Youngmaidainon/Agent-Level-Up

820+ production-grade skills and playbooks for AI coding agents (Antigravity, Claude Code, Cursor). Features DevSecOps, CTF & Security Ops, Full-Stack Architecture, and Caveman token optimizer.

3Stars on the repository
200Mods indexed here, across every type
17d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Identify ransomware-related network indicators, including C2 beaconing patterns, TOR exit node connections, data exfiltration flows, and encryption key exchange, by analyzing Zeek conn.log and NetFlow data. Use when threat hunting for active ransomware network activity or investigating suspected pre-encryption…

not rated 3 17d ago A 72 tokens copy · 94% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution. Use when tracing ransomware bitcoin payments…

not rated 3 17d ago A 75 tokens copy · 86% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parses Software Bill of Materials (SBOM) in CycloneDX and SPDX JSON formats to identify supply chain vulnerabilities by correlating components against the NVD CVE database via the NVD 2.0 API. Builds dependency graphs, calculates risk scores, identifies transitive vulnerability paths, and generates compliance reports.…

not rated 3 17d ago A 110 tokens copy · 95% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. Covers Windows event logs, firewall logs, proxy logs, and authentication data analysis. Activates for requests involving Splunk…

not rated 3 17d ago A 82 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available file-system change activity from USN records. Use during deep forensic analysis of an NTFS image when standard file recovery…

not rated 3 17d ago A 86 tokens copy · 91% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Investigate supply chain attack artifacts including trojanized software updates, compromised build pipelines, and sideloaded dependencies to identify intrusion vectors and scope of compromise.

not rated 3 17d ago A 42 tokens copy · 95% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Systematically map threat actor behavior and observed IOCs to the MITRE ATT&CK framework, build technique coverage heatmaps with the ATT&CK Navigator, identify detection gaps, and produce actionable threat intelligence reports across the Enterprise, Mobile, and ICS matrices. Use when analyzing threat actor TTPs…

not rated 3 17d ago A 95 tokens original MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Map advanced persistent threat (APT) group TTPs to the MITRE ATT&CK framework using the attackcti Python library to query STIX/TAXII data for group-technique associations, then generate ATT&CK Navigator layer files to visualize and compare defensive coverage against adversary profiles. Use when profiling an APT…

not rated 3 17d ago A 99 tokens original MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyzes structured and unstructured threat intelligence feeds to extract actionable indicators, adversary tactics, and campaign context. Use when ingesting commercial or open-source CTI feeds, evaluating feed quality, normalizing data into STIX 2.1 format, or enriching existing IOCs with campaign attribution.…

not rated 3 17d ago A 98 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Query a MISP (Malware Information Sharing Platform) instance via PyMISP to compute event statistics, IOC type breakdowns, threat actor galaxy clusters, and tag trends, and generate threat landscape reports with temporal trends. Use when asked to analyze threat intelligence data, summarize top threat actors or malware…

not rated 3 17d ago A 83 tokens copy · 86% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT. Monitors newly issued certificates for typosquatting and brand impersonation using Levenshtein distance. Use for proactive phishing domain detection and certificate monitoring.

not rated 3 17d ago A 67 tokens original MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Generate domain permutations with dnstwist and check DNS resolution to detect typosquatting, homograph phishing, and brand impersonation domains registered against your organization. Use when asked to monitor for lookalike domains, investigate a phishing domain, or assess brand-impersonation risk.

not rated 3 17d ago A 72 tokens copy · 81% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyzes UEFI bootkit persistence (SPI flash implants, ESP modifications, Secure Boot bypass, UEFI variable manipulation) using chipsec for firmware integrity verification, detecting known families like BlackLotus, LoJax, and MoonBounce. Use for UEFI malware analysis, firmware persistence investigation, or Secure Boot…

not rated 3 17d ago A 77 tokens copy · 95% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Correlate Windows registry keys (USBSTOR, MountedDevices), Event Logs, and setupapi.dev.log to reconstruct USB device connection history, first/last-plugged timestamps, and drive letter mappings. Use when investigating removable media usage, tracking device provenance, or building a timeline for suspected data…

not rated 3 17d ago A 74 tokens copy · 81% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, directory traversal, web scanner fingerprints, and brute-force patterns. Uses regex-based pattern matching against OWASP attack signatures, GeoIP enrichment for source attribution, and statistical anomaly detection for request…

not rated 3 17d ago A 73 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading, including SHA-1 hash correlation with threat intel and timeline reconstruction. Use for Amcache forensics, program execution…

not rated 3 17d ago A 79 tokens copy · 80% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to MITRE ATT&CK techniques. Use when SOC analysts need to investigate Windows-based threats, build detection queries, or…

not rated 3 17d ago A 81 tokens copy · 100% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifiers for forensic timeline reconstruction. Use when investigating recently-accessed files, tracking removable media or network paths referenced by shortcuts, or building a DFIR timeline from LNK…

not rated 3 17d ago A 67 tokens copy · 83% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. Use when investigating renamed or masquerading binaries, verifying program execution timelines, or hunting for suspicious execution patterns in incident…

not rated 3 17d ago A 66 tokens copy · 89% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex needs its repo

Extract and analyze Windows Registry hives with tools like RegRipper and Registry Explorer to uncover user activity, installed software, autostart/persistence entries, and evidence of system compromise. Use when investigating registry-based persistence, reconstructing user or system activity, or performing DFIR triage…

not rated 3 17d ago A 73 tokens copy · 91% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Analyze Windows Shellbag (BagMRU) registry artifacts with SBECmd and Shellbags Explorer to reconstruct folder browsing activity and prove user interaction with directories, including removable media and network shares, even after the folders are deleted. Use when reconstructing a user's folder access history or…

not rated 3 17d ago A 78 tokens copy · 88% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Test RAG vector stores (Pinecone, Qdrant, Weaviate, Chroma, pgvector, FAISS) for embedding inversion, cross-tenant data leakage, and data poisoning per OWASP LLM08:2025. Use when performing an authorized security assessment of a RAG pipeline's retrieval layer or auditing multi-tenant vector-store isolation.

not rated 3 17d ago A 85 tokens copy · 91% MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Enumerate Microsoft Entra ID (Azure AD) tenants with ROADrecon and acquire, exchange, and abuse tokens (including primary refresh tokens) with roadtx. Use for authorized red-team enumeration of a tenant's directory objects or for token-based identity attacks against Entra ID you are explicitly authorized to test.

not rated 3 17d ago A 71 tokens original MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex needs its repo

Run OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID, using TokenTactics-style tooling to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services. Use for authorized red-team engagements simulating device-code or consent-grant phishing against a tenant…

not rated 3 17d ago A 80 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: