liuxinye23

57 mods across 1 repository, 0 stars between them.

ctf-binary-bundle

25

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

Bundle skill for CTF binary triage and solve routing. Use when the prompt mentions ELF, nc services, memory corruption, WASM reversing, native binaries, or uncertain binary challenge direction and Codex should coordinate the core CTF binary skills before deeper specialization.

0 29d ago A 59 tokens original Apache-2.0

ctf-skills

26

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A general workflow for solving CTF challenges, which are security puzzles that award a hidden flag when solved. It first sorts a challenge into Web, Crypto, Pwn, Reverse, Forensics, or Misc categories.

0 29d ago A 47 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

An example security-testing skill package with instructions, scripts, reference files, and assets, demonstrated through Eino and HTTP interfaces.

0 29d ago A 48 tokens copy · 100% Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A code-review guide for checking package versions, lock files, container images, build scripts, and where software dependencies come from.

0 29d ago A 27 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A guide to testing deserialization vulnerabilities, which can occur when software turns untrusted saved data back into objects.

0 29d ago A 16 tokens original Apache-2.0

elf-pwn-triage

30

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A first-pass guide for analysing ELF programs, the executable format commonly used on Linux, in capture-the-flag exploitation challenges.

0 29d ago A 39 tokens original Apache-2.0

file-upload-testing

31

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A guide for testing whether a website’s file-upload feature safely checks file names, contents, types, sizes, and storage paths.

0 29d ago B 14 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

Bundle skill for digital forensics and artifact-first triage. Use when requests involve PCAPs, stego, suspicious images, metadata, extracted files, or mixed forensic artifacts and Codex should coordinate the initial triage skills before deeper analysis.

0 29d ago A 57 tokens original Apache-2.0

idor-testing

33

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A guide to testing IDOR, a web security flaw where changing a user-supplied identifier can expose someone else’s file or record. It covers checks for horizontal access between users and vertical access to administrator resources.

0 29d ago A 18 tokens original Apache-2.0

incident-response

34

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A structured process for handling security incidents, from detecting a problem through containment, cleanup, recovery, and lessons learned.

0 29d ago A 12 tokens original Apache-2.0

jwt-ctf-review

35

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A workflow for reviewing JWTs and other login or session tokens in CTF challenges. JWTs are signed text tokens that can carry information such as a user role or expiration time.

0 29d ago A 37 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A security-testing guide for LDAP injection, where unescaped user input changes a directory search or login query. LDAP is a system commonly used to store and look up users and permissions.

0 29d ago A 16 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A methodology for testing the security of Android and iOS mobile applications. It covers the app itself, stored and transmitted data, authentication, permissions, sessions and network communications.

0 29d ago A 15 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A guide for testing whether web APIs—the endpoints software uses to exchange data—handle identity, permissions, input, business rules, and errors safely.

0 29d ago A 17 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A review process for OpenAPI or Swagger documents, which describe how JSON-based web APIs work. It checks authentication, permissions, input fields, errors and high-impact operations against the documented contract.

0 29d ago A 35 tokens original Apache-2.0

pcap-triage

40

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A first-pass guide for examining PCAP files, which are recorded network conversations, and network logs from capture-the-flag challenges.

0 29d ago A 42 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A security review for finding exposed secrets and sensitive settings in websites, front-end files, backups, history pages, and public resources. It distinguishes usable passwords, keys, and tokens from harmless public identifiers.

0 29d ago A 32 tokens original Apache-2.0

secure-code-review

42

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A checklist and method for reviewing code for security weaknesses. It covers input checks, safe output, authentication, permissions, encryption, error handling, logging, and common vulnerability patterns.

0 29d ago A 14 tokens original Apache-2.0

security-automation

43

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A security-automation guide for organising repeated vulnerability scans, security tests, incident responses, and compliance checks.

0 29d ago A 13 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A security-awareness training guide for teaching people how to recognize and avoid common security risks. It covers passwords, accounts, phishing emails, social engineering, data handling, and physical security.

0 29d ago A 13 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A checklist for reviewing HTTP response headers, browser rules sent by a website that control scripts, cross-site access, caching, and page isolation.

0 29d ago A 29 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A method for checking web applications for SQL injection, a flaw where user input can change a database query.

0 29d ago A 15 tokens original Apache-2.0

ssrf-testing

47

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A guide to testing SSRF, a flaw where a server can be tricked into requesting a URL chosen by a user. It covers URL previews, webhooks, proxies, imports, image processing, and PDF generation.

0 29d ago C 19 tokens original Apache-2.0

liuxinye23/CyberStrikeAI

Skill Claude CodeCodex

A review guide for server-side template injection, where user-controlled text is mistakenly treated as template code by a web application. It is aimed at capture-the-flag challenges and deliberately vulnerable practice targets.

0 29d ago A 36 tokens original Apache-2.0