PurpleAILAB/Decepticon

Autonomous Hacking Agent for Red Team

About the project

Decepticon is an autonomous red-team agent that coordinates AI agents, security tools, sandboxes, and supporting services for authorized cybersecurity assessments. Security researchers and red teams can run it through its Docker stack, cloud service, command-line interface, or Python SDK, with the catalogue entries representing its available skills.

5.5kStars on the repository
200Mods indexed here, across every type
13d agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

waf-bypass

193

PurpleAILAB/Decepticon

Skill Claude Code

WAF evasion — payload obfuscation, HTTP-level evasion, origin-IP discovery, rate/anomaly evasion, per-WAF notes (Cloudflare/Akamai/AWS WAF/ModSecurity).

not rated 5.5k +40 13d ago A SkillSpector: warn 48 tokens original Apache-2.0

web-cache-poisoning

194

PurpleAILAB/Decepticon

Skill Claude Code

Unkeyed-input cache poisoning — X-Forwarded-Host/Scheme/Port, X-Original-URL, fat-GET, parameter cloaking, oversized-header DoS, and chains to stored-XSS / open redirect via shared caches.

not rated 5.5k +40 13d ago A SkillSpector: pass 56 tokens original Apache-2.0

xpath-xslt

195

PurpleAILAB/Decepticon

Skill Claude CodeCodex

XPath + XSLT injection — query manipulation in XML data stores, server-side XSLT RCE via document() / EXSLT extensions.

not rated 5.5k +40 13d ago A SkillSpector: warn 34 tokens original Apache-2.0

xs-leaks

196

PurpleAILAB/Decepticon

Skill Claude CodeCodex

XS-Leaks — cross-site information leaks via timing, frame counting, navigation, error oracles. Side-channel attacks against same-origin authenticated state.

not rated 5.5k +40 13d ago A SkillSpector: pass 33 tokens original Apache-2.0

xss

197

PurpleAILAB/Decepticon

Skill Claude Code

Cross-Site Scripting (XSS) — reflected, stored, DOM-based XSS exploitation. Covers filter bypass, CSP evasion, bot-triggered cookie exfiltration, admin page scraping, and headless browser flag extraction. Use for any challenge involving client-side JavaScript injection, Cross payloads, cookie theft, or browser-based…

not rated 5.5k +40 13d ago B SkillSpector: warn 73 tokens original Apache-2.0

ics-overview

198

PurpleAILAB/Decepticon

Skill Claude CodeCodex

Use when the target is an industrial control system or operational technology network running Modbus, BACnet, S7Comm/S7Comm Plus, DNP3, OPC-UA, or any PLC/HMI/SCADA stack. Engagements MUST set RoE flag industrialsafetycritical=true; this catalog gates every write-scope operation behind explicit operator confirmation…

not rated 5.5k +40 13d ago A SkillSpector: pass 81 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: