adriannoes/awesome-agentic-ai

342 agent skills (Cursor, Claude Code & Codex), 5,380 OpenClaw skills, 201 ML notebooks, 9 textbooks, 93 research papers, 94 curated projects, 18 industry reports for PMs, Designers & Developers.

57Stars on the repository
202Mods indexed here, across every type
14d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

hunt-ssti

145

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Hunt server-side template injection (SSTI) across Jinja2 (Flask/Django), Twig (Symfony), Freemarker (Java), ERB (Rails), Spring, Velocity, Mako, Thymeleaf, Smarty. Detection probes use double-curly and dollar-curly math expressions evaluated server-side. Once an engine is fingerprinted, escalate to RCE via the…

not rated 57 +2 14d ago B SkillSpector: warn 165 tokens original MIT

hunt-subdomain

146

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Hunting skill for subdomain vulnerabilities. Built from 11 public bug bounty reports. Use when hunting subdomain on any target.

not rated 57 +2 14d ago A SkillSpector: pass 30 tokens original MIT

hunt-xss

147

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Hunting skill for xss vulnerabilities. Built from 174 public bug bounty reports. Use when hunting xss on any target.

not rated 57 +2 14d ago C 30 tokens original MIT

hunt-xxe

148

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Hunting skill for xxe vulnerabilities. Built from 4 public bug bounty reports. Use when hunting xxe on any target.

not rated 57 +2 14d ago A ✓ AI review 31 tokens original MIT

m365-entra-attack

149

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Microsoft 365 / Entra ID red-team attack chain — current 2026 reality. AADSTS code reference, user enumeration vectors (with hardening status), Smart Lockout math, Conditional Access bypass options, ROPC + SAML SSO browser flow, Burp/Playwright templates. Built from authorized red-team work where ROPC spray surfaced…

not rated 57 +2 14d ago A 128 tokens copy · 95% MIT

meme-coin-audit

150

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex needs its repo

Meme coin and token security audit — rug pull detection (honeypot, hidden mint, fee manipulation, LP lock bypass), Solana SPL token analysis (freeze authority, mint authority, metadata mutability), Token-2022 extension risks (transfer hooks, permanent delegate), DEX liquidity pool attacks (sandwich amplification, LP…

not rated 57 +2 14d ago A 129 tokens copy · 91% MIT

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Methodology for detecting client SOC patches, attacker activity, and security-state changes that occur DURING a red-team engagement — and converting those observations into deliverable findings. Built from authorized red-team work where the client patched a confirmed SQLi within 30 minutes of detection AND an external…

not rated 57 +2 14d ago A 120 tokens copy · 91% MIT

offensive-osint

152

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Operational arsenal for authorized external red-team and bug-bounty recon. Concrete probes, wordlists, regexes, dorks, curl one-liners for: subdomain enum, GraphQL/Swagger/REST discovery, identity fabric (Entra/Okta/ADFS/Google/SAML/M365 deep — Teams/SharePoint/OneDrive), cloud bucket enum (S3/GCS/Azure), CDN/WAF…

not rated 57 +2 14d ago B 261 tokens copy · 86% MIT

okta-attack

153

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Okta-as-IdP red-team attack chain — tenant discovery, user enumeration (multiple vectors), authentication flow analysis (factors enumeration, push-notification fatigue, SMS bypass), password spray with lockout discipline, Okta-specific phishing primitives (kits, FastPass abuse, OIDC redirecturi tampering), MFA…

not rated 57 +2 14d ago B SkillSpector: warn 149 tokens original MIT

osint-methodology

154

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments. Covers the 5-stage recon pipeline (seed discovery, asset expansion, enrichment, exposure analysis, reporting), asset-graph discipline with 29 asset types, severity rubric (CRITICAL/HIGH/MEDIUM/LOW/INFO)…

not rated 57 +2 14d ago B 258 tokens copy · 100% MIT

redteam-mindset

155

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Red-team operator discipline — the mindset corrections that separate offensive testing from defensive WAPT. Built from authorized red-team work where conservative defaults caused multiple findings to be missed and one to be incorrectly retracted. Use at the START of any red-team engagement and again whenever feeling…

not rated 57 +2 14d ago A 94 tokens copy · 86% MIT

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Client-facing red-team deliverable format — codifies the Subject / Observations / Description / Impact / Recommendation / PoC structure used for external red-team engagements (not bug-bounty platform reports). Different audience, different tone, different cadence. Built from an authorized engagement deliverable where…

not rated 57 +2 14d ago A 139 tokens copy · 95% MIT

report-writing

157

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use…

not rated 57 +2 14d ago C 82 tokens copy · 89% MIT

security-arsenal

158

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex needs its repo

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, or to check if a finding…

not rated 57 +2 14d ago B 103 tokens copy · 89% MIT

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

External recon for software supply-chain attack surface — package-namespace squatting candidates, dependency-confusion vulnerabilities, GitHub Actions injection openings, container image registry exposure, SBOM mining, internal-package-name leakage, and CI/CD configuration exposure. Reconnaissance and identification…

not rated 57 +2 14d ago B SkillSpector: warn 141 tokens original MIT

triage-validation

160

adriannoes/awesome-agentic-ai

Skill Claude CodeCodex

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer…

not rated 57 +2 14d ago A 87 tokens copy · 95% MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: