.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/transilienceai/communitytools
home/skills/transilienceai/communitytools
transilienceai avatar

transilienceai/communitytools

48 skills

View on GitHub
$npx skills add transilienceai/communitytools
SkillInstalls
ai-threat-testingOffensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection,…—api-securityAPI security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.—attack-path-stitcherStitches confirmed single-asset findings into multi-hop attack paths across the organization.—authenticated-session-acquisitionauthenticationAuthentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.—backendBackend tech-stack identification — web servers, runtimes, languages, frameworks, databases, APIs, and CMS via HTTP headers, cookies, error pages, and API…—blockchain-securitySmart contract security testing and blockchain CTF exploitation.—client-sideClient-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.—cloud-containersCloud and container security testing - AWS, Azure, GCP, Docker, and Kubernetes misconfigurations and exploitation.—cloud-defenseDetect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the…—coordinationPentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.—correlationCorrelation, confidence scoring, and conflict resolution across all tech-stack signals. Cross-validates and assigns High/Medium/Low confidence per technology.—cryptographyCryptanalysis techniques — lattice attacks, padding oracles, weak-RNG exploitation, signature forgery, secret-sharing recovery.—cve-poc-generatorCVE research, standalone PoC script and report generation. Given a CVE ID, researches NVD and advisories, generates a safe Python PoC, and writes a detailed…—cve-risk-scoreRetrieve CVE risk scores from NVD. Auto-invoked whenever a CVE ID is mentioned to display CVSS score, severity, CWE, and description.—dfirDigital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline…—essential-toolsCore pentesting tools and methodology - Burp Suite usage, Playwright automation, binary analysis, testing methodology, and professional reporting standards.—firewall-reviewClaude-native firewall ruleset audit playbook — 17 vendor-agnostic detectors across FortiGate / PAN-OS / Cisco ASA·IOS / Azure NSG / AWS SG / iptables, with…—frontendFrontend tech-stack identification — JavaScript frameworks, meta-frameworks, CSS frameworks, UI libraries, build tools, and CMS via DOM, JS globals, HTML, and…—github-workflowGitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.—hackeroneHackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission…—hacktheboxHackTheBox platform operations and automations to solve challenges, machines and capture the flags hacking competitions—infraInfrastructure tech-stack identification — cloud providers, CDN/WAF, DNS services, TLS/CT, DevOps tooling, plus asset discovery (domains, subdomains, IPs).—infrastructureNetwork infrastructure testing - port scanning, DNS attacks, MITM, VLAN hopping, IPv6, SMB/NetBIOS, sniffing, and DoS assessment.—injectionInjection vulnerability testing - SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection techniques.—mobile-securityMobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native…—network-appliance-offensiveosintOpen-source intelligence gathering - company repository enumeration, secret scanning, git history analysis, employee footprint, and code exposure discovery.—patt-fetcherFetches and extracts payloads from PayloadsAllTheThings on demand. Bake into executor prompts for live payload enrichment.—pci-secure-softwareAutomated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.—pentest-engagementRun a professional penetration engagement OR a network vulnerability scan from a scope.—protect-with-passwordreconnaissanceDomain assessment and web application mapping - subdomain discovery, port scanning, endpoint enumeration, API discovery, and attack surface analysis.—regression-sweepRe-validates every previously-confirmed finding against its current target — detects drift (patched, mitigated, re-introduced).—reverse-engineeringStatic and dynamic reverse engineering — ELF/PE analysis, custom-VM bytecode, packed binaries, anti-debug bypass, Frida hooking.—risk-prioritiserRisk-based prioritisation of confirmed attack paths. Combines exploit feasibility, technical CVSS severity, and asset business impact into a single ranked list…—script-generatorGenerates optimized, syntax-validated scripts on demand. Never executes — only generates, optimizes, and validates.—securitySecurity-posture and third-party SaaS identification — security headers, CSP, HSTS, email auth, security.txt, plus payments/analytics/auth/CRM/support…—server-sideServer-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.—skill-pruneIdentify and remove negative-ROI skill content — orphan files, never-read entries, duplicates, content reintroducing challenge-specific lore.—skill-updateSkill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits.—social-engineeringSocial engineering testing - phishing, pretexting, vishing, and physical security assessment techniques.—source-code-scanningSecurity-focused source code review and SAST. Scans for vulnerabilities (OWASP Top 10, CWE Top 25), CVEs in third-party dependencies/packages, hardcoded…—systemSystem exploitation testing - Active Directory attacks, privilege escalation (Linux/Windows), and exploit development.—techstack-identificationOSINT-based technology stack identification. Routes to 6 domain sub-skills (frontend, backend, infra, security, osint, correlation) to discover a target's…—ti-ingestThreat-intel signal ingest — converts a CVE + affected-asset + claim payload into a queued engagement-scope row for the validation pipeline.—transilience-report-styleThreat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.—web-app-logicWeb application logic testing - business logic flaws, race conditions, access control, cache poisoning/deception, and information disclosure.—