dispatcher loops, or maze-style challenges.

not rated 24 1mo ago A 42 tokens

waf-bypass-techniques

101

lhuciverjobs-ui/fox

Skill Claude CodeCodex

WAF bypass methodology and generic evasion techniques. Use when a web application firewall blocks injection payloads (SQLi, XSS, RCE) and you need to craft bypasses using encoding, protocol-level tricks, or WAF-specific weaknesses.

not rated 24 1mo ago A 57 tokens

web-cache-deception

102

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Web cache deception and poisoning playbook. Use when CDN, reverse proxy, or application caching may serve sensitive authenticated content to other users due to path confusion or cache key manipulation.

not rated 24 1mo ago A 40 tokens

websocket-security

103

lhuciverjobs-ui/fox

Skill Claude CodeCodex

WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.

not rated 24 1mo ago A 46 tokens

windows-av-evasion

104

lhuciverjobs-ui/fox

Skill Claude CodeCodex

AV/EDR evasion playbook for Windows. Use when bypassing AMSI, ETW, .NET assembly detection, shellcode execution, process injection, API hooking, and signature-based detection on Windows endpoints.

not rated 24 1mo ago A 49 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Windows lateral movement playbook. Use when pivoting between Windows hosts via PsExec, WMI, WinRM, DCOM, RDP, pass-the-hash, overpass-the-hash, or pass-the-ticket techniques.

not rated 24 1mo ago B 52 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

Windows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to escalate via token abuse, Potato exploits, service misconfigurations, DLL hijacking, UAC bypass, or registry autoruns.

not rated 24 1mo ago A 56 tokens

xslt-injection

107

lhuciverjobs-ui/fox

Skill Claude CodeCodex

XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.

not rated 24 1mo ago A 56 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

XSS playbook. Use when user-controlled content reaches HTML, attributes, JavaScript, DOM sinks, uploads, or multi-context rendering paths.

not rated 24 1mo ago A 36 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

XXE playbook. Use when XML, SVG, OOXML, SOAP, or parser-driven imports may resolve external entities, files, or internal network resources.

not rated 24 1mo ago F 41 tokens

lhuciverjobs-ui/fox

Skill Claude CodeCodex

This skill should be used when the user asks to "run xerxes", "ddos tool", "stress test website", "flood attack", "test network resilience", "xerxes gauntlet", "take down site", "bikin website down", "proxy flood", "amplification attack", "syn flood", "udp flood", "slowloris", "http flood", "multi-vector attack"…

not rated 24 1mo ago A 136 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: