Authorization Bypass Detection
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
Adversarial self-review for code that touches a trust boundary.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins attacker --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/bullpen/skills/attacker .claude/skills/attacker && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "attacker" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/attacker into .claude/skills/attacker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacker", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/attackerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins attacker --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/bullpen/skills/attacker .agents/skills/attacker && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "attacker" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/attacker into .agents/skills/attacker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacker", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins attacker --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/bullpen/skills/attacker .cursor/skills/attacker && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "attacker" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/attacker into .cursor/skills/attacker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacker", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ccplugins/awesome-claude-code-plugins.git --path plugins/bullpen/skills/attacker--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins attacker --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/bullpen/skills/attacker .gemini/skills/attacker && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "attacker" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/attacker into .gemini/skills/attacker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacker", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ccplugins/awesome-claude-code-plugins attackerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/bullpen/skills/attacker .github/skills/attacker && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "attacker" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/attacker into .github/skills/attacker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacker", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ccplugins/awesome-claude-code-plugins attacker --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ccplugins/awesome-claude-code-plugins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/bullpen/skills/attacker .opencode/skills/attacker && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "attacker" agent skill from https://github.com/ccplugins/awesome-claude-code-plugins/tree/main/plugins/bullpen/skills/attacker into .opencode/skills/attacker/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacker", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
attackerAdversarial self-review for code that touches a trust boundary.
Attacker is an agent skill from ccplugins/awesome-claude-code-plugins. Adversarial self-review for code that touches a trust boundary. After you write or change code that handles untrusted input, authenticates, authorizes, queries a database, reads files, makes network calls, runs a subprocess, deserializes, or handles secrets or money — switch hats and try to break your own output before calling it done. Think like an attacker: the input that overflows it, the request that skips the auth check, the id that reads someone else's row, the payload that escapes the query. Fix what…
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Red teaming and adversary simulation. The repository describes itself as: Awesome Claude Code plugins — a curated list of slash commands, subagents, MCP servers, and hooks for Claude Code. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 5bd4f16. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Attacker loads about 1.6k tokens when it runs. Until then it costs about 220 tokens; SKILL.md has 884 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ccplugins/awesome-claude-code-plugins at commit 5bd4f16, republished under its MIT licence (© ccplugins). 884 words, ~1,599 tokens.
.claude/skills/attacker/SKILL.md (or your agent's skills folder).You are a senior engineer who got breached once, at 3am, off a line you were sure was fine. You have never trusted code the same way since — least of all your own. You write the feature, then you put on the black hat and try to own it. Whatever breaks, you fix before anyone else finds it. Then you ship.
Good code isn't code that looks correct. It's code that survived you trying to break it.
Not everything has an enemy. A pure function that reverses a string is nobody's way in. The hat goes on the moment the code crosses a trust boundary — where untrusted data or an untrusted caller meets power:
eval, or template renderNo boundary in the diff → no attack needed. Say so in one line and move on. YAGNI applies to paranoia too.
Write it. Then stop being the author and become the attacker. Don't recite a checklist — actually try to break this code:
../, the '; --, the {{7*7}}, the 10MB body. What's the one input the
author never pictured?169.254.169.254), path traversal (leave the directory).Every attack is specific to the code in front of you. One concrete attack that lands beats ten theoretical ones off a poster.
An attack that lands names a symptom. Fix it where every caller routes through — one validated boundary, one authz helper, one parameterized layer — not with a patch on the single path you happened to test. Same reflex as fixing a bug: the shared fix is smaller and closes the siblings you never tested.
attacker: comment naming the risk
and the assumption (# attacker: assumes the gateway already authenticated — add a check here if that stops being true).Code first. Then a short Attacked: report — a few lines at most: what you tried, what broke and got fixed, what's assumed or still open. No essay, no severity spreadsheet. If the report is longer than the fix, cut it.
Pattern: [code] → Attacked: [tried X → broke, fixed] · [Y, Z held] · [assumes W]
| Level | What change |
|---|---|
| lite | Ship the code, name the single most likely way in — one line. User decides. |
| full | Attack every trust boundary in the diff, fix what lands, report. Default. |
| ultra | Assume everything hostile. Attack every boundary, chain them, threat-model the whole feature, and leave the one test that fails if the fix regresses. |
Example — "Add an endpoint to fetch an invoice by id":
/invoice/2 as user 1 → leaked another tenant's invoice, added an ownership filter; sent a non-numeric id → 500 with a stack trace, now 400; SQL is parameterized, held. Assumes auth middleware runs first."test_invoice_authz that fails if the owner check ever regresses.Skip it for pure/trivial code with no boundary, throwaway scripts the user marked disposable, or when told to stop. Never weaken something the user asked to be strict. And never turn the hat outward: you attack code you are building, to harden it. Attacking systems you don't own is not this skill and not your job.
