Skill Codex
Implement tasks from an OpenSpec change. Use when the user wants to start implementing, continue implementation, or work through tasks.
Harness-driven terminal AI agent for authorized security assessment, with TUI, headless automation, persistent context, 150 built-in skills, and a dedicated pentest mode.
This repository also configures its own agents. See what Mingyi-Atlas tells them →
Skill Codex
Implement tasks from an OpenSpec change. Use when the user wants to start implementing, continue implementation, or work through tasks.
Skill Codex
Archive a completed change in the experimental workflow. Use when the user wants to finalize and archive a change after implementation is complete.
Skill Codex
Enter explore mode - a thinking partner for exploring ideas, investigating problems, and clarifying requirements. Use when the user wants to think through something before or during a change.
Skill Codex
Propose a new change with all artifacts generated in one step. Use when the user wants to quickly describe what they want to build and get a complete proposal with design, specs, and tasks ready for implementation.
Skill Claude Code
Benchmark mode marker — engagement objective is flag capture. Generic engagement rules apply unchanged.
Skill Claude Code
Automate browser interactions, test web pages and work with Playwright tests.
Skill Claude Code
Nuclei CLI parameter reference and usage patterns - YAML-template vulnerability scanning, target input modes, template filters, output formats, rate limits, ProjectDiscovery dashboard upload, and common scan commands.
Skill Claude CodeCodex
Active Directory attack lane — BloodHound ingestion, Kerberoasting, ADCS ESC scanning, DCSync, LAPS extraction.
Skill Claude CodeCodex
Exploit Active Directory Certificate Services ESC1 — vulnerable template allows arbitrary SAN, enabling user impersonation up to domain admin.
Skill Claude CodeCodex
Request AS-REP for accounts with DONTREQPREAUTH set and crack offline — like kerberoast but no auth required.
Skill Claude CodeCodex
BloodHound ingestion + canonical Cypher queries for AD attack-path enumeration. Run after collector dumps zip; promotes findings into the knowledge graph.
Skill Claude Code
ADCS abuse via Certipy — find vulnerable templates (ESC1-ESC15), request a certificate, authenticate as the target, dump the krbtgt. Full chain in 4 commands. Covers ESC1 (any SAN), ESC2 (any-purpose EKU), ESC3 (enrollment-agent), ESC4 (vulnerable ACL), ESC8 (NTLM relay to CA), ESC9/10/11/13.
Skill Claude Code
Authentication coercion against Windows / AD — PetitPotam (MS-EFSR), PrinterBug (MS-RPRN), DFSCoerce (MS-DFSNM), ShadowCoerce (MS-FSRVP), Coercer.py meta-tool. Force a Windows machine to NTLM-authenticate to attacker, then relay or crack offline.
Skill Claude CodeCodex
Abuse replication rights (DS-Replication-Get-Changes + GetChangesAll) to dump krbtgt and arbitrary user NT hashes from a DC.
Skill Claude CodeCodex
Request Kerberos TGS tickets for SPN-bound service accounts and crack offline with hashcat — classic AD priv-esc primitive.
Skill Claude CodeCodex
Extract LAPS-managed local administrator passwords from AD computer objects (ms-Mcs-AdmPwd / msLAPS-Password).
Skill Claude CodeCodex
NetExec (CrackMapExec successor) — unified SMB/LDAP/MSSQL/WinRM/RDP/SSH/FTP/VNC protocol auth + post-auth modules. 200+ modules incl. BloodHound auto-ingest, ESC1-15 scanning, PrintNightmare, LDAP relay.
Skill Claude Code
NTLM relay deep-dive — ntlmrelayx configuration matrix (SMB, LDAP, LDAPS, HTTP, RPC, IMAP, MSSQL), SMB-signing bypass, target selection (DC for DCSync, ADCS for cert, LAPS reader for cleartext), session relay vs cracking trade-off, multi-relay (forward auth from one victim to many).
Skill Claude CodeCodex
Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills.
Skill Claude CodeCodex
Hunt authentication/authorization bypass in route guards, role checks, tenant boundaries, and state-machine transitions.
Skill Claude CodeCodex
Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy.
Skill Claude CodeCodex
Build chains where leaked or weak credentials pivot across services to privileged access.
Skill Claude CodeCodex
Build chains where IDOR enables privilege escalation and high-impact control-plane actions.
Skill Claude CodeCodex
Build and validate SSRF pivot chains toward metadata/infra control and final code execution impact.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: