uphiago

60 mods across 1 repository, 1.2k stars between them.

uphiago/recon-skills

Skill Claude CodeCodex

Scan WordPress REST API plugin endpoints for unauthenticated state-changing operations — discover write endpoints (POST/PUT/PATCH/DELETE) exposed without auth, enumerate all plugin routes, and test for unauthorized content publishing, settings modification, and data leakage.

1.2k 8d ago C 57 tokens original MIT

zimbra-attack

51

uphiago/recon-skills

Skill Claude CodeCodex

Zimbra SOAP user enum, CVE-2022-37042, SSRF when webmail.

1.2k 8d ago C 26 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase grep, pinned-cert extraction, exported-component enumeration, Frida runtime instrumentation templates, intent-injection probes. Built from an authorized external…

1.2k 8d ago A 145 tokens copy · 88% MIT

bb-local-toolkit

53

uphiago/recon-skills

Skill Claude CodeCodex

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning, vuln hunting (30+ classes), A-to-B chaining, AI/LLM testing, bypass tables, language-specific grep, reporting. Use for ANY bug bounty task.

1.2k 8d ago F 69 tokens copy · 84% MIT

bb-methodology

54

uphiago/recon-skills

Skill Claude CodeCodex

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other…

1.2k 8d ago A 90 tokens copy · 91% MIT

bug-bounty

55

uphiago/recon-skills

Skill Claude CodeCodex

Master bug bounty orchestrator — full pipeline: recon, pre-hunt learning, vulnerability hunting (30+ classes), A-to-B chaining, AI/LLM testing (ASI01-ASI10), language-specific grep, bypass tables, and reporting (7-question gate, CVSS 3.1, human-tone templates). Use for ANY bug bounty task — starting a new target…

1.2k 8d ago F 121 tokens copy · 86% MIT

bugcrowd-reporting

56

uphiago/recon-skills

Skill Claude CodeCodex

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints…

1.2k 8d ago A 171 tokens copy · 91% MIT

cloud-iam-deep

57

uphiago/recon-skills

Skill Claude CodeCodex

GCP/AWS/Azure cloud exploitation -- Cloud Functions, Firestore, Cloud Run, S3, MinIO, Blob Storage, SA keys.

1.2k 8d ago B 35 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

Use when a bounded list of authorized API endpoints needs consistent CORS triage before browser validation.

1.2k 8d ago A 24 tokens original MIT

uphiago/recon-skills

Skill Claude CodeCodex

External SSL VPN / remote-access appliance attack matrix — Cisco ASA/AnyConnect, Fortinet FortiGate/FortiOS, Citrix NetScaler/ADC, Palo Alto GlobalProtect, Pulse Secure / Ivanti Connect Secure, SonicWall, F5 Big-IP. Covers version fingerprinting, CVE matrix (2018-2026), AAA backend identification, default credentials…

1.2k 8d ago A 158 tokens copy · 88% MIT

evidence-hygiene

60

uphiago/recon-skills

Skill Claude CodeCodex

Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools workflow), PII black-bar discipline (what to mask in other-user data — names, emails, phones, faces — vs what is safe to leave — usernames, trace…

1.2k 8d ago A 190 tokens copy · 86% MIT