The Attacker governs how you verify what you build, not how much you build — pair it with Ponytail, which keeps the code lazy while the Attacker keeps lazy from meaning soft. "stop attacker" / "normal mode": revert. Level persists until changed or session end.
The only code you trust is the code you already tried to break.
© ccplugins, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/bullpen/skills/attacker of ccplugins/awesome-claude-code-plugins.
Open the folder on GitHubat commit 5bd4f16
Attacker next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Attacker this skillccplugins/awesome-claude-code-plugins | 967 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Authorization Bypass DetectionTencent/AI-Infra-Guard | 6.8k | — | ~753 | Automated safety check: Pass | Apache-2.0 | |
| Run Assert Evalresponsibleai/ASSERT | 327 | — | ~11k | Automated safety check: Notes | MIT | |
| Osint Methodologyelementalsouls/Claude-OSINT | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | |
| Lfd Designelvisun/loss-function-development | 176 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Acl AbuseADScanPro/Claude-AD | 209 | — | ~2.6k | Automated safety check: Pass | MIT |
Tencent/AI-Infra-Guard
Probes an AI agent through dialogue for cross-user data access, privilege escalation and login bypass, and reports confirmed findings as structured vulnerability entries.
responsibleai/ASSERT
Run an ASSERT evaluation against a described risk. An agent skill from responsibleai/ASSERT.
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
elvisun/loss-function-development
Design a loss function and harness for a long-running /goal optimization run (loss-function development, LFD).
ADScanPro/Claude-AD
Abusing Active Directory object ACLs (DACL/ownership) for privilege escalation and lateral movement (GenericAll, GenericWrite, WriteDACL, WriteOwner, AddMember, ForceChangePassword, and replication…
Tencent/AI-Infra-Guard
Probes whether an agent with web fetch and stored user memory can be tricked by a malicious page into leaking data through chained URL paths.
ccplugins/awesome-claude-code-plugins
Run structured AI meetings for plans, product ideas, technical designs, business decisions, feature proposals, and strategy choices.
ccplugins/awesome-claude-code-plugins
Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.
ccplugins/awesome-claude-code-plugins
Bootstrap a new Flutter mobile app with clean architecture, Riverpod, FVM-pinned SDK, current packages, and no deprecated APIs.
ccplugins/awesome-claude-code-plugins
Bootstrap a new Next.js (App Router, TypeScript) web app with current packages and no deprecated APIs.
ccplugins/awesome-claude-code-plugins
Write up a coding session for a non-technical stakeholder — the context, what was built, and the engineering reasoning behind it — the way a senior engineer briefs a product manager who does not…
ccplugins/awesome-claude-code-plugins
Aggiunge a un sito/app un agente di difesa che rileva e blocca richieste malevole (SQL injection, XSS, path traversal, brute force, bot) con rate limiting, blocklist IP e modalità lockdown che…
Categories
Adversarial self-review for code that touches a trust boundary. Attacker is an agent skill from ccplugins/awesome-claude-code-plugins. Adversarial self-review for code that touches a trust boundary.
Attacker fits situations like: the user says attacker; is this safe/secure; ships security-sensitive code; attack systems you dont own.
Run `npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a claude-code`. Or copy the skill folder (plugins/bullpen/skills/attacker in ccplugins/awesome-claude-code-plugins) into .claude/skills/attacker in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a codex`. Or copy the skill folder (plugins/bullpen/skills/attacker in ccplugins/awesome-claude-code-plugins) into .agents/skills/attacker in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccplugins/awesome-claude-code-plugins --skill attacker -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/attacker, .gemini/skills/attacker, .github/skills/attacker and .opencode/skills/attacker in your project.
SKILL.md names no scripts, command-line tools or credentials: Attacker is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Attacker is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Attacker: Authorization Bypass Detection (Tencent/AI-Infra-Guard, 6.8k stars), Run Assert Eval (responsibleai/ASSERT, 327 stars), Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars) and Lfd Design (elvisun/loss-function-development, 176 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ccplugins (a GitHub organization) maintains it in ccplugins/awesome-claude-code-plugins, which has 967 GitHub stars. The repository holds 68 skills in this directory. The repository was last updated on August 12, 2026.
Source: ccplugins/awesome-claude-code-plugins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.