Use Yaak
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…
$ npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills attacking-grpc-protobuf --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-offense/skills/attacking-grpc-protobuf .claude/skills/attacking-grpc-protobuf && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "attacking-grpc-protobuf" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-grpc-protobuf into .claude/skills/attacking-grpc-protobuf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-grpc-protobuf", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-grpc-protobufType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills attacking-grpc-protobuf --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-offense/skills/attacking-grpc-protobuf .agents/skills/attacking-grpc-protobuf && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "attacking-grpc-protobuf" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-grpc-protobuf into .agents/skills/attacking-grpc-protobuf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-grpc-protobuf", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills attacking-grpc-protobuf --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-offense/skills/attacking-grpc-protobuf .cursor/skills/attacking-grpc-protobuf && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "attacking-grpc-protobuf" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-grpc-protobuf into .cursor/skills/attacking-grpc-protobuf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-grpc-protobuf", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-offense/skills/attacking-grpc-protobuf--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills attacking-grpc-protobuf --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-offense/skills/attacking-grpc-protobuf .gemini/skills/attacking-grpc-protobuf && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "attacking-grpc-protobuf" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-grpc-protobuf into .gemini/skills/attacking-grpc-protobuf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-grpc-protobuf", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills attacking-grpc-protobufInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-offense/skills/attacking-grpc-protobuf .github/skills/attacking-grpc-protobuf && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "attacking-grpc-protobuf" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-grpc-protobuf into .github/skills/attacking-grpc-protobuf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-grpc-protobuf", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills attacking-grpc-protobuf --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-offense/skills/attacking-grpc-protobuf .opencode/skills/attacking-grpc-protobuf && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "attacking-grpc-protobuf" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-offense/skills/attacking-grpc-protobuf into .opencode/skills/attacking-grpc-protobuf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "attacking-grpc-protobuf", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
attacking-grpc-protobufTest gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…
Attacking Grpc Protobuf is an agent skill from trilwu/secskills. Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web traffic, and fuzzing unknown message schemas with protobuf-inspector. Use when a target speaks gRPC, HTTP/2 with application/grpc, or when a request body is opaque binary protobuf rather than JSON.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering gRPC and Protobuf. It works with gRPC. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rgpython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
attack.mitre.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Attacking Grpc Protobuf loads about 2.2k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 828 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 828 words, ~2,233 tokens.
.claude/skills/attacking-grpc-protobuf/SKILL.md (or your agent's skills folder).gRPC breaks the tooling assumption that a request is readable text over HTTP/1.1. Burp shows a binary blob or nothing at all, and without the schema you cannot even name the methods. Recover the schema and it becomes an ordinary API test — with the twist that gRPC services are frequently internal services newly exposed, which means their authorization is often weaker than the REST API in front of them.
content-type: application/grpc.proto files, *_pb2.py, *.pb.go, or grpc in a codebaseapplication/grpc-web or application/grpc-web+proto appears in a browser apptesting-apisbypassing-mobile-pinning; gRPC clients often ignore system proxy settingsauditing-code-for-vulnerabilities, and
read the .proto files directlyanalyzing-binariesEverything depends on this. Four routes, in order of cost.
1. Server reflection. Many services ship it enabled, often unintentionally.
grpcurl -plaintext target:50051 list
grpcurl -plaintext target:50051 list package.ServiceName
grpcurl -plaintext target:50051 describe package.ServiceName.MethodName
grpcurl -plaintext target:50051 describe package.RequestMessage
# TLS
grpcurl target:443 list
grpcurl -insecure target:443 list # self-signed / proxy in pathReflection enabled on an internet-facing service is itself worth reporting — it is the gRPC equivalent of GraphQL introspection in production.
2. Descriptors compiled into a client. Protobuf embeds a serialized
FileDescriptorProto in generated code, so the schema is recoverable from any
client binary.
# Mobile/desktop client: find and extract descriptor blobs
rg -a -o 'google/protobuf/descriptor.proto|\.proto' target_binary | head
# protobuf-inspector and protod can reconstruct .proto from embedded descriptors
protod target_binary -o ./protos
# JS/web clients: the descriptor is usually in the bundle as base64 or an array
rg -n 'grpc-web|serializeBinary|deserializeBinary' bundle.js | head3. From the app's source or artifacts. .proto files in a repo, a Swagger
gateway config, or generated stubs in a package.
4. Field-by-field inference. When you have neither, decode the wire format directly. Protobuf is self-describing enough to recover structure without the schema:
protoc --decode_raw < message.bin
protobuf-inspector < message.bin
# Output: field numbers, wire types, and values — enough to fuzz and to
# recognize strings, nested messages, and integersYou lose field names but keep field numbers, which is all the wire format needs. That is sufficient to modify values and to add fields the client never sends.
# With reflection
grpcurl -plaintext -d '{"user_id": 1}' target:50051 package.Service/GetUser
# With a local .proto
grpcurl -import-path ./protos -proto api.proto \
-d '{"user_id": 1}' target:50051 package.Service/GetUser
# Interactive browser UI, good for exploring
grpcui -plaintext target:50051
# Headers, including auth
grpcurl -H 'authorization: Bearer eyJ...' -plaintext target:50051 package.Service/ListFor streaming methods, grpcurl accepts newline-delimited JSON on stdin for
client streaming, and prints each message for server streaming. Streaming
endpoints are frequently less-tested than unary ones and worth specific
attention.
