guib1/red-team-docker

A docker structured with Gemini-cli + Hexstrike-mcp + some kali tools pre configured to use as a attacker machine, a lightweight alternative for Kali Linux

1Stars on the repository
33Mods indexed here, across every type
4mo agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

bug-bounty

01

guib1/red-team-docker

Skill Claude CodeCodex

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload…

1 4mo ago C 371 tokens

bb-methodology

02

guib1/red-team-docker

Skill Claude CodeCodex

Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the 5-phase non-linear hunting workflow with the critical thinking framework (developer psychology, anomaly detection, What-If experiments). Routes to all other…

1 4mo ago C 90 tokens

report-writing

03

guib1/red-team-docker

Skill Claude CodeCodex

Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — report templates, human tone guidelines, impact-first writing, CVSS 3.1 scoring, title formula, impact statement formula, severity decision guide, downgrade counters, pre-submit checklist. Use after validating a finding and before submitting. Never use…

1 4mo ago A 82 tokens

security-arsenal

04

guib1/red-team-docker

Skill Claude CodeCodex

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, or to check if a finding…

1 4mo ago B 103 tokens

triage-validation

05

guib1/red-team-docker

Skill Claude CodeCodex

Finding validation before writing any report — 7-Question Gate (all 7 questions), 4 pre-submission gates, always-rejected list, conditionally valid with chain table, CVSS 3.1 quick reference, severity decision guide, report title formula, 60-second pre-submit checklist. Use BEFORE writing any report. One wrong answer…

1 4mo ago A 87 tokens

web2-recon

06

guib1/red-team-docker

Skill Claude CodeCodex

Web2 recon pipeline — subdomain enumeration (subfinder, Chaos API, assetfinder), live host discovery (dnsx, httpx), URL crawling (katana, waybackurls, gau), directory fuzzing (ffuf), JS analysis (LinkFinder, SecretFinder), continuous monitoring (new subdomain alerts, JS change detection, GitHub commit watch). Use when…

1 4mo ago A 103 tokens

web2-vuln-classes

07

guib1/red-team-docker

Skill Claude CodeCodex

Complete reference for 20 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples. Covers IDOR, auth bypass, XSS, SSRF (11 IP bypass techniques), SQLi, business logic, race conditions, OAuth/OIDC, file upload (10 bypass techniques), GraphQL, LLM/AI (ASI01-ASI10…

1 4mo ago D 189 tokens

web3-audit

08

guib1/red-team-docker

Skill Claude CodeCodex

Smart contract security audit — 10 DeFi bug classes (accounting desync, access control, incomplete path, off-by-one, oracle, ERC4626, reentrancy, flash loan, signature replay, proxy), pre-dive kill signals (TVL < $500K etc), Foundry PoC template, grep patterns for each class, and real Immunefi paid examples. Use for…

1 4mo ago A 103 tokens

find-skills

09

guib1/red-team-docker

Skill Claude CodeCodex

Discover and install skills from the open agent skills ecosystem.

1 4mo ago A 15 tokens

hackerone

10

guib1/red-team-docker

Skill Claude CodeCodex

HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents for each asset, validates PoCs, and generates platform-ready submission reports. Use when testing HackerOne programs or preparing professional vulnerability submissions.

1 4mo ago A 49 tokens

kali-tools

11

guib1/red-team-docker

Skill Claude CodeCodex

Comprehensive reference for Kali Linux tools. Use this skill to find, understand, and use security tools in Kali Linux. It provides a categorized index of all available tools.

1 4mo ago A 38 tokens

pentest-checklist

12

guib1/red-team-docker

Skill Claude CodeCodex

Comprehensive checklist for planning, executing, and following up on penetration tests.

1 4mo ago A 20 tokens

red-team-tactics

13

guib1/red-team-docker

Skill Claude CodeCodex

Red team tactics principles based on MITRE ATT&CK. Attack phases, detection evasion, reporting.

1 4mo ago B 26 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: