GitHub user

Agent skills by trilwu

Every agent skill trilwu publishes on GitHub, ranked by score, with the repositories they come from.
skills
50
repository
1

Repositories by trilwu

Skills by trilwu, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Skills by trilwu, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

trilwu/secskills156—~3.2kAutomated safety check: PassMIT1 mo ago
2

Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

trilwu/secskills156—~3.1kAutomated safety check: NotesMIT1 mo ago
3

Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

trilwu/secskills156—~2.9kAutomated safety check: PassMIT1 mo ago
4

Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

trilwu/secskills156—~2.9kAutomated safety check: PassMIT1 mo ago
5

Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

trilwu/secskills156—~2kAutomated safety check: PassMIT1 mo ago
6

Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

trilwu/secskills156—~2kAutomated safety check: PassMIT1 mo ago
7

Analyze suspected malware safely — containment, static triage, sandboxed detonation, unpacking, capability and C2 extraction, IOC production, and YARA rule authoring.

trilwu/secskills156—~3.6kAutomated safety check: PassMIT1 mo ago
8

Analyze volatile memory images (RAM dumps) using Volatility 3 — process enumeration, injected code detection, credential extraction, network artifacts, rootkit analysis, and timeline construction…

trilwu/secskills156—~4kAutomated safety check: NotesMIT1 mo ago
9

Triage and forensically analyze reported phishing safely — extract the raw message, read the Received chain, verify SPF/DKIM/DMARC, detect display-name and lookalike spoofing, unwrap redirects and…

trilwu/secskills156—~4.2kAutomated safety check: PassMIT1 mo ago
10

Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…

trilwu/secskills156—~4.3kAutomated safety check: PassMIT1 mo ago
11

Test GraphQL APIs — introspection and schema recovery when introspection is disabled, field suggestion abuse, batching and alias-based rate limit bypass, query depth and complexity denial of…

trilwu/secskills156—~2.3kAutomated safety check: PassMIT1 mo ago
12

Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
13

Attack SAML single sign-on by decoding and tampering with signed XML assertions — XML signature wrapping (XSW1-XSW8), signature stripping, assertion and attribute tampering, NameID comment…

trilwu/secskills156—~3.5kAutomated safety check: PassMIT1 mo ago
14

Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…

trilwu/secskills156—~2.8kAutomated safety check: PassMIT1 mo ago
15

Write a new SecSkills skill end to end — choosing the plugin bucket and skill tier, writing a description that triggers correctly without stealing traffic from siblings, the required sections…

trilwu/secskills156—~3.1kAutomated safety check: PassMIT1 mo ago
16

Diagnose and defeat TLS interception failures in mobile apps — certificate pinning, Android Network Security Config, user-CA distrust, native BoringSSL pinning, and mutual TLS — using objection…

trilwu/secskills156—~2.5kAutomated safety check: PassMIT1 mo ago
17

Defeat root, jailbreak, emulator, debugger, and Frida detection in mobile apps using Magisk DenyList, Zygisk modules, objection, and targeted Frida hooks, and understand where hardware-backed…

trilwu/secskills156—~2.4kAutomated safety check: PassMIT1 mo ago
18

Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
19

Locate the vulnerability a security patch fixes by diffing the pre- and post-patch binaries — using BinDiff, Diaphora, or ghidriff to find the changed functions, reading the added checks to recover…

trilwu/secskills156—~1.9kAutomated safety check: PassMIT1 mo ago
20

Build, test, and tune detection content — Sigma, YARA, Suricata, and EDR/SIEM queries — mapped to MITRE ATT&CK with explicit false-positive analysis and detection-as-code practices.

trilwu/secskills156—~3.3kAutomated safety check: PassMIT1 mo ago
21

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

trilwu/secskills156—~1.9kAutomated safety check: PassMIT1 mo ago
22

Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk…

trilwu/secskills156—~3.5kAutomated safety check: PassMIT1 mo ago
23

Hunt planted webshells and backdoors across a web source tree — PHP first (also JSP, ASP, Node) — triaging a directory at scale, statically decoding obfuscation layers without ever executing the…

trilwu/secskills156—~3kAutomated safety check: PassMIT1 mo ago
24

Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…

trilwu/secskills156—~4.8kAutomated safety check: PassMIT1 mo ago
25

Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
26

Investigate security incidents in Microsoft 365 and Entra ID (Azure AD) -- search the Unified Audit Log, correlate sign-in and audit events, trace illicit OAuth consent grants, analyze mailbox rule…

trilwu/secskills156—~4.1kAutomated safety check: PassMIT1 mo ago
27

Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…

trilwu/secskills156—~4.7kAutomated safety check: PassMIT1 mo ago
28

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
29

Navigate security work by MITRE ATT&CK tactic and technique — resolve a technique ID or name to the right skill, map a threat intel report or adversary emulation plan to procedures, and run the…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
30

