GitHub user

Agent skills by Encod3d-Sec

Every agent skill Encod3d-Sec publishes on GitHub, ranked by score, with the repositories they come from.
skills
35
repository
1

Repositories by Encod3d-Sec

Skills by Encod3d-Sec, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Skills by Encod3d-Sec, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

Encod3d-Sec/TORCH3291 repo~1.8kAutomated safety check: PassMIT1 mo ago
2

Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

Encod3d-Sec/TORCH3291 repo~1.3kAutomated safety check: PassMIT1 mo ago
3

IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…

Encod3d-Sec/TORCH3291 repo~2.6kAutomated safety check: PassMIT1 mo ago
4

Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

Encod3d-Sec/TORCH329—~611Automated safety check: PassMIT1 mo ago
5

Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

Encod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT1 mo ago
6

Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
7

Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

Encod3d-Sec/TORCH329—~1.6kAutomated safety check: NotesMIT1 mo ago
8

Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop…

Encod3d-Sec/TORCH329—~3.5kAutomated safety check: NotesMIT1 mo ago
9

Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
10

Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: NotesMIT1 mo ago
11

External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan.

Encod3d-Sec/TORCH329—~1.3kAutomated safety check: PassMIT1 mo ago
12

Drive responsible disclosure of a proven finding to a CVE. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~686Automated safety check: PassMIT1 mo ago
13

Evidence hygiene before any FIND moves to Completed or enters a report.

Encod3d-Sec/TORCH329—~700Automated safety check: PassMIT1 mo ago
14

API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago
15

Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /vtibin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation.

Encod3d-Sec/TORCH329—~2.4kAutomated safety check: PassMIT1 mo ago
16

Business-logic flaw hunting - workflow/state bypass, price/quantity tampering, negative/overflow values, coupon/refund abuse, mass assignment, and logic races.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
17

Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)…

Encod3d-Sec/TORCH329—~3.1kAutomated safety check: PassMIT1 mo ago
18

Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking.

Encod3d-Sec/TORCH329—~1.6kAutomated safety check: PassMIT1 mo ago
19

Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
20

OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection.

Encod3d-Sec/TORCH329—~1.8kAutomated safety check: PassMIT1 mo ago
21

GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE.

Encod3d-Sec/TORCH329—~2kAutomated safety check: PassMIT1 mo ago
22

LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
23

Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC…

Encod3d-Sec/TORCH329—~2kAutomated safety check: PassMIT1 mo ago
24

macOS attack hunting - foothold to root/persistence on a macOS host.

Encod3d-Sec/TORCH329—~1.9kAutomated safety check: PassMIT1 mo ago
25

MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta.

Encod3d-Sec/TORCH329—~1.4kAutomated safety check: PassMIT1 mo ago
26

HTTP request smuggling / desync hunting - CL.TE, TE.CL, TE.TE, CL.0, and HTTP/2 downgrade.

Encod3d-Sec/TORCH329—~1.6kAutomated safety check: PassMIT1 mo ago
27

SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection.

Encod3d-Sec/TORCH329—~3.4kAutomated safety check: PassMIT1 mo ago
28

SSRF hunting - OOB-mandatory methodology. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~2.3kAutomated safety check: PassMIT1 mo ago
29

File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS.

Encod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT1 mo ago
30

XSS hunting - reflected, stored, DOM-based. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~1.7kAutomated safety check: PassMIT1 mo ago
31

Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup…

Encod3d-Sec/TORCH329—~1kAutomated safety check: PassMIT1 mo ago
32

Finding validation gate - 7-Question triage adapted for FIND schema.

Encod3d-Sec/TORCH329—~848Automated safety check: PassMIT1 mo ago
33
33.Wiki

Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status.

Encod3d-Sec/TORCH329—~1.1kAutomated safety check: PassMIT1 mo ago
34

Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index.

Encod3d-Sec/TORCH329—~572Automated safety check: PassMIT1 mo ago
35

Ranked next offensive moves from engagement state. An agent skill from Encod3d-Sec/TORCH.

Encod3d-Sec/TORCH329—~204Automated safety check: PassMIT1 mo ago

Questions, answered from the data.

What is the best skill by Encod3d-Sec?

Bug Bounty Campaign Driver from Encod3d-Sec/TORCH ranks first of the 35 skills by Encod3d-Sec listed here, with the highest score: its repository has 329 GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 1.8k tokens and it passes the automated safety check with no findings. Next come Adaptive Web Fuzzing and Hunt Idor.

Are Encod3d-Sec's skills official?

None yet. All 35 skills by Encod3d-Sec listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.