GitHub user
Agent skills by Encod3d-Sec
- skills
- 35
- repository
- 1
Repositories by Encod3d-Sec
Skills by Encod3d-Sec, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn. | Encod3d-Sec/ | 329 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 2 | Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses. | Encod3d-Sec/ | 329 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 3 | IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and… | Encod3d-Sec/ | 329 | 1 repo | ~2.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 4 | Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures. | Encod3d-Sec/ | 329 | — | ~611 | Automated safety check: Pass | MIT | 1 mo ago |
| 5 | Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 6 | Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 7 | Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely. | Encod3d-Sec/ | 329 | — | ~1.6k | Automated safety check: Notes | MIT | 1 mo ago |
| 8 | Shared discipline for every hunt- skill: scope and authorization gating, the two-account rule, the confirmation gate that separates a real finding from a false positive, enumeration limits, stop… | Encod3d-Sec/ | 329 | — | ~3.5k | Automated safety check: Notes | MIT | 1 mo ago |
| 9 | 9.Research Vulnerability-research loop toward a novel CVE. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 10 | Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 11 | 11.Wiki Recon External recon and OSINT pipeline - subdomain enum, live host discovery, URL crawl, JS analysis, nuclei scan. | Encod3d-Sec/ | 329 | — | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 12 | 12.Disclosure Drive responsible disclosure of a proven finding to a CVE. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~686 | Automated safety check: Pass | MIT | 1 mo ago |
| 13 | 13.Evidence Evidence hygiene before any FIND moves to Completed or enters a report. | Encod3d-Sec/ | 329 | — | ~700 | Automated safety check: Pass | MIT | 1 mo ago |
| 14 | 14.Hunt API API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 15 | 15.Hunt Auth Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /vtibin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation. | Encod3d-Sec/ | 329 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 16 | Business-logic flaw hunting - workflow/state bypass, price/quantity tampering, negative/overflow values, coupon/refund abuse, mass assignment, and logic races. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 17 | 17.Hunt Burp Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)… | Encod3d-Sec/ | 329 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 18 | 18.Hunt Cache Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking. | Encod3d-Sec/ | 329 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 19 | Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 20 | OAuth and SAML attack hunting - redirecturi bypass, state CSRF, SAML XSW (XSW1-XSW8), signature stripping, comment injection. | Encod3d-Sec/ | 329 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 21 | GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE. | Encod3d-Sec/ | 329 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 22 | 22.Hunt LLM LLM / AI application attack hunting - prompt injection (direct + indirect), excessive agency, insecure output handling, system-prompt + data leakage. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 23 | 23.Hunt M365 Microsoft 365 / Entra ID attack - tenant discovery, user enumeration via OneDrive differential (2026 verified), AADSTS code reference, Smart Lockout math (hard cap 1-2 attempts/user), ROPC… | Encod3d-Sec/ | 329 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 24 | 24.Hunt macOS macOS attack hunting - foothold to root/persistence on a macOS host. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 25 | 25.Hunt MCP MCP server attack hunting - tool poisoning, indirect prompt injection via tool output, rug-pull updates, cross-tool shadowing, over-permissioned/excessive-agency tools, lethal trifecta. | Encod3d-Sec/ | 329 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 26 | HTTP request smuggling / desync hunting - CL.TE, TE.CL, TE.TE, CL.0, and HTTP/2 downgrade. | Encod3d-Sec/ | 329 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 27 | 27.Hunt Sqli SQLi and NoSQLi hunting - error-based, boolean-blind, time-based, UNION, NoSQL operator injection. | Encod3d-Sec/ | 329 | — | ~3.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 28 | 28.Hunt Ssrf SSRF hunting - OOB-mandatory methodology. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 29 | 29.Hunt Upload File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS. | Encod3d-Sec/ | 329 | — | ~1.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 30 | 30.Hunt Xss XSS hunting - reflected, stored, DOM-based. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | 31.Metasploit Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup… | Encod3d-Sec/ | 329 | — | ~1k | Automated safety check: Pass | MIT | 1 mo ago |
| 32 | 32.Triage Finding validation gate - 7-Question triage adapted for FIND schema. | Encod3d-Sec/ | 329 | — | ~848 | Automated safety check: Pass | MIT | 1 mo ago |
| 33 | 33.Wiki Search, query, and maintain the qmd-indexed wiki - semantic search, keyword search, re-index after adding pages, check index status. | Encod3d-Sec/ | 329 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 34 | Ingest a CVE writeup, blog post, advisory, or GitHub repo into the wiki - fetch, dedup via sources:, update the right technique/tool page(s), re-index. | Encod3d-Sec/ | 329 | — | ~572 | Automated safety check: Pass | MIT | 1 mo ago |
| 35 | 35.Next Move Ranked next offensive moves from engagement state. An agent skill from Encod3d-Sec/TORCH. | Encod3d-Sec/ | 329 | — | ~204 | Automated safety check: Pass | MIT | 1 mo ago |
Questions, answered from the data.
What is the best skill by Encod3d-Sec?
Bug Bounty Campaign Driver from Encod3d-Sec/TORCH ranks first of the 35 skills by Encod3d-Sec listed here, with the highest score: its repository has 329 GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 1.8k tokens and it passes the automated safety check with no findings. Next come Adaptive Web Fuzzing and Hunt Idor.
Are Encod3d-Sec's skills official?
None yet. All 35 skills by Encod3d-Sec listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.