galact-byte/galact-Skills

个人自用 Agent Skill 库(SKILL.md 标准),现阶段聚焦授权渗透漏洞挖掘:14 类 hunt-* + 攻击面研判总线,自带静态+靶标端到端测试。后续扩展其它领域。

5Stars on the repository
15Mods indexed here, across every type
23d agoLast push, which is what freshness is scored on
customA LICENSE file GitHub cannot name, so bodies are not copied

hunt-auth-bypass

01

galact-byte/galact-Skills

Skill Claude Code

A security-testing guide for finding authentication and authorization bypasses in authorized tests. Authentication checks who you are; authorization checks what that account is allowed to do.

not rated 5 23d ago A 199 tokens

galact-byte/galact-Skills

Skill Claude Code

A security-testing guide for finding web cache poisoning and cache deception in authorized tests. It examines cases where a CDN or reverse proxy stores a response using an incomplete or different cache key.

not rated 5 23d ago A 189 tokens

galact-byte/galact-Skills

Skill Claude Code

A security-testing guide for finding command injection, where user input is treated as part of an operating-system command or an external program's arguments. It covers web applications, APIs, and continuous-integration systems in authorized tests.

not rated 5 23d ago A 208 tokens

hunt-csrf

04

galact-byte/galact-Skills

Skill Claude Code

A security-testing guide for finding cross-site request forgery, or CSRF, where another site causes a user’s browser to send an unwanted state-changing request. It also tests ways common CSRF protections might be bypassed in authorized tests.

not rated 5 23d ago A 188 tokens

galact-byte/galact-Skills

Skill Claude Code

A security-testing guide for finding insecure deserialization, where user-controlled data is rebuilt into an application object. It covers formats and mechanisms used by PHP, Ruby, Python, Java, and .NET applications in authorized tests.

not rated 5 23d ago A 191 tokens

galact-byte/galact-Skills

Skill Claude Code

A security-testing skill for checking whether Node.js's built-in permission controls can be bypassed. It covers the current permission model and older policy files.

not rated 5 23d ago A 209 tokens

hunt-open-redirect

07

galact-byte/galact-Skills

Skill Claude Code

A guide for finding open redirects during authorised penetration tests. An open redirect is a website feature that sends a user to an attacker-chosen outside URL, often through parameters such as next, redirect, or returnUrl.

not rated 5 23d ago A 179 tokens

hunt-path-traversal

08

galact-byte/galact-Skills

Skill Claude Code

A security-testing guide for finding path traversal, where crafted file names or paths escape an intended directory. It also covers unsafe archive extraction, symbolic links, and archive entries that overwrite files in authorized tests.

not rated 5 23d ago A 204 tokens

galact-byte/galact-Skills

Skill Claude Code

A security-testing guide for finding JavaScript prototype pollution in authorised tests of Node.js servers, REST APIs, and web pages. Prototype pollution happens when user input adds unwanted properties to shared JavaScript objects.

not rated 5 23d ago A 191 tokens

galact-byte/galact-Skills

Skill Claude Code

A security-testing guide for HTTP request smuggling, an attack caused by proxy and server disagreeing about where an HTTP request ends.

not rated 5 23d ago A 209 tokens

hunt-sqli

11

galact-byte/galact-Skills

Skill Claude Code

A security-testing skill for finding SQL injection and NoSQL injection in web applications and APIs during authorized penetration tests. SQL injection tricks a database query through user input; NoSQL injection targets databases such as MongoDB.

not rated 5 23d ago A 185 tokens

hunt-ssrf

12

galact-byte/galact-Skills

Skill Claude Code

A workflow for authorized security testing of SSRF, a vulnerability where a server is tricked into sending requests to locations chosen by a user.

not rated 5 23d ago C 195 tokens

hunt-xss

13

galact-byte/galact-Skills

Skill Claude Code

An authorised security-testing workflow for finding cross-site scripting, or XSS, in web pages and APIs. XSS occurs when attacker-controlled input is run or displayed as unsafe browser code.

not rated 5 23d ago A 198 tokens

hunt-xxe

14

galact-byte/galact-Skills

Skill Claude Code

Uma ferramenta para encontrar falhas de injeção de entidades externas em XML (XXE), durante testes de invasão autorizados. XML é um formato de texto usado por APIs, documentos e arquivos como SVG, DOCX e XLSX.

not rated 5 23d ago A 197 tokens

galact-byte/galact-Skills

Skill Claude Code

A security-testing triage guide for identifying a target’s attack surface—the features and components that could be exposed to attack—and choosing suitable tests.

not rated 5 23d ago A 162 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: