MingyiSecLab/Mingyi-Atlas

Harness-driven terminal AI agent for authorized security assessment, with TUI, headless automation, persistent context, 150 built-in skills, and a dedicated pentest mode.

This repository also configures its own agents. See what Mingyi-Atlas tells them →

11Stars on the repository
156Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

xss-to-takeover

25

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Build chains from XSS into account takeover or privileged action execution.

not rated 11 2mo ago A 20 tokens original Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt OS command injection (CWE-78) — user input reaching shell, exec, or system calls. Covers argument-array bypasses, path confusion, and template-string injection in modern frameworks.

not rated 11 2mo ago B 45 tokens copy · 95% Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt insecure deserialization (CWE-502) across Python pickle, Java ObjectInputStream / Jackson / SnakeYAML, .NET BinaryFormatter / DataContractJson, PHP unserialize, Ruby Marshal/YAML.load, and Node.js vm. Direct path to unauthenticated RCE.

not rated 11 2mo ago B 63 tokens copy · 89% Apache-2.0

idor-analysis

28

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt Insecure Direct Object Reference (CWE-639) — missing authorization checks on object IDs. Covers horizontal vs vertical privilege escalation, UUID vs integer guessing, and GraphQL introspection-driven IDOR discovery.

not rated 11 2mo ago B 46 tokens copy · 97% Apache-2.0

path-traversal

29

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt directory traversal and archive traversal (ZipSlip/TarSlip) from user input to filesystem operations.

not rated 11 2mo ago A 26 tokens original Apache-2.0

pattern-exhaustion

30

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Systematic pattern exhaustion methodology. Load after finding any confirmed vulnerability to search for all instances of the same root cause pattern across the codebase.

not rated 11 2mo ago A 33 tokens original Apache-2.0

prompt-injection

31

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt LLM prompt injection and tool-call hijacking in modern AI-integrated applications (CWE-1427). Covers indirect injection via RAG, tool abuse, exfiltration chains, and jailbreak-to-RCE pivots on agentic systems.

not rated 11 2mo ago A ✓ AI review 55 tokens copy · 98% Apache-2.0

prototype-pollution

32

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt JavaScript prototype pollution (CWE-1321) — the 2023-2026 meta-vulnerability that chains into RCE, auth bypass, and SSRF on most Node.js stacks.

not rated 11 2mo ago A 47 tokens copy · 88% Apache-2.0

sql-injection

33

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt SQL injection (CWE-89) via source-level taint tracking. Covers string concat, format-string, ORM raw queries, second-order injection, and NoSQL injection in MongoDB/DynamoDB.

not rated 11 2mo ago A 47 tokens copy · 92% Apache-2.0

ssrf-analysis

34

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt Server-Side Request Forgery (CWE-918) through taint analysis from user-controlled URLs to HTTP client sinks. Covers cloud metadata pivoting, DNS rebinding, gopher smuggling, and the IMDSv1 → IAM role chain that turns SSRF into RCE.

not rated 11 2mo ago C 64 tokens copy · 94% Apache-2.0

ssti-analysis

35

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution.

not rated 11 2mo ago A 34 tokens original Apache-2.0

trust-boundary

36

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Trust boundary mapping and startup sequence audit for developer tools, CLI apps, and plugin systems. Load when the target is a developer tool, CLI, IDE extension, or any application that loads config from the current directory.

not rated 11 2mo ago A 47 tokens copy · 91% Apache-2.0

xxe-analysis

37

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Hunt XML External Entity flaws in parsers and validate file read / SSRF impact with strict negative controls.

not rated 11 2mo ago A 26 tokens original Apache-2.0

atlas

38

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Atlas orchestrator workflow — engagement intake, OPPLAN build, execution loop via task() delegation, final report. Tools=[]; everything ships through sub-agents.

not rated 11 2mo ago A 34 tokens original Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Red team engagement lifecycle management — initiation, phase transitions, go/no-go gates, deconfliction, emergency procedures, completion.

not rated 11 2mo ago A 30 tokens copy · 91% Apache-2.0

engagement-startup

40

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Mandatory first-turn startup procedure — checks for existing engagements, resume/new selection, workspace initialization.

not rated 11 2mo ago A 23 tokens original Apache-2.0

final-report

41

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Final engagement report generation — executive summary, technical report, findings aggregation, attack path narrative, detection gap matrix, remediation roadmap.

not rated 11 2mo ago A 28 tokens original Apache-2.0

kill-chain-analysis

42

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Kill chain analysis and attack path decision-making — findings analysis, attack vector selection, target prioritization, phase transitions.

not rated 11 2mo ago A 27 tokens copy · 91% Apache-2.0

orchestration

43

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Atlas orchestrator patterns — delegation, state management, adaptive re-planning, context handoff protocols.

not rated 11 2mo ago A 24 tokens copy · 88% Apache-2.0

cloud

44

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.

not rated 11 2mo ago A 32 tokens copy · 89% Apache-2.0

aws-iam-enum

45

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Enumerate AWS IAM policies, detect privilege escalation paths per Rhino Security Labs canonical 21 primitives.

not rated 11 2mo ago A 25 tokens copy · 86% Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

AWS IAM privilege escalation via iam:PassRole chains — Lambda/Glue/Sagemaker/EC2/ECS PassRole to a higher-priv role, AssumeRole chains across accounts, sts:GetCallerIdentity recon, account hijack via legacy root-mfa-bypass.

not rated 11 2mo ago D ✓ AI review 63 tokens copy · 100% Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Azure Managed Identity abuse — IMDS at 169.254.169.254 from compromised VM / App Service / Function, token exchange for Graph/ARM/KeyVault, federated workload identity abuse, hybrid AAD Connect MSOL credential extraction.

not rated 11 2mo ago C 55 tokens copy · 100% Apache-2.0

container

48

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Container / Kubernetes attack category — pod escape, RBAC abuse, runtime CVE exploitation, socket-mount escape. Routing skill: identify the surface (pod-internal RCE vs API-level vs build-pipeline), then load the matching sub-skill.

not rated 11 2mo ago A 53 tokens copy · 92% Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: