exploit skills

15 tagged exploit, measured the same way as everything else here.

Browse within: codex-cli 8coding-agent 7

cybersecurity-lab

01

handnewb/hermes-cybersec-lab

Skill Claude CodeCodex

Turnkey cybersecurity lab — 2,077 skills, 131+ tools, 28 frameworks, and evolving methodology for security research, pentesting, forensics, and threat intelligence. Includes one-step ecosystem cloner for 8 repositories.

not rated 12 23d ago A 54 tokens original MIT

poc_forge

02

intimatep/PenTestClaw

Skill Claude CodeCodex

A skill for creating proof-of-concept security scripts, meaning small working programs used to demonstrate or test an idea.

not rated 11 5mo ago A 40 tokens

zebbern/termstack

Skill Claude CodeCodex

Cryptographic attack templates for CTF challenges. Provides ready-to-run Python scripts for RSA attacks (small-e, Wiener, Hastad, common modulus, factorization), AES exploitation (ECB byte-at-a-time, CBC bit-flipping, padding oracle), hash attacks (length extension, collision), XOR key recovery, and Z3 constraint…

not rated 5 4mo ago A 110 tokens

zebbern/termstack

Skill Claude CodeCodex

Pwntools exploit boilerplate for CTF binary exploitation. Provides ready-to-use templates for remote/local process interaction, ROP chain construction, format string attacks, shellcode generation, and interactive shell management. Use when writing binary exploits, when connecting to challenge services with pwntools…

not rated 5 4mo ago A 88 tokens

zebbern/termstack

Skill Claude CodeCodex

Network service interaction patterns for CTF — socket clients, multi-round solvers, flag extraction, PoW solvers. Lean skill with on-demand reference files.

not rated 5 4mo ago A 38 tokens

ctf-solver

06

zebbern/termstack

Skill Claude CodeCodex

Solve CTF (Capture The Flag) challenges by analyzing challenge descriptions, source code, and interacting with challenge environments to capture flags.

not rated 5 4mo ago A 31 tokens

idor-poc

07

zebbern/termstack

Skill Claude CodeCodex

Exploit Insecure Direct Object Reference (IDOR) and Broken Object Level Authorization (BOLA) vulnerabilities to access unauthorized resources. IDOR occurs when applications expose internal object references (IDs, filenames) without proper authorization checks.

not rated 5 4mo ago A 3 tokens

lfi-poc

08

zebbern/termstack

Skill Claude CodeCodex

Exploit Local File Inclusion (LFI) vulnerabilities to read sensitive files, execute code, and escalate to Remote Code Execution (RCE). LFI occurs when web applications include files based on user-controlled input without proper sanitization.

not rated 5 4mo ago B 4 tokens

rce-poc

09

zebbern/termstack

Skill Claude CodeCodex

Exploit OS Command Injection vulnerabilities to achieve Remote Code Execution (RCE). Command injection occurs when user input is passed unsafely to system shell commands, allowing attackers to execute arbitrary commands on the target server.

not rated 5 4mo ago B 4 tokens

sqli-poc

10

zebbern/termstack

Skill Claude CodeCodex

Detect and exploit SQL injection vulnerabilities using automated and manual techniques. Use when testing for SQL injection, when parameters appear injectable, when database enumeration is needed, or when proving SQL injection impact.

not rated 5 4mo ago A 42 tokens

ssti-poc

11

zebbern/termstack

Skill Claude CodeCodex

Exploit Server-Side Template Injection (SSTI) vulnerabilities to achieve Remote Code Execution. SSTI occurs when user input is unsafely embedded into server-side templates, allowing attackers to inject template expressions that execute on the server.

not rated 5 4mo ago A 4 tokens

xxe-poc

12

zebbern/termstack

Skill Claude CodeCodex

Exploit XML External Entity (XXE) vulnerabilities to read local files, perform SSRF attacks, and exfiltrate data. XXE occurs when XML parsers process external entity declarations in user-supplied XML input without proper restrictions.

not rated 5 4mo ago D 4 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: