Spikard
Goldziher/spikard
Scaffold Spikard projects and generate code from OpenAPI, AsyncAPI, OpenRPC, GraphQL, and Protobuf schemas using the Spikard CLI or its MCP server.
Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.
$ npx skills add aoyunyang/spider-king-skill --skill spider-king -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aoyunyang/spider-king-skill spider-king --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
Claude Code skills documentation · loads skills from .claude/skills/
Install the "spider-king" agent skill from https://github.com/aoyunyang/spider-king-skill/tree/main into .claude/skills/spider-king/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spider-king", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aoyunyang/spider-king-skill --skill spider-king -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aoyunyang/spider-king-skill spider-king --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "spider-king" agent skill from https://github.com/aoyunyang/spider-king-skill/tree/main into .agents/skills/spider-king/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spider-king", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aoyunyang/spider-king-skill --skill spider-king -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aoyunyang/spider-king-skill spider-king --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "spider-king" agent skill from https://github.com/aoyunyang/spider-king-skill/tree/main into .cursor/skills/spider-king/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spider-king", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aoyunyang/spider-king-skill --skill spider-king -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aoyunyang/spider-king-skill spider-king --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "spider-king" agent skill from https://github.com/aoyunyang/spider-king-skill/tree/main into .gemini/skills/spider-king/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spider-king", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aoyunyang/spider-king-skill spider-kingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aoyunyang/spider-king-skill --skill spider-king -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "spider-king" agent skill from https://github.com/aoyunyang/spider-king-skill/tree/main into .github/skills/spider-king/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spider-king", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aoyunyang/spider-king-skill --skill spider-king -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aoyunyang/spider-king-skill spider-king --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "spider-king" agent skill from https://github.com/aoyunyang/spider-king-skill/tree/main into .opencode/skills/spider-king/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spider-king", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
spider-kingPure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.
Spider King is an agent skill from aoyunyang/spider-king-skill. Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors. Auto-judge intake and tool path from signals: artifact-only first when samples suffice; for a fresh web live-target, collect sequential fingerprint-baseline then debugger-trace evidence (default chrome-devtools then js-reverse; upgrade baseline host to Camoufox/managed profile only on fingerprint pressure); for continuation, reuse the current gate when target and environment are unchanged. Route only mounted…
Its SKILL.md is about 7.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 193 other files, including scripts and reference files (for example `README.md`, `agents/openai.yaml` and `references/anti-debug-playbook.md`).
It sits in Backend & APIs, covering Browser testing, Realtime and WebSockets and gRPC and Protobuf. It works with Model Context Protocol, Chrome DevTools, Python and gRPC. The repository describes itself as: Protocol-first reverse engineering skill for turning hostile web clients into pure-protocol Python collectors. The licence is MIT.
10 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1ca7136. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Spider King loads about 7.3k tokens when it runs, and up to ~324k if it reads all its reference files. Until then it costs about 204 tokens; SKILL.md has 3,304 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aoyunyang/spider-king-skill at commit 1ca7136, republished under its MIT licence (© aoyunyang). 3,304 words, ~7,336 tokens.
.claude/skills/spider-king/SKILL.md (or your agent's skills folder). This skill also uses 191 other files; get the full folder from GitHub.Turn hostile web clients into stable protocol collectors.
This is a pure-web protocol-recovery skill, not a browser-automation skill and not an APK/mini-program reverse skill. Use browser tooling only to gather web evidence. Deliver raw HTTP plus narrow local sign, bootstrap, decode, or transport helpers. If the primary target is APK, native app, or mini-program, state out-of-scope instead of inventing a web dual-browser first-pass.
references/mcp-routing-playbook.md: decide intake, whether a browser is needed, which baseline host to use, and whether js-reverse is required. Do not open tools first and rationalize later.live-target with sequential evidence for both roles before claiming that live web target is understood: fingerprint-baseline then debugger-trace. Default means are chrome-devtools then js-reverse. When fingerprint pressure is proved, the baseline host may be Camoufox or another managed profile; debugger-trace still prefers js-reverse only after a real handoff and only when a debug attach surface exists. This skill's primary scope is web clients only; APK, native app, and mini-program primary tasks are out of scope and must not invent paired-browser proof as ceremony. If a required role or its available means is missing for a web live-target, report the blocker before claiming the live target is understood.TARGET_ACTIVE, and never place both families in the same parallel tool batch. Apply the handoff gate in references/tool-playbook.md; preserve unique unreplayable state with RETAINED_EXCEPTION instead of destroying it for cleanup.compact-replay and collector, deliver a browser-free Python run path. Never use browser automation, Playwright, Selenium, CDP page-driving, page-context fetch, browser profiles, or manual browser state as the final replay path or fallback.window, document, browser storage, page driving, or manual clicks.evidence or local-proof as a collector, and do not disguise incomplete automation as a temporary collector.compact-replay and collector delivery include a PyCharm right-click runnable Python entrypoint, normally project-root main.py or collector/main.py, with no required terminal arguments. evidence and local-proof do not require an entrypoint unless the requested artifact is executable code.TARGET_ACTIVE owner, but they do not replace web live first-pass evidence and must not become the final run path.compact-replay and collector must remain free of MCP browser runtime, page driving, and profile-bound operation.For failure-shaped counterexamples, read references/anti-patterns-playbook.md. Before packaging a result, apply only the matching capability gate from references/delivery-gate-playbook.md.
Use these labels internally to keep the first move small. Do not force a rigid machine header in normal user replies.
| Shape | Deliverable |
|---|---|
evidence | real request, initiator, state source, mutation point, or precise blocker |
local-proof | fixed vectors, decoded sample, restored source, or callable helper without live egress |
compact-replay | one bounded right-click runnable replay for a proved request |
collector | repeatable browser-free Python collector with bounds |
Default to the smallest shape that answers the user. User-provided HAR, packet capture, request text, JS/WASM, cookie/token sample, fixed vector, or existing project artifact starts as evidence or local-proof; do not open a browser just to satisfy live-target ceremony. A bare URL by itself does not authorize browser navigation, live replay, writes, account/session use, dependency installation, or broad collection.
Route names describe the current capability owner, not the gate family: evidence-reuse, chromium-recon, browser-hook, static-ast, env-patch, iv8-local-runtime, verifier, transport, pure-python-rebuild, or python-collector. Run one route until it returns evidence or a named blocker. If two routes look plausible, pick the smaller offline route first and record what proof would justify escalation.
Before any route writes files, sends live egress, executes target-supplied code, uses account/session state, installs dependencies, or changes runtime state, apply the compact contract in references/provider-work-order.md.
Use a focused route when the goal is already narrow. Do not restart full unknown-target discovery for these cases.
| Current goal | Route |
|---|---|
| Paste-ready browser observation Hook at a known boundary | references/profiles/browser-hook-snippets/index.md |
| Structured Babel AST restoration of a supplied JS file | references/profiles/static-ast/index.md |
| Known entry + invocation + fixed browser output in Node/VM | references/profiles/env-patch/index.md |
| Fixed-trace pure-Python signer/decoder rebuild or regression | references/pure-python-rebuild-playbook.md |
| Unknown or multi-layer end-to-end collector | Continue Startup Gate + Universal Reverse Loop below |
| Entry/call-chain location only | Dedicated reverse skill when available; else chrome-devtools / js-reverse initiator evidence |
| Explicit Python + iv8 runtime | iv8 skill when available; if unavailable, report the unmet constraint and use env-patch/local helper only after the user accepts that substitution |
| Confirmed CAPTCHA/TDC or family-owned protocol | Matching specialist skill when available; Spider stays secondary runtime help only |
| Already-captured HAR, Reqable history, or request text to explain or draft replay | evidence-reuse; read references/mcp-routing-playbook.md before opening browsers |
| Fingerprint or managed profile required before evidence | Auto-judge high fingerprint pressure -> Camoufox/managed host baseline, then attach/js-reverse handoff when debug endpoint exists |
| Enough HAR/request/JS/cookie sample and no fresh live proof needed | artifact-only / evidence-reuse; do not open Camoufox, Chrome, or js-reverse for ceremony |
Focused profile rules:
artifact-only or already-proved known-boundary work, but still require reversible changes and secret-safe logs. Structure-only static AST detection may begin from the supplied file alone; require fixed samples before behavioral claims or dynamic escalation. If the route needs fresh interaction with a current target, classify it as live-target and apply the paired sequential browser rule above.js_reverse_cache/tasks/<task-id>/ (task.json, network.jsonl, runtime-evidence.jsonl, handoff.json, fixtures/, report.md). Delivery proof remains analysis/proof_manifest.json and related analysis files. Never write task secrets into this skill directory. Apply references/project-artifact-contract.md before the first save or promotion.Use this before tool choice. It does not relax any delivery gate.
Full signal tables and host-upgrade rules live in references/mcp-routing-playbook.md and references/startup-triage-playbook.md.
