mr-pmillz/gogatoz

GitLab Attack Toolkit

This repository also configures its own agents. See what gogatoz tells them →

20Stars on the repository
7Mods indexed here, across every type
yesterdayLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

add-analysis-rule

01

mr-pmillz/gogatoz

Skill Codex

Add a new analysis or false positive rule to GoGatoZ enumerate pipeline. Use when adding detection for new CI/CD vulnerability patterns or false positive suppression rules.

not rated 20 yesterday A 36 tokens

bump-deps

02

mr-pmillz/gogatoz

Skill Codex

Apply a round of Dependabot dependency bumps (npm, GitHub Actions, Go modules) without merging the Dependabot branch. Extracts just the intended changes onto the current branch, avoiding reverts of unrelated work that merged since the PR was opened. Use when processing Dependabot PRs or any grouped dependency update.

not rated 20 yesterday A 68 tokens

ctf-qa-validation

03

mr-pmillz/gogatoz

Skill Codex

QA testing and validation of GoGatoZ features against the local GoGatoZ CTF lab. Invoke for post-change testing, live flag validation, lab infrastructure checks, payload smoke tests, enumerate/attack/search/pivot/notify validation, or any request to confirm that GoGatoZ still works.

not rated 20 yesterday A 68 tokens

mr-pmillz/gogatoz

Skill Codex

Post-process GoGatoZ enumerate results to identify and filter false positives, deduplicate fork clusters, remove noise projects, and produce adjusted severity reports. Use this skill whenever the user mentions "false positive", "filter findings", "clean up results", "verify findings", "noise removal", "deduplicate"…

not rated 20 yesterday A 106 tokens

mr-pmillz/gogatoz

Skill Codex

Use when the user wants to search GitLab projects or scan them for CI/CD security vulnerabilities. Trigger on keywords like "search gitlab", "scan projects", "enumerate", "CI/CD security", "find vulnerabilities", "gitlab recon".

not rated 20 yesterday A 60 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: