Agent skill

Legba

by evilsocket in evilsocket/legba

A skill your agent uses when the user wants to brute-force credentials, spray passwords, or enumerate services/subdomains against any network protocol (HTTP, SSH, FTP, SMB, RDP, databases, mail…

Custom licenceAuto-check passedBackend & APIs

Install Legba

skills CLI
$ npx skills add evilsocket/legba --skill legba -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install evilsocket/legba legba --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/evilsocket/legba.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/legba .claude/skills/legba && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
legba
GitHub stars
1.9k
Token cost
~2.2k tokens
SKILL.md length
675 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Custom licence

At a glance

A skill your agent uses when the user wants to brute-force credentials, spray passwords, or enumerate services/subdomains against any network protocol (HTTP, SSH, FTP, SMB, RDP, databases, mail…

  • The user wants to brute-force credentials
  • SKILL.md covers Installation, Core Concepts, Key CLI Options and Supported Plugins, plus 5 more sections
  • Calls brew, cargo and docker
  • Spray passwords

What it does

Legba is an agent skill from evilsocket/legba. Use this skill when the user wants to brute-force credentials, spray passwords, or enumerate services/subdomains against any network protocol (HTTP, SSH, FTP, SMB, RDP, databases, mail protocols, DNS, etc.) using legba. Also use it when the user asks how to use legba, how to write a recipe, how to configure the REST API or MCP server, or asks for help constructing a legba command.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs. It works with Model Context Protocol. The repository describes itself as: The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷.

When your agent uses it

  • The user wants to brute-force credentials
  • Spray passwords
  • Enumerate services/subdomains against any network protocol (HTTP
  • Etc.) using legba

Example prompts

  • “/legba”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit dab974b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • brew
    • cargo
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • legba.evilsocket.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Legba loads about 2.2k tokens when it runs. Until then it costs about 97 tokens; SKILL.md has 675 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 675 words (~2,154 tokens).

“legba is a fast, multi-protocol credential bruteforcer, password sprayer, and enumerator written in Rust on top of the Tokio async runtime. It is a modern replacement for THC-Hydra, Medusa, Ncrack, and Patator — benchmarked at 4.5× faster on HTTP basic…”

— opening of SKILL.md by evilsocket, Custom licence
name
legba

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/legba of evilsocket/legba.

Open the folder on GitHubat commit dab974b

Compare with similar skills

Legba next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Legba compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Legba this skillevilsocket/legba1.9k—~2.2kAutomated safety check: PassCustom licence
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0
Databuddydatabuddy-analytics/Databuddy1.2k—~2.1kAutomated safety check: PassAGPL-3.0
API Endpoint Contracttrycompai/comp2k—~2.7kAutomated safety check: PassAGPL-3.0
Cloudflare Email Servicehodgef/apiker1273 repos~2kAutomated safety check: PassMIT
Skyllassafelovic/skyll247—~928Automated safety check: PassApache-2.0

Similar skills

  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Databuddy

    databuddy-analytics/Databuddy

    Integrate Databuddy analytics using the SDK, REST API, or MCP.

    1.2k GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Endpoint Contract

    trycompai/comp

    The contract every new or modified API endpoint must follow so it is correct for the public OpenAPI spec, the MCP server (npm @trycompai/mcp-server), the ValidationPipe, and the docs.

    2k GitHub stars~2.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Send and receive transactional emails with Cloudflare Email Service (Email Sending + Email Routing).

    127 GitHub starsUsed in 3 repos~2k tokens
    Backend & APIsAuto-check passed
  • Skyll

    assafelovic/skyll

    Search and retrieve agent skills at runtime. An agent skill from assafelovic/skyll.

    247 GitHub stars~928 tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Pixiu MCP Gateway

    apache/dubbo-go-pixiu

    Creates and validates dubbo-go-pixiu MCP gateway conf.yaml. An agent skill from apache/dubbo-go-pixiu.

    568 GitHub stars~3.1k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

Categories

Questions about Legba

What does Legba do?

A skill your agent uses when the user wants to brute-force credentials, spray passwords, or enumerate services/subdomains against any network protocol (HTTP, SSH, FTP, SMB, RDP, databases, mail…. Legba is an agent skill from evilsocket/legba.) using legba.

When should I use Legba?

Legba fits situations like: the user wants to brute-force credentials; spray passwords; enumerate services/subdomains against any network protocol (HTTP; etc.) using legba.

How do I install Legba in Claude Code?

Run `npx skills add evilsocket/legba --skill legba -a claude-code`. Or copy the skill folder (skills/legba in evilsocket/legba) into .claude/skills/legba in your project. Claude Code loads it when a task matches its description.

How do I install Legba in Codex?

Run `npx skills add evilsocket/legba --skill legba -a codex`. Or copy the skill folder (skills/legba in evilsocket/legba) into .agents/skills/legba in your project. Codex loads it when a task matches its description.

Can I use Legba in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add evilsocket/legba --skill legba -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/legba, .gemini/skills/legba, .github/skills/legba and .opencode/skills/legba in your project.

What does Legba need to run?

Going by SKILL.md and its folder, Legba needs the command-line tools its instructions call (brew, cargo and docker). Our summary lists: Docker.

Does Legba access the network?

SKILL.md names 1 domain. As links in the text: legba.evilsocket.net. This is read from the text; nothing was executed.

Is Legba safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Legba use?

Legba has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Legba use?

About 2.2k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Legba?

Skills that share tags, products or a category with Legba: OpenAPI to MCP Server (mcp-use/mcp-use, 11k stars), Databuddy (databuddy-analytics/Databuddy, 1.2k stars), API Endpoint Contract (trycompai/comp, 2k stars) and Cloudflare Email Service (hodgef/apiker, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Legba?

evilsocket (a GitHub user) maintains it in evilsocket/legba, which has 1,949 GitHub stars. The repository was last updated on August 14, 2026.

Source: evilsocket/legba on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.