Judge in this order and record the branch before the first target action:
artifact-only; bare URL or fresh page/session proof -> web live-target; same target/env/goal -> continuation; APK/app/mini-program primary -> out of scope.js-reverse after attach owner is confirmed.chrome-devtools; upgrade to Camoufox/managed host only on fingerprint pressure or clean-baseline failure; never default Camoufox for ordinary low-risk work.js-reverse; if attach is missing, export artifacts, record debugger_attach_gap, and continue offline.capability snapshot
-> Auto Judge
-> fingerprint-baseline (chrome-devtools default; Camoufox/managed host only on pressure)
-> sequential handoff
-> js-reverse when attach exists
-> offline rebuild + delivery gateComplete and report this gate before deep analysis. Expanded checklists stay in references/startup-triage-playbook.md.
Declare one mode before tool use:
live-target: current web page/endpoint needs fresh browser and wire evidence; use sequential role orderartifact-only: only saved requests/source/tokens/samples; mark live acceptance unprovencontinuation: same target/env/goal; reuse the current gate and reopen only changed surfacesSnapshot installed MCP families, attach/debug availability, and optional passive wire stores. Route only confirmed tools. Missing optional families are gaps, not ceremony.
Tag the smallest dominant gate family (signer-gated, transport-gated, verifier-gated, decode-gated, session-gated) from current evidence, then open only that path.
State the declared shape (evidence, local-proof, compact-replay, collector) and stop at that gate. Do not brand incomplete automation as a temporary collector.
Start immediately when the user provides a target page or API URL, site and collection goal, captured request, JS or WASM sample, cookie or token sample, or packet capture. Choose the intake mode before deciding whether browser evidence is required.
Ask only for missing information that changes implementation: target fields, collection scope, output format, login requirement, and whether dedupe, resume, or incremental sync is required.
For read-only evidence or local-proof requests, ask only for the missing sample, vector, trigger action, or source path. Delay project-root, retention, live replay, and request-budget questions until the next action would write, execute target code, or contact the target.
Before implementing a compact-replay or collector, use the conditional implementation brief in references/provider-work-order.md when multiple implementation forms remain viable or the next step would widen the currently resolved runtime, dependency, writable-scope, or live-authority boundary. Do not turn that brief into a mandatory approval ceremony for evidence, local-proof, or an implementation choice the user already made.
Use references/workflow-overview.md as the short execution map and references/tool-playbook.md for tool selection.
Deliver one confirmed request on the real business path.
Classify every changing part: timestamp, nonce, signed query or body, rotating header or cookie, wrapper field, operation name, cursor, bootstrap artifact, decode key, glyph map, session secret, profile baseline, sparse delta, counter, heartbeat, elapsed-time dependency, media key, page exception, account state, or host semantic. When the surface is an export or signed open platform style API, also bucket fields into business, static app, server-issued, and per-request dynamic classes before designing regeneration.
Prove cookie provenance and distinguish server-issued artifacts from locally minted filler. Treat page text about session participation as a hypothesis only until wire behavior confirms it. When login is only the first gate, validate tenant, role, and data-range with a final identity reread before export; see references/multi-context-session-playbook.md. Keep stored jar state separate from the authoritative outbound Cookie header when they diverge.
Trace in this order:
beforeSend, fetch, Ajax, XHR, worker, or message boundariesThe canonical mutation point is where the wire-shaped payload actually changes, not where business code creates a placeholder.
When a named digest is present, prove it on fixed inputs before trusting a standard library. Prefer environment-selected digest constants and the browser branch over UI or function names; route to references/crypto-patterns.md.
references/escalation-ladder-playbook.md before widening runtime, patch surface, or transport profile.references/native-transport-profile-playbook.md before building a route-local native adapter.references/opaque-runtime-profile-playbook.md; preserve one atomic run, port stage by stage, and distinguish algorithmic generation from snapshot-driven generation or pool replay.ROTL edge cases, and per-byte packing masks on a frozen preimage before live replay.references/profiles/static-ast/index.md detector and conservative rewrite, then recover the decoder offline with a two-pass rewrite before deep beautify work; see references/obfuscation-guide.md and references/offline-inline-deob-playbook.md.references/async-export-job-playbook.md.js_reverse_cache/tasks/<task-id>/; do not use OS temp, Desktop drop folders, the skill directory, or hidden browser profiles as primary storage.references/case-reuse-playbook.md: match by exact scope or multiple independent signals, run fixed vectors first, and never promote copied secrets or historical notes as current proof.Use scripts/scaffold_reverse_project.py for a Python-first project, scripts/protocol_diff.py for request or response deltas, scripts/transport_profile_diff.py for structured TLS and H2 profile deltas, scripts/transform_trace_diff.py for staged runtime parity, and scripts/crypto_fingerprint.py for preliminary encoding or digest hints.
For reusable evidence, read references/reproducible-evidence-playbook.md; use scripts/evidence_normalizer.py to create a redacted ordered package, scripts/transcript_diff.py to locate the first chain divergence, and scripts/practice_lab.py to exercise positive and negative protocol controls offline.
The skill-owned loopback practice lab is deterministic fixture evaluation, not a fresh live target. Probe it with direct HTTP only; do not activate the paired browser Startup Gate for this self-test.
Do not mark complete until every gate relevant to the declared shape passes:
live-target, both first-pass tool evidence surfaces are recorded; artifact-only web work states those surfaces as unproven, and non-web primary targets are out of scope instead of inventing web browser proof.200, a current cookie jar, or an expired browser export are not acceptance by themselves.compact-replay and collector, repeated live replay succeeds unless the accepted result is an explicitly bounded offline replay with live acceptance marked unproven.references/project-artifact-contract.md; runnable replay or collector manifests additionally record capability, session scope, helper, and replay evidence without copying secrets. A no-write conversational evidence result does not require a manifest file.After each meaningful phase, use the concise phase-delta format from references/report-templates.md; use the full templates only for major decisions and final delivery. For compact-replay and collector, finish with its compact protocol handoff summary rather than creating redundant project documents. Always report family choice, what each available evidence surface proved, real endpoint, moving parts, misleading signals, fixed-input proof, final protocol path, collector/helper split, saved paths, browser-free status, and remaining instability. Add cookie, observer effect, sibling route, envelope-family, decode, session, pagination, or minimal-verifiable-fact details only when relevant.
When a reusable family emerges, preserve 5 to 15 structural facts using references/minimal-verifiable-facts-playbook.md. Keep a one-job lesson task-local; after two independent reproductions, use references/experience-card-schema.md to promote only the invariant, fixture, positive/negative oracles, and applicability boundary.
Load only references that match current evidence, but keep every route directly discoverable here.
references/profiles/browser-hook-snippets/index.mdreferences/profiles/static-ast/index.mdreferences/profiles/env-patch/index.mdreferences/pure-python-rebuild-playbook.mdreferences/startup-triage-playbook.mdreferences/workflow-overview.mdreferences/tool-playbook.mdreferences/mcp-routing-playbook.md when deciding among artifact-only, Camoufox/managed host, chrome-devtools, js-reverse, passive wire stores, wire visibility, or environment providersreferences/local-mcp-environment.mdreferences/escalation-ladder-playbook.mdreferences/delivery-gate-playbook.mdreferences/anti-patterns-playbook.mdreferences/report-templates.mdreferences/doctrine-index.mdreferences/symptom-heuristics.mdreferences/pattern-atlas.mdreferences/minimal-verifiable-facts-playbook.mdreferences/reproducible-evidence-playbook.mdreferences/provider-work-order.mdreferences/specialist-handoff-contract.mdreferences/project-artifact-contract.mdreferences/case-reuse-playbook.mdreferences/experience-card-schema.mdreferences/crypto-patterns.mdreferences/obfuscation-guide.md, references/offline-inline-deob-playbook.mdreferences/decoy-and-real-request-playbook.mdreferences/transport-wrapper-playbook.mdreferences/patched-helper-playbook.mdreferences/jsvmp-analysis-playbook.mdreferences/opaque-runtime-profile-playbook.mdreferences/multi-context-session-playbook.mdreferences/cookie-provenance-playbook.mdreferences/session-contract-playbook.mdreferences/public-bootstrap-envelope-playbook.mdreferences/challenge-state-envelope-playbook.mdreferences/dual-writer-param-playbook.mdreferences/local-challenge-executor-playbook.mdreferences/server-js-cookie-bootstrap-playbook.mdreferences/side-asset-bootstrap-playbook.mdreferences/environment-patch-playbook.mdreferences/embedded-browser-runtime-playbook.mdreferences/iv8-runtime-cheatsheet.mdreferences/challenge-artifact-harvest-playbook.mdreferences/local-challenge-executor-playbook.mdreferences/hook-techniques.mdreferences/anti-debug-playbook.mdreferences/env-diff-playbook.mdreferences/async-export-job-playbook.mdreferences/transport-pre-gate-playbook.mdreferences/native-transport-profile-playbook.mdreferences/response-decode-playbook.mdreferences/structured-transport-playbook.mdreferences/stateful-stream-e2ee-playbook.mdreferences/verifier-replay-playbook.mdreferences/verifier-error-localization-playbook.mdreferences/positive-sample-hygiene-playbook.mdreferences/pagination-route-pivot-playbook.mdreferences/page-specific-exception-playbook.mdreferences/troubleshooting-playbook.mdreferences/skill-maintenance.mdreferences/official-self-test-task-suite.mdreferences/forward-testing-playbook.mdBefore editing, read references/skill-maintenance.md. Validate against references/official-self-test-task-suite.md and run scripts/validate_skill.py when present. The default validation is static; run scripts/validate_skill.py --run-trusted-self-tests only against the trusted current skill root. Use scripts/validate_skill.py --export-tests <path-outside-skill> when a machine-readable JSON suite is needed; keep the Markdown suite as the single source of truth. Static PASS is not behavioral proof. For a behavioral non-regression claim, follow references/forward-testing-playbook.md and validate an external fresh-runner, independent-reviewer report with scripts/forward_test_report.py; keep the report and response artifacts outside this skill tree.
