.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/neothecapt/redteamagent
home/skills/neothecapt/redteamagent
neothecapt avatar

neothecapt/redteamagent

31 skills

View on GitHub
$npx skills add neothecapt/redteamagent
SkillInstalls
auth-bypassTest for authentication and authorization flaws including credential attacks, session issues, and access control bypasses—business-logic-testingBusiness logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws—command-injectionOS command injection detection, exploitation, and filter bypass—cors-testingCORS misconfiguration testing for data theft and access control bypass—csrf-testingCross-site request forgery testing for state-changing operations—deserialization-testingInsecure deserialization detection and gadget chain exploitation—directory-fuzzingDiscover hidden directories, files, and endpoints on a web server—file-inclusionDetect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution—file-upload-testingFile upload vulnerability testing — webshells, bypass, path traversal—graphql-testingGraphQL security testing — introspection, injection, auth bypass, DoS—idor-testingInsecure direct object reference testing for broken access control—info-disclosure-testingInformation disclosure detection — error messages, files, headers, debug endpoints—jwt-testingJWT token attack techniques — alg bypass, key confusion, claim tampering—open-redirect-testingTest for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains—osint-reconOpen-source intelligence gathering — CVE lookup, breach search, DNS history, social profiling—parameter-fuzzingDiscover hidden parameters, test values, and identify input handling anomalies—port-scanningDiscover open ports, running services, and their versions on a target—race-condition-testingRace condition and TOCTOU exploitation — parallel request attacks—report-generationEngagement report structure and formatting guidelines—request-smugglingHTTP request smuggling via CL.TE/TE.CL desync and cache poisoning—sensitive-data-detectionDetect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts—source-analysisFrontend source code analysis for hidden routes, API endpoints, and secrets—sqli-testingDetect and exploit SQL injection vulnerabilities in web application parameters—ssrf-testingDetect and exploit server-side request forgery to access internal resources and cloud metadata—ssti-testingServer-side template injection detection, engine identification, and RCE—subdomain-enumerationSubdomain discovery via subfinder, DNS brute-force, and passive sources—user-enumerationDiscover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference—web-reconEnumerate web technologies, headers, endpoints, and metadata from a target—websocket-testingWebSocket security testing — injection, auth bypass, hijacking—xss-testingDetect and exploit cross-site scripting vulnerabilities in web applications—xxe-testingXML external entity injection for file read, SSRF, and DoS—