Rifteo

38 mods across 1 repository, 34 stars between them.

less-noise-attack

25

Rifteo/skills

Skill Claude CodeCodex

Runs offensive work in a low-noise mode — passive recon first, minimal footprint, and only deliberate, targeted active actions that blend with legitimate traffic, so the engagement stays below detection thresholds. Not the default; activate only when the user explicitly signals stealth as the priority, e.g. "stay…

34 18d ago A 93 tokens original MIT

Rifteo/skills

Skill Claude CodeCodex

Convert a vulnerability description or HTTP request/response pair into a ready-to-run Nuclei YAML template handles auth strategies, matcher selection, OOB detection, and multi-step flows. Trigger when the user found a vulnerability and wants to automate detection on other targets, pastes an HTTP request/response and…

34 18d ago A 104 tokens original MIT

pentest-report

27

Rifteo/skills

Skill Claude CodeCodex

Generates a complete, client-ready penetration test report from all findings in the current engagement executive summary, risk table, technical findings, and recommendations. Trigger when the user says "generate the report", "write the report", or "produce the deliverable", is at the end of an engagement with all…

34 18d ago A 83 tokens original MIT

redirect-forge

28

Rifteo/skills

Skill Claude CodeCodex

Complete open redirect detection and exploitation methodology parameter discovery, 30+ bypass techniques, OAuth token theft, SSRF chaining, CSP abuse, phishing escalation, and report structure. Trigger when the user asks to test for open redirect or unvalidated redirect/forward, sees a parameter like…

34 18d ago C 124 tokens original MIT

redmind

29

Rifteo/skills

Skill Claude CodeCodex

Red team mindset that shifts the agent to offensive security thinking across any target or engagement type. Trigger when the goal of the engagement is offensive (finding what can be broken, bypassed, or abused), the user wants to understand a target's security posture from an attacker's perspective, or the objective…

34 18d ago A 79 tokens original MIT

remediation-planner

30

Rifteo/skills

Skill Claude CodeCodex

Convert a security finding or vulnerability into a prioritized step-by-step remediation plan with effort estimates per step. Trigger when the user provides a vulnerability, finding, or bug needing a fix plan, asks "how do we fix this?" or "what's the remediation for X?", wants to estimate the work involved in…

34 18d ago A 82 tokens original MIT

risk-assessor

31

Rifteo/skills

Skill Claude CodeCodex

Scores a vulnerability using likelihood × impact, CIA triad analysis, CVSS correlation, and SLA-bound remediation urgency. Trigger when the user describes a vulnerability and wants to know how serious it is, asks "what's the risk level?" or "how urgent is this to fix?", has a CVSS score but wants it contextualized…

34 18d ago A 101 tokens original MIT

scope-grill

32

Rifteo/skills

Skill Claude CodeCodex

Interviews the user about a pentest or audit engagement before any testing begins, capturing target, scope, rules of engagement, auth, and deliverables into a structured brief. Trigger when the user says "start a pentest", "begin an engagement", or "test this target", describes a target without mentioning…

34 18d ago A 84 tokens original MIT

skill-benchmark

33

Rifteo/skills

Skill Claude CodeCodex

Scores any SKILL.md across 5 quality dimensions, runs a compatibility check against 50+ AI agents, and returns a ranked fix list. Trigger when the user asks to benchmark, score, or audit a skill, wants to check cross-agent compatibility (Cursor, Windsurf, Gemini, etc.), needs a ranked fix list before publishing a…

34 18d ago A 104 tokens original MIT

ssrf-hunter

34

Rifteo/skills

Skill Claude CodeCodex

Complete SSRF detection and exploitation methodology injection point discovery, cloud metadata theft (AWS/GCP/Azure), internal network enumeration, protocol handler abuse, filter bypass techniques, blind SSRF via OOB, and report structure. Trigger when the user sees any parameter that accepts a URL, hostname, IP, or…

34 18d ago B 103 tokens original MIT

ssti-hunter

35

Rifteo/skills

Skill Claude CodeCodex

An SSTI detection, fingerprinting, and exploitation engine. Triggered by suspected server-side evaluation (e.g., {{77}} = 49) or stack traces referencing a template engine (Jinja2, Twig, FreeMarker, etc.). Facilitates blind detection, sandbox escapes, and escalation to RCE. Includes report structuring (severity, CWE…

34 18d ago E 81 tokens original MIT

vuln-diagnose

36

Rifteo/skills

Skill Claude CodeCodex

Builds deterministic, reproducible proof-of-concepts to validate suspected or partially-confirmed vulnerabilities (e.g., XSS, IDOR) and eliminate false positives. Triggered when tool outputs flag potential issues, or when manual confirmation of exploitability is required before documenting a finding.

34 18d ago A 63 tokens original MIT

xss-hunter

37

Rifteo/skills

Skill Claude CodeCodex

Complete XSS testing methodology reflected, stored, DOM-based, blind, and mutation XSS, CSP bypass, DOM clobbering, filter/WAF evasion, and impact escalation. Trigger when the user asks to test for XSS or cross-site scripting (reflected, stored, DOM-based, blind, mutation), wants to bypass XSS filters/WAF rules/CSP…

34 18d ago A 133 tokens original MIT

xxe-phantom

38

Rifteo/skills

Skill Claude CodeCodex

An XXE detection and exploitation methodology engine. Triggered when testing for XML injection, interacting with XML content-types/endpoints, or processing XML-based file uploads (SVG, DOCX, SAML, SOAP). Facilitates classic file reads, blind OOB exfiltration, WAF bypasses, and SSRF chaining. Includes report…

34 18d ago E 76 tokens original MIT