Creates task-oriented technical documentation with progressive disclosure. Use when writing READMEs, API docs, architecture docs, or markdown documentation. Also use this skill at the END of any completed reverse engineering, penetration testing, CTF, or security analysis task to generate a formal report in the user's…
A security-testing guide for studying how endpoint defenses such as EDR, Defender, and antivirus monitor Windows systems, then testing ways to avoid those detections in authorized exercises.
Goal-contract, capability graph, TraceCard, and promotion-gate control plane for self-evolving reverse/security skill routing. Use before macro-routing when the task needs end-to-end completion, route repair, or reusable learning.
A workflow for auditing firmware, the software built into devices such as routers, cameras, and smart-home products, from a firmware file through testing and exploitation research.
A Ghidra assistant for examining compiled programs through the GhydraMCP bridge. Ghidra is a free tool that helps turn machine code into readable structures and approximate source code.
An IDA Pro assistant for examining compiled programs such as Windows executables, Linux binaries, Android libraries, and firmware files. IDA Pro is a tool that turns machine code into a form people can inspect.
A combined Android and iOS workflow for examining mobile applications, including their permissions, code, protections, network checks, and runtime behaviour.
A workflow for comparing patched and unpatched program files to infer what security bug a vendor fixed, then develop a proof of concept for the older version.
13 22d agoA192 tokens
copy · 89%MIT
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: