ShulkwiSEC

60 mods across 1 repository, 21 stars between them.

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Execute sophisticated Prompt Injection and Jailbreak techniques against Large Language Models (LLMs) to bypass safety filters, extract system prompts, and manipulate the AI's output to perform malicious or disallowed actions.

21 1mo ago B 50 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Advanced techniques for bypassing LLM safety filters, instruction tuning, and system prompt restrictions using specialized linguistic constructs, hypothetical scenarios, and persona adoption.

21 1mo ago A 38 tokens original MIT

ai-ml-security

27

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.

21 1mo ago B 53 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Configure Claude as a "Pair Hunter" — autonomous overnight hacking, context management via per-target .claudemd files, sub-agent compaction avoidance, and scope enforcement. Based on Critical Thinking Bug Bounty Podcast Episode 166.

21 1mo ago A 58 tokens original MIT

ai-prompt-leaking

29

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Systematically extract hidden system prompts, core directives, and invisible context intentionally concealed within Large Language Model (LLM) applications. This skill utilizes targeted linguistic engineering and boundary manipulation to bypass prompt opacity.

21 1mo ago A 47 tokens original MIT

ai-redteam

30

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

AI/LLM red-team assessment using the OWASP LLM Top 10 (2025) + OWASP AI Testing Guide (AITG v1, Nov 2025) frameworks, plus OWASP MCP Top 10 runtime testing for agentic/MCP targets. Tests prompt injection, jailbreaks, system prompt leakage, sensitive data extraction, excessive agency, improper output handling, model…

21 1mo ago C 229 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Prevent common AI report pitfalls — bug blending, inflated threat models, and generic language. Train Claude with your best past reports for concise, technical submissions. Based on Critical Thinking Bug Bounty Podcast Episode 166.

21 1mo ago A 51 tokens original MIT

aikido-triage

32

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Triages an Aikido security findings CSV against a local codebase. For each finding, reads the flagged file, traces the code path, and verdicts it as KEEP OPEN or CLOSE with a specific reason. Outputs a reviewed CSV and a self-contained HTML evidence report. Run this at the end of a pentest when an Aikido CSV is…

21 1mo ago A 80 tokens original MIT

amend-skill

33

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Inspects a skill's SKILL.md and its observations/runs.md log, identifies failure patterns, and proposes a targeted amendment to improve the skill. Trigger on: "improve this skill", "fix this skill", "update this skill", "why does X keep failing", "this skill is wrong", "add this to the skill", or automatically when…

21 1mo ago A 121 tokens original MIT

amsi-bypass

34

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Bypass the Windows Antimalware Scan Interface (AMSI) using memory patching, reflection, and obfuscation techniques. Execute undetected PowerShell, VBScript, JScript, and .NET assemblies in-memory without triggering Microsoft Defender or third-party AV/EDR solutions. Use this skill during Red Team engagements when…

21 1mo ago A 93 tokens original MIT

analyze-cve

35

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Analyzes CVE vulnerabilities in project dependencies with code path tracing and PoC generation for Burp Suite. Traces vulnerable code from user input to sink, assesses exploitability, and generates HTTP requests for testing.

21 1mo ago A 47 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Decompile, analyze, and reverse engineer Android applications (APKs). Utilize tools like JADX, Apktool, and dex2jar to extract source code (Java/Kotlin), analyze manifest configurations (Intents, Activities), and identify hardcoded secrets or insecure API endpoints.

21 1mo ago A 64 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent redirection, root detection bypass, tapjacking, and backup extraction during authorized mobile security assessments.

21 1mo ago A 53 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Anti-debugging detection and bypass playbook. Use when reversing protected binaries that detect debuggers via ptrace, PEB flags, timing checks, or signal/exception handlers on Linux and Windows.

21 1mo ago A 46 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

21 1mo ago A 41 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Test APIs for authentication and authorization bypass vulnerabilities including JWT manipulation, OAuth2 flaws, API key leakage, broken authentication, and token forgery. Use this skill when assessing REST/GraphQL APIs for access control weaknesses, session management flaws, or credential handling issues. Covers JWT…

21 1mo ago A 72 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

API authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or weak function-level authorization.

21 1mo ago A 36 tokens copy · 100% MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Systematically discover hidden Application Programming Interfaces (APIs), uncover undocumented endpoints (Shadow APIs), and fuzz parameters. Use this skill as the pivotal first step in API Bug Hunting, transforming a basic frontend application into a vast mapped attack surface.

21 1mo ago A 57 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Identify and exploit Mass Assignment vulnerabilities in APIs. Use this skill when testing REST APIs or application forms that directly map user-supplied JSON or POST input to internal database objects. An attacker can inject undocumented variables (e.g., isadmin, verified) to illegally modify restricted properties.

21 1mo ago A 68 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Identify and exploit flaws in API rate limiting enforcement. Use this skill when encountering HTTP 429 Too Many Requests errors during password brute-forcing, OTP validation, credential stuffing, or enumeration attacks. These bypasses leverage IP spoofing, parameter manipulation, and edge-case application logic.

21 1mo ago A 66 tokens original MIT

api-recon-and-docs

45

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.

21 1mo ago A 38 tokens copy · 100% MIT

api-sec

46

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Entry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter workflows before any deeper API topic skill.

21 1mo ago A 36 tokens copy · 100% MIT

api-security

47

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Deep API security assessment beyond surface scanning. Covers the full OWASP API Security Top 10 (2023): Broken Object Level Authorization (BOLA / IDOR), Broken Authentication, Broken Object Property Level Authorization (mass assignment + excessive data exposure), Unrestricted Resource Consumption, Broken Function…

21 1mo ago B 314 tokens original MIT

ShulkwiSEC/bb-huge

Skill Claude CodeCodex

Complete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques.

21 1mo ago A 25 tokens original MIT