Prohao42/aimy-skill

aimy-skill is a lightweight, embeddable penetration testing assistant skill for AI Agents, designed for automated information gathering and basic vulnerability detection in authorized environments. It can be called by AI assistants such as AutoGPT and LangChain applications, or run independently from the command line.

158Stars on the repository
102Mods indexed here, across every type
2d agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

recon-for-sec

73

Prohao42/aimy-skill

Skill Claude CodeCodex

Entry P1 category router for reconnaissance and methodology. Use when mapping scope, discovering assets, fingerprinting technology, building endpoint inventory, and choosing the first high-value security testing path.

not rated 158 +23 2d ago A 41 tokens

request-smuggling

74

Prohao42/aimy-skill

Skill Claude CodeCodex

HTTP request smuggling and desynchronization testing. Use when front proxies, CDNs, or load balancers disagree with the origin on message framing (Content-Length vs Transfer-Encoding), on HTTP/2→HTTP/1 translation, or when exploring client-side desync via browser fetch pipelines.

not rated 158 +23 2d ago B 62 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Reverse shell techniques playbook. Use when establishing remote shells including language one-liners, encrypted shells (OpenSSL/socat/ncat), web shells, PTY upgrades, file transfer methods, PowerShell shells, and Windows payload generation.

not rated 158 +23 2d ago C 52 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to recover plaintext by exploiting weak keys, small exponents, shared factors, or padding oracles.

not rated 158 +23 2d ago A 53 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

not rated 158 +23 2d ago A 44 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex ⚠ unsafe

Sandbox escape playbook. Use when breaking out of Python sandbox, Lua sandbox, seccomp filter, chroot jail, container/Docker, browser sandbox, or namespace isolation to achieve unrestricted code execution or file access.

not rated 158 +23 2d ago E ⚑ AI: unsafe 49 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack patterns.

not rated 158 +23 2d ago A 46 tokens

sqli-sql-injection

80

Prohao42/aimy-skill

Skill Claude CodeCodex

SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.

not rated 158 +23 2d ago A 39 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.

not rated 158 +23 2d ago A ✓ AI review 45 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

SSTI playbook. Use when template expressions, server-side rendering, preview features, or templating engines may evaluate attacker-controlled content.

not rated 158 +23 2d ago B 36 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Stack overflow and ROP playbook. Use when exploiting buffer overflows to hijack control flow via return address overwrite, ROP chains, ret2libc, ret2csu, ret2dlresolve, or SROP on Linux userland binaries.

not rated 158 +23 2d ago A 59 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Steganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audio (spectrogram, DTMF), files (polyglots, appended data, ADS), and text (whitespace, zero-width, homoglyphs) for hidden data.

not rated 158 +23 2d ago A 70 tokens

subdomain-takeover

85

Prohao42/aimy-skill

Skill Claude CodeCodex

Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned cloud resources, expired third-party services, or unclaimed SaaS tenants that an attacker can register to serve content under the victim's domain.

not rated 158 +23 2d ago A 61 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Symbolic execution and constraint solving playbook. Use when solving CTF reversing challenges, recovering keys, bypassing checks, or automating binary analysis with angr, Z3, or Unicorn Engine.

not rated 158 +23 2d ago A 45 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Symmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-and-paste, bit flipping), stream cipher key reuse, or meet-in-the-middle attacks.

not rated 158 +23 2d ago A 47 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Traffic analysis and PCAP forensics playbook. Use when analyzing network captures including Wireshark filters, protocol analysis (HTTP/DNS/FTP/SMTP/USB/WiFi), data extraction, covert channel detection, PCAP repair, TLS decryption, and tshark command-line analysis.

not rated 158 +23 2d ago D 64 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.

not rated 158 +23 2d ago B 59 tokens

type-juggling

90

Prohao42/aimy-skill

Skill Claude CodeCodex

PHP type juggling and weak comparison (==) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.

not rated 158 +23 2d ago A 54 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Unauthorized access playbook for common exposed services. Use when Redis, Rsync, PHP-FPM, AJP/Ghostcat, Hadoop YARN, H2 Console, or similar management interfaces are exposed without authentication.

not rated 158 +23 2d ago A 49 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Insecure file upload playbook. Use when testing upload validation, storage paths, processing pipelines, preview behavior, overwrite risks, and upload-to-RCE chains.

not rated 158 +23 2d ago C 37 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

Custom VM and bytecode reverse engineering playbook. Use when CTF challenges or protected software implement custom virtual machines with proprietary bytecode, dispatcher loops, or maze-style challenges.

not rated 158 +23 2d ago A 42 tokens

Prohao42/aimy-skill

Skill Claude CodeCodex

WAF bypass methodology and generic evasion techniques. Use when a web application firewall blocks injection payloads (SQLi, XSS, RCE) and you need to craft bypasses using encoding, protocol-level tricks, or WAF-specific weaknesses.

not rated 158 +23 2d ago A 57 tokens

web-cache-deception

95

Prohao42/aimy-skill

Skill Claude CodeCodex

Web cache deception and poisoning playbook. Use when CDN, reverse proxy, or application caching may serve sensitive authenticated content to other users due to path confusion or cache key manipulation.

not rated 158 +23 2d ago A 40 tokens

websocket-security

96

Prohao42/aimy-skill

Skill Claude CodeCodex

WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.

not rated 158 +23 2d ago A 46 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: