PurpleAILAB/Decepticon

Autonomous Hacking Agent for Red Team

About the project

Decepticon is an autonomous red-team agent that coordinates AI agents, security tools, sandboxes, and supporting services for authorized cybersecurity assessments. Security researchers and red teams can run it through its Docker stack, cloud service, command-line interface, or Python SDK, with the catalogue entries representing its available skills.

5.5kStars on the repository
200Mods indexed here, across every type
13d agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

cicd

145

PurpleAILAB/Decepticon

Skill Claude Code

CI/CD pipeline attack category — poisoned pipeline execution, GitHub Actions expression injection, self-hosted runner abuse, secrets/OIDC exfil. Routing skill: fingerprint the CI provider + workflow surface, then load the matching leaf.

not rated 5.5k +40 13d ago A SkillSpector: pass 49 tokens original Apache-2.0

cicd-secrets-exfil

146

PurpleAILAB/Decepticon

Skill Claude Code

Extracting CI secrets / OIDC tokens once you have code execution in a build job — echo/printenv exfil, log-masking bypass (base64, char-split, reversal), OIDC token abuse to assume cloud roles, GITHUBTOKEN / CIJOBTOKEN scope abuse, cache / artifact secret leakage, provenance pivot.

not rated 5.5k +40 13d ago C SkillSpector: warn 75 tokens original Apache-2.0

PurpleAILAB/Decepticon

Skill Claude Code needs its repo

GitHub Actions ${{ }} expression injection — attacker-controlled context (issue/PR title, body, branch name, commit message) substituted into run: steps, unsafe pullrequesttarget + PR-head checkout, GITHUBTOKEN scope abuse, artifact/cache poisoning, action tag-vs-SHA pinning.

not rated 5.5k +40 13d ago A SkillSpector: warn 65 tokens original Apache-2.0

PurpleAILAB/Decepticon

Skill Claude Code

Poisoned Pipeline Execution (PPE) — direct + indirect: inject commands via attacker-controllable build files (Makefile, package.json scripts, build.gradle, Dangerfile, .pre-commit-config.yaml), abuse pullrequesttarget / fork-PR triggers, and ride dependency / test-script execution on CI.

not rated 5.5k +40 13d ago A SkillSpector: warn 71 tokens original Apache-2.0

crypto-decode

149

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Cipher detection + automated decryption via Ciphey, Cyberchef recipes, hashcat hash-ID, format conversion, common encoding chains.

not rated 5.5k +40 13d ago A SkillSpector: warn 30 tokens original Apache-2.0

ics-ot-overview

150

PurpleAILAB/Decepticon

Skill Claude Code

ICS / OT attack category — Modbus, BACnet, S7Comm, DNP3. Routing skill: fingerprint the industrial protocol by port + Wireshark dissector, then load the matching sub-skill. SAFETY-CRITICAL: always confirm written scope before any write/control class action.

not rated 5.5k +40 13d ago A SkillSpector: warn 67 tokens original Apache-2.0

ics-bacnet

151

PurpleAILAB/Decepticon

Skill Claude Code

BACnet/IP attack — UDP/47808 discovery via Who-Is broadcast, ReadProperty / WriteProperty without auth, BBMD abuse for remote reach, vendor-specific I-Am responses, COV (Change Of Value) subscription flood, Building Automation HMI pivot.

not rated 5.5k +40 13d ago A SkillSpector: warn 57 tokens original Apache-2.0

ics-dnp3

152

PurpleAILAB/Decepticon

Skill Claude Code

DNP3 attack — TCP/20000 (or 19999 serial-over-TCP) outstation enumeration, binary input / analog input poll, control relay output block (CROB) actuation, unsolicited reporting abuse, DNP3 Secure Authentication (DNP3-SA) downgrade, vendor-specific objects.

not rated 5.5k +40 13d ago A SkillSpector: warn 67 tokens original Apache-2.0

enip-cip

153

PurpleAILAB/Decepticon

Skill Claude Code

EtherNet/IP + CIP (TCP 44818 / UDP 2222) attack playbook — List Identity broadcast, pylogix tag-database dump, tag read/write on Allen-Bradley ControlLogix/CompactLogix, CIP Forward Open, PLC mode change (Stop/Run), and historical Rockwell auth-bypass CVEs. North American ICS dominant protocol.

not rated 5.5k +40 13d ago A SkillSpector: warn 81 tokens original Apache-2.0

ics-modbus

154

PurpleAILAB/Decepticon

Skill Claude Code

Modbus TCP attack — port 502 enumeration, coil/holding-register read/write without auth, function-code abuse (FC8 diagnostic, FC43 read-device-id), Modbus-over-Serial via TCP gateway, write-with-no-confirm DoS, value tampering against PLCs.

not rated 5.5k +40 13d ago A SkillSpector: warn 60 tokens original Apache-2.0

opcua

155

PurpleAILAB/Decepticon

Skill Claude Code

OPC-UA (TCP 4840) attack playbook — endpoint enumeration, SecurityPolicy mapping, anonymous/weak-auth abuse, address-space browsing and tag read, HistoryRead exfiltration, Method call for control actions, session-exhaustion DoS. Modern IT/OT DMZ convergence protocol replacing legacy fieldbus.

not rated 5.5k +40 13d ago A SkillSpector: warn 68 tokens original Apache-2.0

profinet

156

PurpleAILAB/Decepticon

Skill Claude Code

PROFINET (L2 EtherType 0x8892 / DCP) attack playbook — DCP Identify-All broadcast enumeration, device fingerprinting, station-name and IP reassignment (breaks IO-controller mapping), flash-LED physical location, factory-reset, RT frame injection/replay for cyclic-IO spoofing. Siemens/EU fieldbus peer of S7Comm…

not rated 5.5k +40 13d ago A SkillSpector: warn 88 tokens original Apache-2.0

ics-s7comm

157

PurpleAILAB/Decepticon

Skill Claude Code

Siemens S7 PLC attack — TCP/102 ISO-TP+S7-COMM, snap7 / python-snap7 enumeration, DB/M/E/A area read+write, PLC stop/start/run, password bypass (S7-300/400 vs S7-1200/1500 differences), CVE chain (e.g., Stuxnet's legacy primitives, CVE-2019-10936).

not rated 5.5k +40 13d ago A SkillSpector: warn 91 tokens original Apache-2.0

exploit-reporting

158

PurpleAILAB/Decepticon

Skill Claude Code

Exploitation finding documentation — initial access reports, exploit chain documentation, CVSS v4.0 scoring, shell/credential inventory, detection gap analysis.

not rated 5.5k +40 13d ago A SkillSpector: warn 35 tokens original Apache-2.0

rmm-tool-abuse

159

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Legitimate RMM tool abuse — deploy or hijack Atera, ScreenConnect, AnyDesk, TeamViewer for persistence, lateral movement, and C2. Leverages trusted software to evade EDR and blend with IT admin traffic.

not rated 5.5k +40 13d ago C SkillSpector: warn 53 tokens original Apache-2.0

supplychain-overview

160

PurpleAILAB/Decepticon

Skill Claude Code

Supply-chain attack category — dependency confusion, typosquatting, package-registry abuse, build-pipeline poisoning, SBOM manipulation.

not rated 5.5k +40 13d ago A SkillSpector: pass 33 tokens original Apache-2.0

dep-confusion

161

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Dependency confusion — publish a higher-version internal package name on public registry (npm/PyPI/Maven/Crates) to coerce CI/CD into pulling attacker code.

not rated 5.5k +40 13d ago A SkillSpector: warn 38 tokens original Apache-2.0

web

162

PurpleAILAB/Decepticon

Skill Claude Code needs its repo

Web application exploitation — the primary category skill for all web-based attacks. This is a routing skill: read this first to identify the attack type, then load the appropriate specialized sub-skill for detailed procedures. Covers 11 technique areas across injection, file access, authentication, and API…

not rated 5.5k +40 13d ago A SkillSpector: warn 60 tokens original Apache-2.0

ato-methodology

163

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Account Takeover decision tree — 9 canonical ATO paths, chaining patterns (IDOR→ATO, XSS→ATO, OAuth→ATO), MFA bypass entry points.

not rated 5.5k +40 13d ago A SkillSpector: pass 39 tokens original Apache-2.0

bfla

164

PurpleAILAB/Decepticon

Skill Claude Code

Broken Function Level Authorization (BFLA) — exploit action-level access control failures where lower-privileged principals invoke admin/staff functions across REST, GraphQL, gRPC, WebSocket, and background job paths.

not rated 5.5k +40 13d ago B SkillSpector: warn 47 tokens original Apache-2.0

blind-sqli

165

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Blind SQL injection under hostile WAF — manual bypass playbook for when sqlmap fails because common tokens (SUBSTRING, IF, AND, WHERE, single quotes) are filtered. Covers token-fingerprinting probe loops, arithmetic-multiplication boolean evaluation, hex-encoded literals, and exponential-probe binary search. Loaded on…

not rated 5.5k +40 13d ago A SkillSpector: pass 88 tokens original Apache-2.0

business-logic

166

PurpleAILAB/Decepticon

Skill Claude Code

Business logic / authentication bypass / privilege escalation — POST body field tampering (role/isadmin/usertype), 2FA bypass via response manipulation, predictable TOTP seeds, hidden authorization headers, multi-step workflow tampering. For challenges tagged businesslogic, privilegeescalation, 2fabypass, or…

not rated 5.5k +40 13d ago B SkillSpector: warn 77 tokens original Apache-2.0

cache-deception

167

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Web cache deception — trick CDN/proxy into caching authenticated responses under unauthenticated URLs, exposing PII to any visitor.

not rated 5.5k +40 13d ago A SkillSpector: pass 29 tokens original Apache-2.0

clickjacking

168

PurpleAILAB/Decepticon

Skill Claude Code

UI redressing — missing X-Frame-Options / frame-ancestors, frame-buster bypass, drag-and-drop, cursorjacking, double-clickjacking, and sensitive-action framing.

not rated 5.5k +40 13d ago A SkillSpector: warn 43 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: