A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…
Apache-2.0Auto-check passed
Install Com Proxy Triage
skills CLI
$ npx skills add SpecterOps/skills --skill com-proxy-triage -a claude-code
Project install by default; add -g for ~/.claude/skills/.
Install the "com-proxy-triage" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/tradecraft-windows/skills/com-proxy-triage into .claude/skills/com-proxy-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "com-proxy-triage", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add SpecterOps/skills --skill com-proxy-triage -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "com-proxy-triage" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/tradecraft-windows/skills/com-proxy-triage into .agents/skills/com-proxy-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "com-proxy-triage", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add SpecterOps/skills --skill com-proxy-triage -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "com-proxy-triage" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/tradecraft-windows/skills/com-proxy-triage into .cursor/skills/com-proxy-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "com-proxy-triage", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add SpecterOps/skills --skill com-proxy-triage -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "com-proxy-triage" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/tradecraft-windows/skills/com-proxy-triage into .gemini/skills/com-proxy-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "com-proxy-triage", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add SpecterOps/skills --skill com-proxy-triage -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "com-proxy-triage" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/tradecraft-windows/skills/com-proxy-triage into .github/skills/com-proxy-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "com-proxy-triage", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add SpecterOps/skills --skill com-proxy-triage -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "com-proxy-triage" agent skill from https://github.com/SpecterOps/skills/tree/main/plugins/tradecraft-windows/skills/com-proxy-triage into .opencode/skills/com-proxy-triage/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "com-proxy-triage", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
com-proxy-triage
GitHub stars
702
Token cost
~1.5k tokens
SKILL.md length
578 words
Files
31 (incl. scripts, references, assets)
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0
At a glance
A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…
Works in 7 steps: Run the watcher from an elevated… → Keep only HKCU InProcServer32 misses… → Deduplicate by Clsid. → …
Mapping each CLSID to the machine-wide HKLM\SOFTWARE\Classes\CLSID\{...}\InProcServer32 DLL
SKILL.md covers Overview, Workflow, Rules and Database Snapshot, plus 1 more section
Optionally testing HKCU overrides with a Koppeling-style proxy DLL
What it does
Com Proxy Triage is an agent skill from SpecterOps/skills. Use this skill when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping each CLSID to the machine-wide HKLM\SOFTWARE\Classes\CLSID\{...}\InProcServer32 DLL, and optionally testing HKCU overrides with a Koppeling-style proxy DLL. Good for Zoom, Edge, and similar COM activation hunts.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 33 other files, including scripts, reference files and assets (for example `agents/openai.yaml` and `assets/apps.json`).
The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.
When your agent uses it
Mapping each CLSID to the machine-wide HKLM\SOFTWARE\Classes\CLSID\{...}\InProcServer32 DLL
Optionally testing HKCU overrides with a Koppeling-style proxy DLL
Example prompts
“/com-proxy-triage”
Workflow steps
7 steps, taken from the first numbered list in SKILL.md.
1Run the watcher from an elevated PowerShell session and filter to the target process with -ProcessName.
2Keep only HKCU InProcServer32 misses where MachineInprocServer32 is present.
3Deduplicate by Clsid.
4Build or reuse a proxy DLL that clones the HKLM target DLL's exports and runs the chosen payload.
5Override HKCU\Software\Classes\CLSID{CLSID}\InProcServer32, launch a fresh target process, and check whether the payload fired.
6Restore the prior HKCU state after every test. If the key did not exist before, remove it.
7Resolve installed apps by name first. Use assets\apps.json as an override cache when present, not as a required source of truth.
What it can do on your machine
Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships 1 file in scripts/, which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Com Proxy Triage loads about 1.5k tokens when it runs, and up to ~2.1k if it reads all its reference files. Until then it costs about 106 tokens; SKILL.md has 578 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~106
When it runs· the whole SKILL.md, loaded when a task matches
~1.5k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~2.1k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Download SKILL.mdSave it as .claude/skills/com-proxy-triage/SKILL.md (or your agent's skills folder). This skill also uses 30 other files; get the full folder from GitHub.
name
com-proxy-triage
description
Use this skill when the user wants to triage Windows COM proxy/hijack candidates by capturing `HKCU\Software\Classes\CLSID\{...}\InProcServer32` `NAME NOT FOUND` lookups for a process, mapping each CLSID to the machine-wide `HKLM\SOFTWARE\Classes\CLSID\{...}\InProcServer32` DLL, and optionally testing HKCU overrides with a Koppeling-style proxy DLL. Good for Zoom, Edge, and similar COM activation hunts.
metadata.author
GhostWorks
COM Proxy Triage
Overview
This skill captures live OpenKey misses for *InProcServer32, enriches them with the corresponding machine-wide InProcServer32 DLL, and tests only CLSIDs that have a usable HKLM backing DLL.
Fresh hosts should start with scripts/Initialize-ComHijackHost.ps1 -ValidateOnly. If the FAIL rows show missing build prerequisites such as MSBuild, VC x64 toolchain, Windows SDK, or vswhere/Visual Studio Build Tools details, run scripts/Initialize-ComHijackHost.ps1 -InstallBuildTools and then rerun -ValidateOnly before full validation. Use scripts/Watch-InProcServer32Misses.ps1 for the capture step, scripts/Invoke-ComHijackProbe.ps1 for a low-level probe, scripts/Invoke-ComHijackApp.ps1 for an app-name-first single-app run, scripts/Invoke-ComHijackSurvey.ps1 for batch runs, and scripts/Get-ComHijackOverlap.ps1 to analyze the running JSONL database. Read references/workflow.md when you need the concrete test loop, registry handling, or Koppeling build notes.
Workflow
Run the watcher from an elevated PowerShell session and filter to the target process with -ProcessName.
Keep only HKCUInProcServer32 misses where MachineInprocServer32 is present.
Deduplicate by Clsid.
Build or reuse a proxy DLL that clones the HKLM target DLL's exports and runs the chosen payload.
Override HKCU\Software\Classes\CLSID\{CLSID}\InProcServer32, launch a fresh target process, and check whether the payload fired.
Restore the prior HKCU state after every test. If the key did not exist before, remove it.
Resolve installed apps by name first. Use assets\apps.json as an override cache when present, not as a required source of truth.
Rules
Ignore candidates that do not have a corresponding MachineInprocServer32 value.
Treat 0xC0000034 as NAME NOT FOUND.
Prefer cold-start launches of the target app for each test.
Record whether the payload fired and whether the proxy DLL was actually loaded.
Never leave a test override behind unless the user explicitly asks to keep it.
Treat the repo-local Koppeling\ submodule as the primary proxy dependency. Only fall back to adjacent or Documents\Codex checkouts if the submodule is unavailable.
Seed Koppeling\Bin\NetClone.exe from assets\koppeling-netclone\ before trying to rebuild it on a fresh or offline host.
Always write discovery artifacts even when the host is missing the VC toolchain for full payload validation.
By default, validate every discovered candidate. Use -MaxCandidates only as an explicit throttle for faster spot checks.
When Initialize-ComHijackHost.ps1 -ValidateOnly fails on build-toolchain checks (MSBuild, VC x64 toolchain, Windows SDK, or vswhere/Build Tools-related details), run Initialize-ComHijackHost.ps1 -InstallBuildTools before retrying full validation.
Do not treat -InstallBuildTools as a fix for missing elevation, missing target apps, or other non-toolchain blockers; discovery-only runs remain valid when full validation is not possible.
Show full SKILL.md (182 more words)Show less
Database Snapshot
Before pushing updates to com-proxy-triage, verify whether the published COM-Proxy-Database snapshot also needs to be refreshed.
If the push changes probe behavior, result semantics, or dashboard-visible fields, update the local COM-Proxy-Database clone, run scripts\Refresh-ComProxyDatabaseSnapshot.ps1, and push that repo as part of the same publishing pass.
Keep the published database snapshot aligned with the live dashboard metrics:
Active Apps, Unique CLSIDs, Unique DLLs, Shared DLLs, and Shared CLSIDs.
Com Proxy Triage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Runs KAPE (Kroll Artifact Parser and Extractor) to collect targeted forensic artifacts (registry hives, $MFT, event logs, prefetch, browser data) via Targets and parse them with Modules wrapping…
Triage Paperclip inbox issues that are stale, blocked, in-review, or assigned-but-not-progressing, and decide a single next action per issue (resume, reassign, unblock, escalate, or close).
Triage an incoming GitHub issue against the pnpm codebase and related open issues, then apply exactly one implementation-readiness label using pnpm's state: taxonomy.
Triages open herdr GitHub issues into a short decision-first Markdown table with a priority light, recommendation, age, reactions and a reason for each.
Runs issue triage and PR triage in parallel, then cross-analyzes the results to flag duplicate coverage, security gaps, P0 issues with no PR, and PR conflicts.
A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.
Run in-scope network commands through a SOCKS5 tunnel with proxychains4, including tunnel readiness checks and evidence capture.
702 GitHub stars~826 tokensUpdated 14 days ago
Auto-check passed
Questions about Com Proxy Triage
What does Com Proxy Triage do?
A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…. Com Proxy Triage is an agent skill from SpecterOps/skills.}\InProcServer32 DLL, and optionally testing HKCU overrides with a Koppeling-style proxy DLL.
When should I use Com Proxy Triage?
Com Proxy Triage fits situations like: mapping each CLSID to the machine-wide HKLM\SOFTWARE\Classes\CLSID\{...}\InProcServer32 DLL; optionally testing HKCU overrides with a Koppeling-style proxy DLL.
How do I install Com Proxy Triage in Claude Code?
Run `npx skills add SpecterOps/skills --skill com-proxy-triage -a claude-code`. Or copy the skill folder (plugins/tradecraft-windows/skills/com-proxy-triage in SpecterOps/skills) into .claude/skills/com-proxy-triage in your project. Claude Code loads it when a task matches its description.
How do I install Com Proxy Triage in Codex?
Run `npx skills add SpecterOps/skills --skill com-proxy-triage -a codex`. Or copy the skill folder (plugins/tradecraft-windows/skills/com-proxy-triage in SpecterOps/skills) into .agents/skills/com-proxy-triage in your project. Codex loads it when a task matches its description.
Can I use Com Proxy Triage in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill com-proxy-triage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/com-proxy-triage, .gemini/skills/com-proxy-triage, .github/skills/com-proxy-triage and .opencode/skills/com-proxy-triage in your project.
What does Com Proxy Triage need to run?
SKILL.md names no scripts, command-line tools or credentials: Com Proxy Triage is instructions for the agent only.
Does Com Proxy Triage access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Com Proxy Triage safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
What licence does Com Proxy Triage use?
Com Proxy Triage is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Com Proxy Triage use?
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 597 tokens, read only when the agent opens those files.
What are the alternatives to Com Proxy Triage?
Skills that share tags, products or a category with Com Proxy Triage: Triaging Windows With Kape (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Triaging Issues (pytorch/pytorch, 104k stars), Issue Triage (paperclipai/paperclip, 98k stars) and Triage (pnpm/pnpm, 37k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Com Proxy Triage?
SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 702 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.
Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.