GitHub user
Agent skills by trilwu
- skills
- 50
- repository
- 1
Repositories by trilwu
Skills by trilwu, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis. | trilwu/ | 156 | — | ~3.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 2 | Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access. | trilwu/ | 156 | — | ~3.1k | Automated safety check: Notes | MIT | 1 mo ago |
| 3 | Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP… | trilwu/ | 156 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 4 | Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation. | trilwu/ | 156 | — | ~2.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 5 | Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling… | trilwu/ | 156 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 6 | Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and… | trilwu/ | 156 | — | ~2k | Automated safety check: Pass | MIT | 1 mo ago |
| 7 | Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring. | trilwu/ | 156 | — | ~3.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 8 | Analyze volatile memory images (RAM dumps) using Volatility 3 — process enumeration, injected code detection, credential extraction, network artifacts, rootkit analysis, and timeline construction… | trilwu/ | 156 | — | ~4k | Automated safety check: Notes | MIT | 1 mo ago |
| 9 | Triage and forensically analyze reported phishing safely — extract the raw message, read the Received chain, verify SPF/DKIM/DMARC, detect display-name and lookalike spoofing, unwrap redirects and… | trilwu/ | 156 | — | ~4.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 10 | Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse… | trilwu/ | 156 | — | ~4.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 11 | Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of… | trilwu/ | 156 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 12 | Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 13 | Attack SAML single sign-on by decoding and tampering with signed XML assertions — XML signature wrapping (XSW1-XSW8), signature stripping, assertion and attribute tampering, NameID comment… | trilwu/ | 156 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 14 | Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash… | trilwu/ | 156 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 15 | Write a new SecSkills skill end to end — choosing the plugin bucket and skill tier, writing a description that triggers correctly without stealing traffic from siblings, the required sections… | trilwu/ | 156 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 16 | Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection… | trilwu/ | 156 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 17 | Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed… | trilwu/ | 156 | — | ~2.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 18 | Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 19 | Locate the vulnerability a security patch fixes by diffing the pre- and post-patch binaries — using BinDiff, Diaphora, or ghidriff to find the changed functions, reading the added checks to recover… | trilwu/ | 156 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 20 | Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices. | trilwu/ | 156 | — | ~3.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 21 | Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage… | trilwu/ | 156 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 22 | Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 156 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 23 | Hunt planted webshells and backdoors across a web source tree — PHP first (also JSP, ASP, Node) — triaging a directory at scale, statically decoding obfuscation layers without ever executing the… | trilwu/ | 156 | — | ~3k | Automated safety check: Pass | MIT | 1 mo ago |
| 24 | Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access… | trilwu/ | 156 | — | ~4.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 25 | Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 26 | Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule… | trilwu/ | 156 | — | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 27 | Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log… | trilwu/ | 156 | — | ~4.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 28 | Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 29 | Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 30 | Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh… | trilwu/ | 156 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 31 | Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and… | trilwu/ | 156 | — | ~4.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 32 | Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with… | trilwu/ | 156 | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 33 | Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure. | trilwu/ | 156 | — | ~3.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 34 | Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline. | trilwu/ | 156 | — | ~2.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 35 | Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and… | trilwu/ | 156 | — | ~2.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 36 | Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities. | trilwu/ | 156 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 37 | Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links… | trilwu/ | 156 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 38 | Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment… | trilwu/ | 156 | — | ~2.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 39 | Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping… | trilwu/ | 156 | — | ~2.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 40 | Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the… | trilwu/ | 156 | — | ~4k | Automated safety check: Pass | MIT | 1 mo ago |
| 41 | Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with… | trilwu/ | 156 | — | ~4.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 42 | Author durable YARA detection rules — meta/strings/condition anatomy, string types and modifiers, structural conditions with file magic and offsets, the PE/ELF/math/hash modules… | trilwu/ | 156 | — | ~4.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 43 | Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection… | trilwu/ | 156 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 44 | Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs… | trilwu/ | 156 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 45 | Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened… | trilwu/ | 156 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 46 | Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C flash; dumping firmware off-chip; triaging secure boot; and studying sub-GHz RF… | trilwu/ | 156 | — | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 47 | Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher… | trilwu/ | 156 | — | ~1.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 48 | Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and… | trilwu/ | 156 | — | ~3.9k | Automated safety check: Notes | MIT | 1 mo ago |
Questions, answered from the data.
What is the best skill by trilwu?
Auditing Code For Vulnerabilities from trilwu/secskills ranks first of the 50 skills by trilwu listed here, with the highest score: its repository has 156 GitHub stars, its SKILL.md loads about 3.2k tokens and it passes the automated safety check with no findings. Next come Performing Reconnaissance and Securing AI Systems.
Are trilwu's skills official?
None yet. All 50 skills by trilwu listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.