Youngmaidainon/Agent-Level-Up

820+ production-grade skills and playbooks for AI coding agents (Antigravity, Claude Code, Cursor). Features DevSecOps, CTF & Security Ops, Full-Stack Architecture, and Caveman token optimizer.

3Stars on the repository
200Mods indexed here, across every type
17d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat.

not rated 3 17d ago A 48 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Detonate malware samples in Cuckoo Sandbox to observe runtime behavior — process creation, file system and registry changes, network communications, and API calls — and generate behavioral reports for classification and IOC extraction. Use when a sample has passed static triage and needs dynamic/behavioral analysis…

not rated 3 17d ago A 93 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Query the Malpedia API to look up malware family aliases and naming (platform.familyname), pull community/vendor YARA rules, link families to threat actors, and map family relationships such as loader-payload chains and shared authorship. Use when researching a malware family's aliases, lineage, or actor attribution…

not rated 3 17d ago A 82 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Use Sysinternals Autoruns to systematically enumerate and analyze malware persistence mechanisms across Windows registry run keys, scheduled tasks, services, drivers, and startup locations. Use when hunting for persistence during Windows incident response, triaging a compromised endpoint, or validating that malware…

not rated 3 17d ago A 74 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Detect sandbox and VM evasion techniques in malware samples by analyzing timing checks, VM/hypervisor artifact queries, user-interaction checks, and sleep-inflation patterns from Cuckoo or AnyRun behavioral reports. Use when a sample shows no or minimal activity in a sandbox, when a behavioral report needs review for…

not rated 3 17d ago A 89 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. Supports Windows, Linux, and macOS memory forensics. Activates for requests involving memory forensics, RAM analysis…

not rated 3 17d ago C 80 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.

not rated 3 17d ago A 71 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyze the NTFS Master File Table ($MFT) with MFTECmd, analyzeMFT, and X-Ways Forensics to recover metadata and content of deleted files by examining MFT record entries, $LogFile, $UsnJrnl, and MFT slack space. Use when recovering evidence of deleted files, reconstructing NTFS file-system timelines, or detecting…

not rated 3 17d ago A 100 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Detect and analyze covert communication channels used by malware, including DNS tunneling, ICMP exfiltration, steganographic HTTP, and other protocol abuse used for C2 and data exfiltration. Use when investigating suspicious DNS/ICMP/HTTP traffic patterns, hunting for hidden C2 channels in network captures, or…

not rated 3 17d ago A 90 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse NetFlow v9 and IPFIX records to detect volumetric anomalies, port scanning, data exfiltration, and C2 beaconing patterns. Uses the Python netflow library to decode flow records, builds traffic baselines, and applies statistical analysis to identify flows with abnormal byte counts, connection durations, and…

not rated 3 17d ago A 76 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. Use when performing authorized network reconnaissance, protocol-level forensic analysis, or building traffic anomaly detection during…

not rated 3 17d ago A 75 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and exploitation attempts. Uses Wireshark, Zeek, and NetFlow analysis techniques. Activates for requests involving network traffic…

not rated 3 17d ago A 91 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement patterns using Wireshark, Zeek, and Suricata. Activates for requests involving malware network analysis, C2 traffic decoding…

not rated 3 17d ago A 81 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.

not rated 3 17d ago B 49 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the Recoverable Items folder. Use when conducting email forensic investigations, legal e-discovery, or incident response that…

not rated 3 17d ago A 83 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Identifies and unpacks UPX-packed malware samples, including binaries with modified UPX magic bytes or headers that block automated decompression, to recover the original executable for static analysis. Use when a sample shows high entropy, minimal imports, or only LoadLibrary/GetProcAddress in its import table, or…

not rated 3 17d ago A 88 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious…

not rated 3 17d ago A 84 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Scan Linux systems for persistence mechanisms including crontab/systemd entries, LDPRELOAD injection, shell profile modifications (.bashrc, .profile), and SSH authorizedkeys backdoors, then correlate findings with auditd logs into an installation timeline. Use during incident response or threat hunting to detect or…

not rated 3 17d ago A 82 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string, Base64-encoded WebClient/FromBase64String payloads, known module invocations (Invoke-Mimikatz, Invoke-Kerberoast), and staging URL…

not rated 3 17d ago A 99 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scripts, applies entropy analysis and pattern matching for Base64-encoded commands, Invoke-Expression…

not rated 3 17d ago A 88 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a…

not rated 3 17d ago A 98 tokens copy · 91% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyzes encryption algorithms, key management, and file encryption routines used by ransomware families to assess decryption feasibility, identify implementation weaknesses, and support recovery efforts. Covers AES, RSA, ChaCha20, and hybrid encryption schemes. Activates for requests involving ransomware…

not rated 3 17d ago A 79 tokens copy · 95% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Safely monitor ransomware group Tor-hosted data leak sites (DLS) to collect and extract structured victim posting data, track group activity trends over time, and produce sector- and geography-specific ransomware risk assessments. Use when performing threat intelligence gathering on active ransomware groups or…

not rated 3 17d ago A 77 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: