MingyiSecLab/Mingyi-Atlas

Harness-driven terminal AI agent for authorized security assessment, with TUI, headless automation, persistent context, 150 built-in skills, and a dedicated pentest mode.

This repository also configures its own agents. See what Mingyi-Atlas tells them →

11Stars on the repository
156Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

MingyiSecLab/Mingyi-Atlas

Skill Codex

Implement tasks from an OpenSpec change. Use when the user wants to start implementing, continue implementation, or work through tasks.

not rated 11 2mo ago A 31 tokens copy · 88% Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Codex

Archive a completed change in the experimental workflow. Use when the user wants to finalize and archive a change after implementation is complete.

not rated 11 2mo ago A 31 tokens copy · 88% Apache-2.0

openspec-explore

03

MingyiSecLab/Mingyi-Atlas

Skill Codex

Enter explore mode - a thinking partner for exploring ideas, investigating problems, and clarifying requirements. Use when the user wants to think through something before or during a change.

not rated 11 2mo ago A 39 tokens copy · 92% Apache-2.0

openspec-propose

04

MingyiSecLab/Mingyi-Atlas

Skill Codex

Propose a new change with all artifacts generated in one step. Use when the user wants to quickly describe what they want to build and get a complete proposal with design, specs, and tasks ready for implementation.

not rated 11 2mo ago A 47 tokens copy · 100% Apache-2.0

benchmark

05

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.

not rated 11 2mo ago A 18 tokens original Apache-2.0

playwright-cli

06

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Automate browser interactions, test web pages and work with Playwright tests.

not rated 11 2mo ago A 19 tokens original Apache-2.0

nuclei

07

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Nuclei CLI parameter reference and usage patterns - YAML-template vulnerability scanning, target input modes, template filters, output formats, rate limits, ProjectDiscovery dashboard upload, and common scan commands.

not rated 11 2mo ago A 42 tokens original Apache-2.0

ad

08

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.

not rated 11 2mo ago A 29 tokens copy · 89% Apache-2.0

adcs-esc1

09

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.

not rated 11 2mo ago A 30 tokens copy · 94% Apache-2.0

asrep-roasting

10

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Request AS-REP for accounts with DONTREQPREAUTH set and crack offline — like kerberoast but no auth required.

not rated 11 2mo ago A 31 tokens copy · 94% Apache-2.0

bloodhound-query

11

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.

not rated 11 2mo ago A 32 tokens copy · 94% Apache-2.0

certipy-esc-chain

12

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.

not rated 11 2mo ago B 93 tokens copy · 97% Apache-2.0

coercer

13

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.

not rated 11 2mo ago B 71 tokens copy · 100% Apache-2.0

dcsync

14

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Abuse replication rights (DS-Replication-Get-Changes + GetChangesAll) to dump krbtgt and arbitrary user NT hashes from a DC.

not rated 11 2mo ago A 35 tokens copy · 94% Apache-2.0

kerberoasting

15

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Request Kerberos TGS tickets for SPN-bound service accounts and crack offline with hashcat — classic AD priv-esc primitive.

not rated 11 2mo ago A 30 tokens copy · 97% Apache-2.0

laps

16

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Extract LAPS-managed local administrator passwords from AD computer objects (ms-Mcs-AdmPwd / msLAPS-Password).

not rated 11 2mo ago A 27 tokens copy · 98% Apache-2.0

netexec

17

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.

not rated 11 2mo ago A 64 tokens copy · 97% Apache-2.0

ntlm-relay

18

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

NTLM relay deep-dive — ntlmrelayx configuration matrix (SMB, LDAP, LDAPS, HTTP, RPC, IMAP, MSSQL), SMB-signing bypass, target selection (DC for DCSync, ADCS for cert, LAPS reader for cleartext), session relay vs cracking trade-off, multi-relay (forward auth from one victim to many).

not rated 11 2mo ago B 84 tokens copy · 98% Apache-2.0

analyst

19

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills.

not rated 11 2mo ago A 33 tokens original Apache-2.0

auth-bypass

20

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.

not rated 11 2mo ago A 25 tokens copy · 89% Apache-2.0

bounty-hunting

21

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy.

not rated 11 2mo ago A 35 tokens copy · 91% Apache-2.0

cred-reuse

22

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Build chains where leaked or weak credentials pivot across services to privileged access.

not rated 11 2mo ago A 18 tokens original Apache-2.0

idor-to-priv-esc

23

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Build chains where IDOR enables privilege escalation and high-impact control-plane actions.

not rated 11 2mo ago A 22 tokens copy · 89% Apache-2.0

ssrf-to-rce

24

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Build and validate SSRF pivot chains toward metadata/infra control and final code execution impact.

not rated 11 2mo ago C 24 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: