GitHub user
Agent skills by NeoTheCapt
- skills
- 25
- repository
- 1
Repositories by NeoTheCapt
Skills by NeoTheCapt, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses | NeoTheCapt/ | 140 | — | ~1.3k | Automated safety check: Pass | No licence | 2 mo ago |
| 2 | Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws | NeoTheCapt/ | 140 | — | ~2.8k | Automated safety check: Pass | No licence | 2 mo ago |
| 3 | CORS misconfiguration testing for data theft and access control bypass | NeoTheCapt/ | 140 | — | ~904 | Automated safety check: Pass | No licence | 2 mo ago |
| 4 | Cross-site request forgery testing for state-changing operations | NeoTheCapt/ | 140 | — | ~791 | Automated safety check: Pass | No licence | 2 mo ago |
| 5 | Insecure deserialization detection and gadget chain exploitation | NeoTheCapt/ | 140 | — | ~836 | Automated safety check: Pass | No licence | 2 mo ago |
| 6 | Discover hidden directories, files, and endpoints on a web server | NeoTheCapt/ | 140 | — | ~737 | Automated safety check: Notes | No licence | 2 mo ago |
| 7 | Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains | NeoTheCapt/ | 140 | — | ~608 | Automated safety check: Pass | No licence | 2 mo ago |
| 8 | Discover hidden parameters, test values, and identify input handling anomalies | NeoTheCapt/ | 140 | — | ~944 | Automated safety check: Pass | No licence | 2 mo ago |
| 9 | Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution | NeoTheCapt/ | 140 | — | ~988 | Automated safety check: Warn | No licence | 2 mo ago |
| 10 | Discover open ports, running services, and their versions on a target | NeoTheCapt/ | 140 | — | ~634 | Automated safety check: Pass | No licence | 2 mo ago |
| 11 | HTTP request smuggling via CL.TE/TE.CL desync and cache poisoning | NeoTheCapt/ | 140 | — | ~982 | Automated safety check: Pass | No licence | 2 mo ago |
| 12 | Frontend source code analysis for hidden routes, API endpoints, and secrets | NeoTheCapt/ | 140 | — | ~3k | Automated safety check: Pass | No licence | 2 mo ago |
| 13 | 13.Sqli Testing Detect and exploit SQL injection vulnerabilities in web application parameters | NeoTheCapt/ | 140 | — | ~1.2k | Automated safety check: Pass | No licence | 2 mo ago |
| 14 | 14.Ssrf Testing Detect and exploit server-side request forgery to access internal resources and cloud metadata | NeoTheCapt/ | 140 | — | ~768 | Automated safety check: Pass | No licence | 2 mo ago |
| 15 | Subdomain discovery via subfinder, DNS brute-force, and passive sources | NeoTheCapt/ | 140 | — | ~1.7k | Automated safety check: Notes | No licence | 2 mo ago |
| 16 | Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference | NeoTheCapt/ | 140 | — | ~2.9k | Automated safety check: Pass | No licence | 2 mo ago |
| 17 | 17.Web Recon Enumerate web technologies, headers, endpoints, and metadata from a target | NeoTheCapt/ | 140 | — | ~770 | Automated safety check: Pass | No licence | 2 mo ago |
| 18 | 18.Xss Testing Detect and exploit cross-site scripting vulnerabilities in web applications | NeoTheCapt/ | 140 | — | ~1.4k | Automated safety check: Pass | No licence | 2 mo ago |
| 19 | 19.Xxe Testing XML external entity injection for file read, SSRF, and DoS. An agent skill from NeoTheCapt/RedteamAgent. | NeoTheCapt/ | 140 | — | ~1k | Automated safety check: Pass | No licence | 2 mo ago |
| 20 | Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts | NeoTheCapt/ | 140 | — | ~5.1k | Automated safety check: Notes | No licence | 2 mo ago |
| 21 | OS command injection detection, exploitation, and filter bypass | NeoTheCapt/ | 140 | — | ~754 | Automated safety check: Pass | No licence | 2 mo ago |
| 22 | File upload vulnerability testing — webshells, bypass, path traversal | NeoTheCapt/ | 140 | — | ~1.6k | Automated safety check: Pass | No licence | 2 mo ago |
| 23 | 23.Idor Testing Insecure direct object reference testing for broken access control | NeoTheCapt/ | 140 | — | ~793 | Automated safety check: Pass | No licence | 2 mo ago |
| 24 | Information disclosure detection — error messages, files, headers, debug endpoints | NeoTheCapt/ | 140 | — | ~1.1k | Automated safety check: Notes | No licence | 2 mo ago |
| 25 | 25.Ssti Testing Server-side template injection detection, engine identification, and RCE | NeoTheCapt/ | 140 | — | ~748 | Automated safety check: Pass | No licence | 2 mo ago |
Questions, answered from the data.
What is the best skill by NeoTheCapt?
Auth Bypass from NeoTheCapt/RedteamAgent ranks first of the 25 skills by NeoTheCapt listed here, with the highest score: its repository has 140 GitHub stars, its SKILL.md loads about 1.3k tokens and it passes the automated safety check with no findings. Next come Business Logic Testing and Cors Testing.
Are NeoTheCapt's skills official?
None yet. All 25 skills by NeoTheCapt listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.