MingyiSecLab/Mingyi-Atlas

Harness-driven terminal AI agent for authorized security assessment, with TUI, headless automation, persistent context, 150 built-in skills, and a dedicated pentest mode.

This repository also configures its own agents. See what Mingyi-Atlas tells them →

11Stars on the repository
156Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

lfi

97

MingyiSecLab/Mingyi-Atlas

Skill Claude Code needs its repo

Path traversal and Local File Inclusion (LFI) — arbitrary file reading via directory traversal, PHP filter/input/data wrappers for RCE, log poisoning, static resource disclosure, and information leakage. Use for any challenge involving file path manipulation, ../ traversal, local file read, PHP wrappers, or sensitive…

not rated 11 2mo ago D 66 tokens copy · 100% Apache-2.0

mass-assignment

98

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Mass assignment + ORM leak — inject extra fields into create/update requests, escalate to admin, leak protected fields via response.

not rated 11 2mo ago A 28 tokens copy · 100% Apache-2.0

nosqli

99

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

NoSQL injection — MongoDB operator injection ($ne, $gt, $where, $regex), CouchDB / Firebase / Redis attack patterns, auth bypass, blind extraction.

not rated 11 2mo ago A 38 tokens copy · 100% Apache-2.0

oauth

100

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

OAuth 2.0 / OIDC attacks — redirecturi bypass, state CSRF, code leak via Referer, responsetype confusion, PKCE downgrade, scope creep, ATO chains.

not rated 11 2mo ago A 41 tokens copy · 100% Apache-2.0

open-redirect

101

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Open redirect + tabnabbing — URL filter bypass, OAuth chain extension, phishing infrastructure-free, SSRF chain.

not rated 11 2mo ago A 27 tokens copy · 98% Apache-2.0

proxy-misconfig

102

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Reverse proxy misconfigurations — nginx alias traversal, Apache modrewrite SSRF, Spring Boot Actuator exposure, Tomcat manager, IIS short-name disclosure.

not rated 11 2mo ago C 37 tokens copy · 94% Apache-2.0

race-condition

103

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Race condition / TOCTOU exploitation — concurrent and parallel-request attacks against web applications that check then act, write session state before validating it, or perform slow operations that widen the race window. Covers single-endpoint races (double-spend, coupon abuse, balance overflow) and multi-endpoint…

not rated 11 2mo ago A 80 tokens copy · 97% Apache-2.0

saml

104

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

SAML 2.0 attacks — XSW (XML Signature Wrapping) variants 1-8, comment injection, signature stripping, assertion forgery, IdP metadata abuse.

not rated 11 2mo ago A 40 tokens copy · 100% Apache-2.0

smuggling

105

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

HTTP Request Smuggling (HRS) — front-end / back-end parser disagreement attacks that desync the proxy stack. Covers CL.TE, TE.CL, TE.TE, CL.0, HTTP/2 downgrade (h2.cl, h2.te), pipelining, and connection-state pinning. Includes a confirm-desync gate, header obfuscation catalog, and minimal raw-socket Python harnesses…

not rated 11 2mo ago B 97 tokens copy · 95% Apache-2.0

sqli

106

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

SQL Injection — automated and manual exploitation of unsanitized SQL queries. Covers Union-based, Error-based, Blind (Boolean/Time-based), and Stacked queries. Includes sqlmap automation with WAF bypass tamper scripts.

not rated 11 2mo ago A 48 tokens copy · 91% Apache-2.0

ssrf-exploitation

107

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Server-Side Request Forgery (SSRF) — exploiting server-side URL fetching to access internal services, cloud metadata (AWS/GCP/Azure), internal APIs, and port scanning. Covers IP bypass techniques, DNS rebinding, Gopher protocol smuggling, and redirect-based bypass.

not rated 11 2mo ago A ✓ AI review 62 tokens original Apache-2.0

ssti-exploitation

108

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex needs its repo

Server-Side Template Injection (SSTI) — RCE through template engines. Covers Jinja2 (Python/Flask), Twig (PHP/Symfony), Freemarker (Java), ERB (Ruby), Razor (.NET). Includes engine fingerprinting, MRO chain construction, and filter bypass.

