.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/shulkwisec/bb-huge
home/skills/shulkwisec/bb-huge
shulkwisec avatar

shulkwisec/bb-huge

58 skills

View on GitHub
$npx skills add shulkwisec/bb-huge
SkillInstalls
2fa-bypassExploit pervasive logical flaws in Multi-Factor Authentication (MFA/2FA) implementations to bypass the secondary authentication challenge entirely.—401-403-bypass-techniquesaccess-controlComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques—active-directory-acl-abuseactive-directory-asreproastingExecute AS-REP Roasting to extract and crack the NTLM hashes of Active Directory user accounts that have the "Do not require Kerberos preauthentication" flag…—active-directory-certificate-servicesactive-directory-dcsync-attackExecute a DCSync attack mimicking the behavior of a legitimate Active Directory Domain Controller (DC).—active-directory-full-attack-chainExecute a complete Active Directory penetration test from initial enumeration to domain dominance.—active-directory-golden-ticketForge highly privileged Kerberos Ticket Granting Tickets (TGTs) to gain persistent, undetectable, and long-term administrative access across an entire Active…—active-directory-kerberoastingExecute a Kerberoasting attack to extract and systematically crack the NTLM hashes of Service Principal Name (SPN) accounts in an Active Directory environment.—active-directory-kerberos-attacksad-asreproast-attackExploit Active Directory environments using AS-REP Roasting. This skill details how to identify user accounts with the 'Do not require Kerberos…—ad-assessmentActive Directory security audit using the MITRE ATT&CK framework.—ad-cs-esc1-abuseExploit Active Directory Certificate Services (AD CS) misconfigurations, specifically ESC1.—ad-dcsync-attackExploit Active Directory replication privileges (DS-Replication-Get-Changes) to perform a DCSync attack, allowing an attacker to impersonate a Domain…—ad-pass-the-hashExploit Active Directory environments using Pass-the-Hash (PtH).—advanced-sql-injection-sqliExecute advanced SQL Injection attacks to bypass WAFs and extract data from complex architectures.—ai-agent-tool-abuse-and-privilege-escalationTest AI agent systems for tool abuse, unauthorized actions, privilege escalation through tool chaining, and safety bypass via agentic workflows.—ai-data-extraction-via-ssrfExploit AI assistants equipped with web-browsing capabilities or internal API plugins to perform Server-Side Request Forgery (SSRF).—ai-data-poisoningExecute and analyze AI Data Poisoning attacks. By subtly injecting malicious or targeted misinformation into an LLM's training or fine-tuning dataset, an…—ai-data-poisoning-model-skewingIdentify and simulate Data Poisoning attacks aimed at degrading or skewing an AI model's accuracy.—ai-jailbreak-obfuscation-ciphersBypass AI safety filters by encoding malicious prompts using ciphers and obfuscation techniques (e.g., Base64, ROT13, Leetspeak, Morse code).—ai-jailbreak-prompt-injectionExecute sophisticated Prompt Injection and Jailbreak techniques against Large Language Models (LLMs) to bypass safety filters, extract system prompts, and…—ai-jailbreak-system-promptsAdvanced techniques for bypassing LLM safety filters, instruction tuning, and system prompt restrictions using specialized linguistic constructs, hypothetical…—ai-ml-securityai-pair-hunting-with-claudeConfigure Claude as a "Pair Hunter" — autonomous overnight hacking, context management via per-target .claudemd files, sub-agent compaction avoidance, and…—ai-prompt-leakingSystematically extract hidden system prompts, core directives, and invisible context intentionally concealed within Large Language Model (LLM) applications.—ai-redteamAI/LLM red-team assessment using the OWASP LLM Top 10 (2025) + OWASP AI Testing Guide (AITG v1, Nov 2025) frameworks, plus OWASP MCP Top 10 runtime testing for…—ai-report-writing-guardrailsPrevent common AI report pitfalls — bug blending, inflated threat models, and generic language.—aikido-triageTriages an Aikido security findings CSV against a local codebase.—amend-skillInspects a skill's SKILL.md and its observations/runs.md log, identifies failure patterns, and proposes a targeted amendment to improve the skill.—amsi-bypassBypass the Windows Antimalware Scan Interface (AMSI) using memory patching, reflection, and obfuscation techniques.—analyze-cveAnalyzes CVE vulnerabilities in project dependencies with code path tracing and PoC generation for Burp Suite.—android-apk-reverse-engineeringDecompile, analyze, and reverse engineer Android applications (APKs).—android-pentesting-tricksanti-debugging-techniquesapi-auth-and-jwt-abuseapi-authentication-bypassTest APIs for authentication and authorization bypass vulnerabilities including JWT manipulation, OAuth2 flaws, API key leakage, broken authentication, and…—api-authorization-and-bolaapi-enumeration-fuzzing-discoverySystematically discover hidden Application Programming Interfaces (APIs), uncover undocumented endpoints (Shadow APIs), and fuzz parameters.—api-mass-assignment-exploitationIdentify and exploit Mass Assignment vulnerabilities in APIs. Use this skill when testing REST APIs or application forms that directly map user-supplied JSON…—api-rate-limit-bypass-techniquesIdentify and exploit flaws in API rate limiting enforcement. Use this skill when encountering HTTP 429 Too Many Requests errors during password brute-forcing,…—api-recon-and-docsapi-secapi-securityDeep API security assessment beyond surface scanning. Covers the full OWASP API Security Top 10 (2023): Broken Object Level Authorization (BOLA / IDOR), Broken…—api-testing-labsComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques—arbitrary-write-to-rceauth-bypassBypass authentication via forced browsing to protected URLs, parameter tampering (authenticated=yes, debug=true, fromtrustIP=true), session ID prediction from…—auth-secauthbypass-authentication-flawsauthenticationComplete PortSwigger deep-dive with exact payloads for every lab variant including zero-day techniques—authz-bypassTest horizontal and vertical authorization bypass via session ID swapping between accounts, IDOR through parameter manipulation (invoice=, user=, menuitem=,…—av-edr-evasion-techniquesBypass antivirus and Endpoint Detection & Response solutions during red team operations using payload obfuscation, process injection, AMSI bypass, ETW…—aws-cloud-penetration-testingPenetration test AWS cloud environments for misconfigurations, privilege escalation, data exposure, and lateral movement.—aws-cognito-abuseExploit misconfigurations in AWS Cognito, specifically focusing on unauthorized identity pool access, user pool self-registration issues, and privilege…—aws-iam-privilege-escalationIdentify and exploit misconfigured Identity and Access Management (IAM) permissions within Amazon Web Services (AWS) to escalate privileges.—aws-imdsv2-ssrf-bypassExploit Server-Side Request Forgery (SSRF) vulnerabilities to extract AWS IAM credentials from the Instance Metadata Service version 2 (IMDSv2).—bb-hugeBug bounty findings secretary, tracker, and workspace initializer for the bb-huge portal.—