bob-debug
01Skill Claude CodeCodex
Debug a completed or stuck Hacker Bob session — pipeline quality, drift, failures, improvements.
102 tagged fuzzing, measured the same way as everything else here.
Browse within: penetration-testing 61reconnaissance 61bugbounty 60reverse-engineering 60web-security 60audithub 16blockchain-security 16appsec 8CVE 7
Skill Claude CodeCodex
Debug a completed or stuck Hacker Bob session — pipeline quality, drift, failures, improvements.
Skill Claude CodeCodex
Headless Bob diff-review pipeline — invoked by bob-runner.ts via 'claude --dangerously-skip-permissions --print "/bob-diff-review -- ..."'. Ingests a unified diff, initializes a Bob repo session, builds the symbol surface index, maps changed hunks to impacted surfaces, spawns per-surface evaluator agents, and…
Skill Claude CodeCodex
Hacker Bob orchestrator runtime — invoked by /bob-evaluate. Do not call directly.
Skill Claude CodeCodex
Exhaustively test a target against every applicable CWE.
Skill Claude CodeCodex
Drive extroosint with the right kind, feeds, pivots, and keys.
Skill Claude CodeCodex
Run a scoped pentest with NmapIt, Burp, Metasploit, and a written report.
Skill Claude CodeCodex
Select and implement a layered security testing strategy for a codebase: design unit tests for security properties (boundary conditions, negative inputs, access control invariants), set up integration testing with non-production seed data (avoiding the production data copy anti-pattern), choose and configure dynamic…
Skill Claude CodeCodex
Generate best-effort DeFi Vanguard custom detectors from English security invariants for Solidity projects. Use when the user provides invariant lists, properties, protocol rules, assumptions, or expected behaviors and wants them converted into PAQL or Detector.register Luau detectors, usually one detector per…
Skill Claude CodeCodex
Coordinate full or multi-stage AuditHub OrCa fuzzing campaigns for Solidity projects. Use when a user asks to run an autonomous OrCa campaign, plan and execute setup/tuning/spec/long-run loops, resume an OrCa campaign, or coordinate target selection, deployment setup, smoke runs, callmetrics.json analysis, tuning, [V]…
Skill Claude CodeCodex
Prepare live-state OrCa campaign inputs for deployed Solidity contracts. Use when a campaign will fuzz on-chain state, needs chain/block/address/name/ABI data, needs Etherscan or explorer ABI handling, needs proxy implementation ABI resolution, or needs on-chain deployment JSON validation.
Skill Claude CodeCodex
Run the two-role, agent-driven UX walkthrough of the HexGraph web UI against the living contract in docs/dev/ux-contract.md. Use this on every major UI change, fix evaluation, or release: one agent (the VR analyst) drives HexGraph the way a researcher's agent would and populates every surface; a second, separate agent…
Skill Claude CodeCodex
Dynamic testing framework that generates random inputs to discover vulnerabilities and invariant violations in smart contracts.
Skill Claude CodeCodex
Agentic LLDB fuzzer and crash-triage toolkit for Apple Mach-O on arm64(e). Use this skill whenever a user mentions alf, wants an AI agent to drive LLDB over MCP, asks about triaging a crash on macOS, wants to fuzz a Mach-O target with LLM guidance, is debugging a macOS kernel via Virtualization.framework / KDP /…
Skill Claude CodeCodex
Agentic LLDB fuzzer and crash-triage toolkit for Apple Mach-O on arm64(e). Use this skill whenever a user mentions alf, wants an AI agent to drive LLDB over MCP, asks about triaging a crash on macOS, wants to fuzz a Mach-O target with LLM guidance, is debugging a macOS kernel via Virtualization.framework / KDP /…