Metabigor OSINT Recon
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
$ npx skills add Encod3d-Sec/TORCH --skill fuzz -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Encod3d-Sec/TORCH fuzz --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workflow/fuzz .claude/skills/fuzz && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fuzz" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/fuzz into .claude/skills/fuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/fuzzType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Encod3d-Sec/TORCH --skill fuzz -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Encod3d-Sec/TORCH fuzz --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/workflow/fuzz .agents/skills/fuzz && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fuzz" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/fuzz into .agents/skills/fuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill fuzz -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Encod3d-Sec/TORCH fuzz --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/workflow/fuzz .cursor/skills/fuzz && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fuzz" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/fuzz into .cursor/skills/fuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Encod3d-Sec/TORCH.git --path skills/workflow/fuzz--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Encod3d-Sec/TORCH --skill fuzz -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Encod3d-Sec/TORCH fuzz --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/workflow/fuzz .gemini/skills/fuzz && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fuzz" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/fuzz into .gemini/skills/fuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Encod3d-Sec/TORCH fuzzInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Encod3d-Sec/TORCH --skill fuzz -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/workflow/fuzz .github/skills/fuzz && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fuzz" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/fuzz into .github/skills/fuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Encod3d-Sec/TORCH --skill fuzz -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Encod3d-Sec/TORCH fuzz --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/workflow/fuzz .opencode/skills/fuzz && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fuzz" agent skill from https://github.com/Encod3d-Sec/TORCH/tree/main/skills/workflow/fuzz into .opencode/skills/fuzz/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fuzz", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fuzzAdaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.
The skill reads the engagement type from the active target's state.md and sets a profile. The ctf profile runs loud and fast, pt uses a calibrated rate and obeys rules-of-engagement flags such as no_bruteforce and no_dos by skipping the brute-force tiers, and bb runs at a low rate with jitter while watching for a ban. Work then proceeds on two axes: widening across content, files, vhosts, APIs and artifacts, and deepening into hidden parameters once an endpoint is observed to accept input.
Wordlists are chosen by a script, wl-pick.sh, which prints the SecLists base, the profile flags and ordered list paths from smallest to largest. The agent is told never to pick a list from memory or to start with the 220k directory-list-2.3-medium list. Filters are calibrated with ffuf -ac and feroxbuster auto-filtering, falling back to probing random bogus paths when a wildcard soft-404 fools them. The agent then climbs from the harness list to SecLists, then cewl-generated words, then product-specific lists as fingerprints appear, and backs off when it detects a WAF or throttling.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bashpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Adaptive Web Fuzzing loads about 1.3k tokens when it runs. Until then it costs about 165 tokens; SKILL.md has 531 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 531 words, ~1,264 tokens.
.claude/skills/fuzz/SKILL.md (or your agent's skills folder).Read engagement_type from the active targets/<eng>/state.md frontmatter and set the profile:
no_bruteforce/no_dos -> SKIP the brute tiers entirely).wl-pick.sh emits the profile flags; you apply them.# what to run for a surface, given the engagement type and any fingerprint:
bash scripts/wl-pick.sh content "" ctf # generic content discovery
bash scripts/wl-pick.sh content wordpress bb # WordPress-aware, BB-stealth
bash scripts/wl-pick.sh vhost "" pt
bash scripts/wl-pick.sh params "" bbIt prints the seclists base, the profile flags line, and the ordered absolute paths (T0 harness -> T3 fingerprint list -> T1 surface lists, size-ordered). NEVER hand-pick a list from memory and NEVER start with directory-list-2.3-medium (220k). The size order is already correct in the output; run top-to-bottom, stop climbing when you have enough signal.
-ac/-acc and feroxbuster auto-filtering.-ac (everything returns 200 with varying size): fire 2-3 known-bogus random paths first, read status/size/words, then set explicit -fs/-fw on the catch-all baseline, or -mc 200,301,302,401,403 on a clean 404.Climb T0 -> T1 -> T2 -> T3 when the current tier is exhausted OR a fingerprint unlocks a better list:
cewl -d 3 -m 5 --lowercase -w targets/<eng>/custom-words.txt https://TARGET then feed that list back through the same axis. See [[cewl]].wl-pick.sh <surface> <product> <type> to jump straight to its shipped list. For a product with no shipped list, Skill(wiki-arsenal) for its known paths, then cewl its docs / probe robots.txt sitemap.xml swagger.json openapi.json.When a discovered endpoint takes input, fuzz hidden params: arjun -u https://TARGET/endpoint (see [[arjun]]) or ffuf with bash scripts/wl-pick.sh params. Discovered params feed the hunt-* skills (SSRF/LFI/IDOR/cmdi).