Put reusable detail in its most specific reference. Keep this entry as the protocol-first execution path and direct router. Preserve generic facts and fixed vectors, never live secrets, copied cookies, account tokens, or site-specific folklore.
When a site looks browser-only, ask:
Most targets collapse once those questions are answered with wire evidence and repeatable replay.
© aoyunyang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 191 other files (scripts, references) in the repository root of aoyunyang/spider-king-skill.
Open the folder on GitHubat commit 1ca7136
Spider King next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Spider King this skillaoyunyang/spider-king-skill | 509 | — | ~7.3k | Automated safety check: Pass | MIT | |
| SpikardGoldziher/spikard | 123 | — | ~799 | Automated safety check: Pass | MIT | |
| Uxcholon-run/uxc | 116 | — | ~1.8k | Automated safety check: Pass | MIT | |
| API ForgeEliasOulkadi/shokunin | 114 | — | ~2.9k | Automated safety check: Pass | MIT | |
| User EnumerationNeoTheCapt/RedteamAgent | 142 | — | ~2.9k | Automated safety check: Pass | None | |
| API Protocol Securityzhaji2333/CkSKILLS | 114 | — | ~520 | Automated safety check: Pass | MIT |
Goldziher/spikard
Scaffold Spikard projects and generate code from OpenAPI, AsyncAPI, OpenRPC, GraphQL, and Protobuf schemas using the Spikard CLI or its MCP server.
holon-run/uxc
Discover and call remote schema-exposed interfaces with UXC.
EliasOulkadi/shokunin
Design REST/GraphQL APIs with OpenAPI 3.1, error handling, pagination, rate limiting, webhooks, and idempotency.
NeoTheCapt/RedteamAgent
Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference
zhaji2333/CkSKILLS
当目标存在REST/GraphQL/gRPC/WebSocket接口、Swagger/OpenAPI文档、调试端点(actuator/console)、旧版本API、内部接口、微服务网关,或需要测试HTTP走私、DoS、速率限制时调用。负责API全方法测试、BOLA越权、GraphQL深度攻击、协议层漏洞挖掘。
HoangNguyen0403/agent-skills-standard
Select how services talk: REST, gRPC, GraphQL, WebSocket, SSE, or webhook per hop, sync versus async per flow, service discovery mode, and DNS/edge routing.
Categories
Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors. Spider King is an agent skill from aoyunyang/spider-king-skill. Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.
Spider King fits situations like: hostile web sign; response-decode; browser-fingerprint; challenge-bootstrap.
Run `npx skills add aoyunyang/spider-king-skill --skill spider-king -a claude-code`. Or copy the skill folder (the aoyunyang/spider-king-skill repository) into .claude/skills/spider-king in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aoyunyang/spider-king-skill --skill spider-king -a codex`. Or copy the skill folder (the aoyunyang/spider-king-skill repository) into .agents/skills/spider-king in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aoyunyang/spider-king-skill --skill spider-king -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spider-king, .gemini/skills/spider-king, .github/skills/spider-king and .opencode/skills/spider-king in your project.
SKILL.md names no scripts, command-line tools or credentials: Spider King is instructions for the agent only. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Spider King is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.3k tokens (SKILL.md is roughly 29k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 316k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Spider King: Spikard (Goldziher/spikard, 123 stars), Uxc (holon-run/uxc, 116 stars), API Forge (EliasOulkadi/shokunin, 114 stars) and User Enumeration (NeoTheCapt/RedteamAgent, 142 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aoyunyang (a GitHub user) maintains it in aoyunyang/spider-king-skill, which has 509 GitHub stars. The repository was last updated on September 2, 2026.
Source: aoyunyang/spider-king-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.