Run a sustained, multi-agent vulnerability-discovery campaign against a target — split its attack surface into slices, hunt each slice with a builder agent, and have a separate critic with fresh…

trilwu/secskills156—~3.5kAutomated safety check: PassMIT1 mo ago
31

Produce cyber threat intelligence by pivoting on indicators to find related infrastructure, tracking actors and campaigns, enriching and contextualizing IOCs, applying attribution discipline and…

trilwu/secskills156—~4.4kAutomated safety check: PassMIT1 mo ago
32

Recognize defensive deception during an engagement — honeypots, honeytokens and canary tokens, decoy AD accounts and shares, canary files, and deceptive cloud credentials — before interacting with…

trilwu/secskills156—~2.7kAutomated safety check: PassMIT1 mo ago
33

Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.

trilwu/secskills156—~3.4kAutomated safety check: PassMIT1 mo ago
34

Perform a security review of a diff, branch, or pull request — assessing what the change introduces, weakens, or exposes, with a triage-first workflow and false-positive discipline.

trilwu/secskills156—~2.3kAutomated safety check: PassMIT1 mo ago
35

Review cryptographic implementations and protocol usage for misuse — weak primitives, nonce and IV handling, key management, authentication of ciphertext, randomness, timing side channels, TLS and…

trilwu/secskills156—~2.7kAutomated safety check: PassMIT1 mo ago
36

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

trilwu/secskills156—~2.8kAutomated safety check: PassMIT1 mo ago
37

Test mobile inter-process communication and deep link attack surface — exported Android activities, services, receivers and content providers, intent redirection, PendingIntent hijacking, App Links…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
38

Work a security alert queue to a defensible disposition — separating true positives from false positives and benign true positives, reasoning about base rates before escalating, ordering enrichment…

trilwu/secskills156—~2.5kAutomated safety check: PassMIT1 mo ago
39

Unpack and dump protected executables — UPX and commodity packers, custom crypters, commercial protectors like Themida and VMProtect, and .NET packers — by finding the original entry point, dumping…

trilwu/secskills156—~2.1kAutomated safety check: PassMIT1 mo ago
40

Fact-check LLM-drafted technical content against primary sources — source hierarchy, programmatic existence probes for tool and plugin names, class-before-instance error triage, the…

trilwu/secskills156—~4kAutomated safety check: PassMIT1 mo ago
41

Author and maintain Sigma detection rules — structure, logsource taxonomy, detection logic with modifiers, false-positive filtering, backend conversion with pySigma, and offline validation with…

trilwu/secskills156—~4.1kAutomated safety check: PassMIT1 mo ago
42

Author durable YARA detection rules — meta/strings/condition anatomy, string types and modifiers, structural conditions with file magic and offsets, the PE/ELF/math/hash modules…

trilwu/secskills156—~4.4kAutomated safety check: PassMIT1 mo ago
43

Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection…

trilwu/secskills156—~5.3kAutomated safety check: PassMIT1 mo ago
44

Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs…

trilwu/secskills156—~5.3kAutomated safety check: PassMIT1 mo ago
45

Reverse engineer and security-review macOS applications and Mach-O binaries — thinning universal binaries, recovering Objective-C/Swift structure, reading code-signing entitlements and the hardened…

trilwu/secskills156—~1.7kAutomated safety check: PassMIT1 mo ago
46

Assess the physical attack surface of embedded devices — finding and using UART consoles, JTAG/SWD debug, and SPI/I2C flash; dumping firmware off-chip; triaging secure boot; and studying sub-GHz RF…

trilwu/secskills156—~1.8kAutomated safety check: PassMIT1 mo ago
47

Recover the original logic from code protected by a virtualization obfuscator — VMProtect, Themida/WinLicense, Code Virtualizer, or a custom opcode VM — by locating the VM dispatcher…

trilwu/secskills156—~1.6kAutomated safety check: PassMIT1 mo ago
48

Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

trilwu/secskills156—~3.9kAutomated safety check: NotesMIT1 mo ago

Questions, answered from the data.

What is the best skill by trilwu?

Auditing Code For Vulnerabilities from trilwu/secskills ranks first of the 50 skills by trilwu listed here, with the highest score: its repository has 156 GitHub stars, its SKILL.md loads about 3.2k tokens and it passes the automated safety check with no findings. Next come Performing Reconnaissance and Securing AI Systems.

Are trilwu's skills official?

None yet. All 50 skills by trilwu listed here come from community repositories; a skill counts as official when the product's own GitHub organization publishes it.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.