Detect: wafw00f/whatwaf up front; headers cf-ray/server: cloudflare/x-sucuri/x-datadome/incapsula; mid-run 429+Retry-After, climbing latency, 000/timeouts, a wall of uniform 403.
Respond, in order:
-p 0.1-2.0 jitter, drop one size-tier.python3 scripts/campaign.py pause-host <host> and call Skill(redteamlead) for a re-vector rather than tuning the tooling.no_bruteforce/no_dos -> skip the brute tiers; scope-guard also enforces this at the Bash layer.A 403 on a discovered dir is a signal, not an end. Try bypass BEFORE abandoning: path mutations (/admin/, /admin/., /admin/..;/, /%2e/admin, case, trailing ?), method swap (GET->POST/HEAD/TRACE), and header spoofs (X-Forwarded-For: 127.0.0.1, X-Original-URL, X-Rewrite-URL). Use a dedicated tool (byp4xx/nomore403) rather than a wordlist - 403 bypass is mutation, not brute. See [[cdn-waf-bypass]].
Tools: [[ffuf]] [[wiki/tools/feroxbuster]] [[cewl]] [[arjun]]. Reference: [[wordlists]] (the selection matrix, human-readable twin of wordlist-map.json), [[cdn-waf-bypass]] (WAF/origin bypass). Stuck -> Skill(redteamlead).
© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/workflow/fuzz of Encod3d-Sec/TORCH.
Open the folder on GitHubat commit d21b6c9
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Encod3d-Sec/TORCH, which our catalogue first saw on October 7, 2026.
Adaptive Web Fuzzing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Adaptive Web Fuzzing this skillEncod3d-Sec/TORCH | 329 | 1 repos | ~1.3k | Automated safety check: Pass | MIT | |
| Metabigor OSINT Reconj3ssie/metabigor | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Client Request Signature Reversalawarexone/Agentic-Bug-Hunter | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | |
| Web3 Bug Bounty AI Toolstradecatlabs/vibe-coding-cn | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | |
| Penetration Flowlingbol088-spec/ReiPenFlow | 222 | — | ~1.8k | Automated safety check: Pass | MIT |
j3ssie/metabigor
Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
awarexone/Agentic-Bug-Hunter
Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.
tradecatlabs/vibe-coding-cn
A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.
lingbol088-spec/ReiPenFlow
Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.
samugit83/redamon
Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.
Encod3d-Sec/TORCH
Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.
Encod3d-Sec/TORCH
IDOR / BOLA hunting - two-account methodology, identifier discovery and UUID leak chaining, the trusted-identifier test, GraphQL node and nested-object IDOR, cross-tenant escalation, write and…
Encod3d-Sec/TORCH
Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.
Encod3d-Sec/TORCH
Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.
Encod3d-Sec/TORCH
Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.
Encod3d-Sec/TORCH
Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.
Categories
Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses. md and sets a profile. The ctf profile runs loud and fast, pt uses a calibrated rate and obeys rules-of-engagement flags such as no_bruteforce and no_dos by skipping the brute-force tiers, and bb runs at a low rate with jitter while watching for a ban.
Adaptive Web Fuzzing fits situations like: running content or vhost discovery against a web target in a security engagement; looking for hidden parameters on an endpoint that accepts input; choosing which wordlist to run next for a given surface.
Run `npx skills add Encod3d-Sec/TORCH --skill fuzz -a claude-code`. Or copy the skill folder (skills/workflow/fuzz in Encod3d-Sec/TORCH) into .claude/skills/fuzz in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Encod3d-Sec/TORCH --skill fuzz -a codex`. Or copy the skill folder (skills/workflow/fuzz in Encod3d-Sec/TORCH) into .agents/skills/fuzz in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill fuzz -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fuzz, .gemini/skills/fuzz, .github/skills/fuzz and .opencode/skills/fuzz in your project.
Going by SKILL.md and its folder, Adaptive Web Fuzzing needs the command-line tools its instructions call (bash and python3). Our summary lists: ffuf, gobuster, feroxbuster, cewl or arjun; SecLists wordlists; The wl-pick.sh script and a target state.md file.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Adaptive Web Fuzzing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Adaptive Web Fuzzing: Metabigor OSINT Recon (j3ssie/metabigor, 1.8k stars), Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Client Request Signature Reversal (awarexone/Agentic-Bug-Hunter, 5.3k stars) and Web3 Bug Bounty AI Tools (tradecatlabs/vibe-coding-cn, 17k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.
Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.