not rated 11 2mo ago A 68 tokens original Apache-2.0

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Web crypto exploitation — padding-oracle (Vaudenay), AES-CBC bit-flipping / IV manipulation, AES-ECB pattern attacks (cut-and-paste, prefix/suffix recovery), HMAC bypass, hash-length extension, JWT alg confusion. Covers detection signals, working in-file Python harnesses (concurrent.futures, timeout=5, python3 -u…

not rated 11 2mo ago A 97 tokens original Apache-2.0

xpath-xslt

110

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

XPath + XSLT injection — query manipulation in XML data stores, server-side XSLT RCE via document() / EXSLT extensions.

not rated 11 2mo ago A 34 tokens copy · 95% Apache-2.0

xs-leaks

111

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

XS-Leaks — cross-site information leaks via timing, frame counting, navigation, error oracles. Side-channel attacks against same-origin authenticated state.

not rated 11 2mo ago A 33 tokens copy · 98% Apache-2.0

xss

112

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Cross-Site Scripting (XSS) — reflected, stored, DOM-based XSS exploitation. Covers filter bypass, CSP evasion, bot-triggered cookie exfiltration, admin page scraping, and headless browser flag extraction. Use for any challenge involving client-side JavaScript injection, Cross payloads, cookie theft, or browser-based…

not rated 11 2mo ago B 73 tokens copy · 88% Apache-2.0

xxe-exploitation

113

MingyiSecLab/Mingyi-Atlas

Skill Claude Code needs its repo

XML External Entity (XXE) injection — local file reading via XML parsers, SOAP/WSDL API exploitation, blind out-of-band exfiltration, SVG/DOCX/XLSX upload XXE. Use for any challenge involving XML processing, SOAP endpoints, WSDL services, or XML-based file upload parsing.

not rated 11 2mo ago B 69 tokens original Apache-2.0

mobile

114

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Mobile application red team category — Android (APK) and iOS (IPA) pentest. Routing skill: identifies the platform + attack surface, then loads the matching sub-skill.

not rated 11 2mo ago A 39 tokens original Apache-2.0

android

115

MingyiSecLab/Mingyi-Atlas

Skill Claude CodeCodex

Android APK pentest workflow — apktool/jadx static, Frida dynamic instrumentation, SSL pinning bypass, root detection bypass, intent fuzzing, keystore extraction.

not rated 11 2mo ago B 36 tokens original Apache-2.0

c2-sliver

116

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Sliver C2 framework operations — server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles.

not rated 11 2mo ago A 38 tokens original Apache-2.0

c2

117

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Framework-agnostic C2 orchestration — listener types, implant modes, redirector architecture, malleable profiles, jitter strategy, OPSEC guidance.

not rated 11 2mo ago A 34 tokens original Apache-2.0

havoc

118

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Havoc C2 framework (C5pider/Havoc) — modern Sliver/CS alternative, Demon agent with indirect syscalls, sleep obfuscation (Ekko/Zilean/FOLIAGE), Donut PIC loader integration, profile-driven HTTP comms, MaterialUI web client. Best when you need modern OPSEC without Cobalt Strike cost.

not rated 11 2mo ago A 77 tokens original Apache-2.0

mythic

119

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Mythic C2 framework operations — multi-agent (Apfell, Apollo, Athena, Poseidon, Medusa), web UI on 7443, RabbitMQ + PostgreSQL backend, JSON-RPC tasking model, building an agent via mythic-cli, profile design (HTTP/SMB/named pipe/peer-to-peer), opsec defaults. Comparison to Sliver: more pluggable, less polished UI.

not rated 11 2mo ago B 90 tokens original Apache-2.0

credential-access

120

MingyiSecLab/Mingyi-Atlas

Skill Claude Code

Credential extraction and capture — LSASS dumping, SAM/SECURITY hive extraction, DPAPI decryption, NTLM relay, Responder poisoning, password spraying, hash cracking.

not rated 11 2mo ago B 38 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: