forefy/.context

AI Agent Skills, Loops and Dynamic Workflows for Security Auditing, Pentesting and Research

133Stars on the repository
30Mods indexed here, across every type
5d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

forefy/.context

Skill Claude CodeCodex

Replay captured requests with swapped identities and bumped object IDs to surface broken access control. Use when testing for IDOR or authz flaws.

133 5d ago A 31 tokens original MIT

cdn-peek

02

forefy/.context

Skill Claude CodeCodex

Uncover the real origin IP behind a CDN or WAF like Cloudflare, using only standard tools. Use to bypass a CDN/WAF or check if an origin leaks.

133 5d ago C 39 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Detect HTTP request smuggling by desynchronising front-end and back-end request parsing, using raw-socket timing and differential probes. Use when testing for HTTP desync (CL.TE, TE.CL).

133 5d ago A 46 tokens original MIT

jwt-attacks

04

forefy/.context

Skill Claude CodeCodex

Forge and re-sign captured JWTs to test signature validation - algorithm confusion (alg:none, RS256 to HS256), key injection, and secret cracking. Use when testing JWT or bearer-token auth.

133 5d ago A 44 tokens original MIT

ssrf-oob

05

forefy/.context

Skill Claude CodeCodex

Prove blind SSRF by injecting an out-of-band callback into URL params and forwarding headers, then watching for the hit. Use when testing for SSRF.

133 5d ago A 37 tokens original MIT

webapp-probe

06

forefy/.context

Skill Claude CodeCodex

Probe a web app for what it exposes or leaks - passively from captured traffic and actively against the target. Use to assess a web app's exposure or review Burp/ZAP history.

133 5d ago C 43 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Expert blockchain forensics assistant for investigators and auditors, including threat recognition, incident scoping, data collection, transaction tracking, chain analysis, attribution, OSINT, advanced demixing, cross-chain tracing, graph clustering, and reporting.

133 5d ago A 51 tokens original MIT

foundry-poc

08

forefy/.context

Skill Claude CodeCodex

Generates a Foundry PoC for smart contracts that scientifically proves the path from no special privileges to funds lost. Focused on proof of concept for EVM using forge test.

133 5d ago A 42 tokens original MIT

safe-hunt

09

forefy/.context

Skill Claude CodeCodex

Sweeps DeFi protocol Safe multisig wallets for governance misconfigurations and security weaknesses. Given a protocol name, Safe address, or "sweep all", fetches live config and tx history from the Safe Transaction Service API, scores each Safe against a finding pattern library, and produces an audit-ready ranked…

133 5d ago A 92 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Comprehensive smart contract security audit framework with multi-expert analysis. Use for full audits of Ethereum / EVM Solidity and Vyper, Solana / SVM Anchor Rust, TON / FunC / Tact, or Sui / Move projects.

133 5d ago A 55 tokens original MIT

cloud-bucket-brute

11

forefy/.context

Skill Claude CodeCodex

Discover publicly readable cloud storage by permuting a company name into likely bucket names and probing AWS S3, Google Cloud, DigitalOcean, Alibaba, Oracle, and Vultr. Use to find exposed buckets.

133 5d ago A 47 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations. Use for full infrastructure audits.

133 5d ago A 29 tokens original MIT

dylib-hijack-scan

13

forefy/.context

Skill Claude CodeCodex

Scan macOS for hijackable dynamic libraries, separating exploitable privesc hijacks from harmless ones. Use to check if an app is hijackable.

133 5d ago A 42 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Hunt a live macOS, Linux, or Windows endpoint for malware across process, network, and persistence. Use to scan for threats or check for compromise.

133 5d ago A 37 tokens original MIT

agent-onboarding

15

forefy/.context

Skill Claude CodeCodex

Onboard yourself to a repo where several agents work in parallel, syncing through a shared TODO.md. Use when joining the team on a shared codebase.

133 5d ago A 35 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Takes the active conversation as reference to understand how a skill can be created, with all the lessons learned from the user's needs in the conversation.

133 5d ago A 35 tokens original MIT

git-commit

17

forefy/.context

Skill Claude CodeCodex

Commit to Git safely: runs tests, security-reviews the diff, strips secrets and dead code, and enforces clean messages. Use before any commit or push.

133 5d ago A 37 tokens original MIT

training-guide

18

forefy/.context

Skill Claude CodeCodex

Build an interactive visual course as one self-contained HTML page, one idea per screen. Use to explain or teach a subject visually, step by step.

133 5d ago A 33 tokens original MIT

variant-table

19

forefy/.context

Skill Claude CodeCodex

Lay draft copy out as a table with three distinct rewrites per line and a top pick. Use to compare wording for posts, headlines, CTAs, or microcopy.

133 5d ago A 38 tokens original MIT

audit-scope

20

forefy/.context

Skill Claude CodeCodex

Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table. Use when scoping a new engagement.

133 5d ago A 35 tokens original MIT

auditor-quiz

21

forefy/.context

Skill Claude CodeCodex

Quiz an auditor on a codebase's mechanics and vulnerabilities, drawn from its own code and docs. Use to test understanding before or during a review.

133 5d ago A 35 tokens original MIT

forefy/.context

Skill Claude CodeCodex

Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs. Use to recon an external attack surface or enumerate subdomains.

133 5d ago A 37 tokens original MIT

gdocs-audit-report

23

forefy/.context

Skill Claude CodeCodex

Write and format security-audit reports in Google Docs via the Docs API - findings, tables, and severity styling. Use to build or fix a report.

133 5d ago A 37 tokens original MIT

hackerone-report

24

forefy/.context

Skill Claude CodeCodex

Draft and file a HackerOne report in the browser, with a proof-of-concept package and demo-video notes. Use to submit or prepare a bug-bounty report.

133 5d ago A 39 tokens original MIT