Use when operating the metabigor CLI for OSINT recon and infrastructure mapping without API keys. Covers finding network ranges from an ASN, org, domain, or IP (net); enumerating subdomains from certificate logs (cert); enriching IPs with ports/CVEs via Shodan InternetDB (ip); searching public GitHub code for secrets…
A specialized skill for analyzing Windows program files such as EXE, DLL, and driver files, including .NET applications. It covers examining how a program works and looking for security weaknesses.
A security skill for finding web vulnerabilities in user input, browser code, cross-origin settings, and rendered AI or Markdown content. XSS means injected content runs as someone else’s browser code; CSRF tricks a browser into making an unwanted request.
Full-spectrum security research skill for web servers, REST APIs, web applications, and network/port enumeration. Triggers whenever the user wants to: find vulnerabilities, run a security assessment, scan a target, test an API for security issues, enumerate ports or services, check for OWASP Top 10 vulnerabilities…
Full offensive reconnaissance skill for Web Pentest and Bug Bounty. Activate when the user mentions recon, reconnaissance, subdomain enumeration, attack surface mapping, bug bounty recon, or any variation of "start a pentest" on a domain/target. Covers: subdomain enumeration, DNS resolution, live detection…
An asset-discovery workflow that searches Fofa, checks which results are reachable, removes duplicates, and exports the results. Fofa is a search engine for internet-connected systems and services.
Triage recon fingerprint candidates across the bounded DNS catalog surface. Reads private single-domain discovery output, aggregate catalog baselines, or candidate queues, then classifies candidates as pending, promoted, rejected, or deferred under the v2.14 catalog-quality gates. Use when the user asks to find…
Public-metadata domain intelligence - Microsoft 365 / Google Workspace tenant identification, email security configuration (DMARC, DKIM, SPF, MTA-STS, BIMI), SaaS fingerprinting from DNS, certificate-transparency findings, related-domain discovery. Use when a domain name appears alongside phrases like "what does use"…
Use when the user wants a security/exposure check on a domain or website they own or are authorized to test — "audit my site", "what's my attack surface look like", "did anything change on my domain", etc. Drives the nirikshak MCP tools (fullsurfacescan, and the individual checks) and turns raw output into a…