# mitmproxy speaks HTTP/2 and can decode gRPC with a schema
mitmproxy --mode regular --set http2=true
# the gRPC content-view renders protobuf; supply .proto for field names
# Burp: enable HTTP/2, and use a protobuf decoder extension
# without one, you see length-prefixed binary frames
# gRPC-Web is easier — it rides HTTP/1.1 with base64 or binary framing,
# so a normal proxy sees the requestsgRPC framing: each message is a 1-byte compression flag, a 4-byte
big-endian length, then the protobuf bytes. When a decoder shows nothing,
strip those five bytes before feeding the payload to protoc --decode_raw.
python3 -c "
import sys
d = sys.stdin.buffer.read()
sys.stdout.buffer.write(d[5:])" < frame.bin | protoc --decode_rawClients that ignore the system proxy need a network-layer redirect; see
bypassing-mobile-pinning.
The bug classes are the same as any API, but gRPC changes where they hide.
Authorization per method. gRPC has no path-based access control, so a
reverse proxy or WAF that filters /admin/* does nothing. Each method must
check authorization itself — enumerate every method from reflection and call
each one with a low-privilege token.
for m in $(grpcurl -plaintext target:50051 list package.Service | tail -n +2); do
echo "== $m"; grpcurl -H "authorization: Bearer $LOW_PRIV" -plaintext -d '{}' target:50051 "$m" 2>&1 | head -3
doneInternal services exposed. gRPC is a service-mesh protocol, so many services were written assuming only other services would call them. If you can reach one directly, expect no authentication at all — and expect it to trust identity claims passed as ordinary request fields or metadata.
Metadata trust. Look for headers the service reads as identity:
x-user-id, x-tenant-id, x-forwarded-user. If a gateway sets them and the
service trusts them, sending them yourself is a complete authentication bypass.
grpcurl -H 'x-user-id: 1' -H 'x-role: admin' -plaintext -d '{}' target:50051 package.Service/GetProfileUnknown-field injection. Protobuf ignores fields it does not recognize,
but intermediate services may forward them. More usefully: add fields the
client never sends but the server schema defines — is_admin,
internal_notes, tenant_id — the mass-assignment equivalent.
Type confusion and resource exhaustion. Wire types are loosely enforced;
send a bytes where a string is expected, deeply nested messages to blow
the recursion limit, or a huge repeated field. Check for a configured
message size limit.
TLS and mTLS posture. Many gRPC deployments use insecure channels
internally. Check whether the service accepts plaintext, and whether mTLS is
required or merely optional.
protoc --decode_raw
recovers structure from any message. Field numbers are all you need.<!-- attack:start -->
Generated from secskills-core/ttp-index.json — edit that file, then run
python3 scripts/sync_attack.py --write. Re-verify IDs against the
current ATT&CK release before citing them in a report.
Initial Access (TA0001)
testing-web-applications, testing-apis, enumerating-network-services, attacking-graphql, exploiting-deserialization, exploiting-ssrf, exploiting-xxeDetection content for any of these: engineering-detections. Proactive search: hunting-threats. Post-compromise: responding-to-incidents.
<!-- attack:end -->
testing-apis — the general API methodology this specializesauditing-code-for-vulnerabilities — reading .proto and handlers in sourcebypassing-mobile-pinning — when a mobile gRPC client ignores your proxyexploiting-cloud-platforms — service mesh and internal exposure context© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-offense/skills/attacking-grpc-protobuf of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Attacking Grpc Protobuf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Attacking Grpc Protobuf this skilltrilwu/secskills | 157 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Use Yaakmountain-loop/yaak | 19k | — | ~1.9k | Automated safety check: Pass | MIT | |
| Golang Proantoniopaya22/go-rest-template | 172 | 3 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Debug Grpc ConnectionGetBindu/Bindu | 10k | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Aspnet Corefanslead/ReverseProxy.Store | 161 | 2 repos | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Regenerate Grpc StubsGetBindu/Bindu | 10k | — | ~810 | Automated safety check: Pass | Custom licence |
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
antoniopaya22/go-rest-template
Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…
GetBindu/Bindu
Diagnose gRPC connection issues between the Bindu core and a language SDK.
fanslead/ReverseProxy.Store
Build, review, refactor, or architect ASP.NET Core web applications using current official guidance for .NET web development.
GetBindu/Bindu
Regenerate Python + TypeScript gRPC stubs after editing proto files.
aoyunyang/spider-king-skill
Pure-web protocol reverse skill: turn hostile browser clients into browser-free Python collectors.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Categories
Test gRPC and Protocol Buffers services — recovering .proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web…. Attacking Grpc Protobuf is an agent skill from trilwu/secskills.proto definitions from server reflection or compiled descriptors, calling methods with grpcurl and grpcui, intercepting HTTP/2 and gRPC-Web traffic, and fuzzing unknown message schemas with protobuf-inspector.
Attacking Grpc Protobuf fits situations like: A target speaks gRPC; HTTP/2 with application/grpc; A request body is opaque binary protobuf rather than JSON.
Run `npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a claude-code`. Or copy the skill folder (secskills-offense/skills/attacking-grpc-protobuf in trilwu/secskills) into .claude/skills/attacking-grpc-protobuf in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a codex`. Or copy the skill folder (secskills-offense/skills/attacking-grpc-protobuf in trilwu/secskills) into .agents/skills/attacking-grpc-protobuf in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill attacking-grpc-protobuf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/attacking-grpc-protobuf, .gemini/skills/attacking-grpc-protobuf, .github/skills/attacking-grpc-protobuf and .opencode/skills/attacking-grpc-protobuf in your project.
Going by SKILL.md and its folder, Attacking Grpc Protobuf needs the command-line tools its instructions call (rg and python3). Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: attack.mitre.org. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Attacking Grpc Protobuf is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Attacking Grpc Protobuf: Use Yaak (mountain-loop/yaak, 19k stars), Golang Pro (antoniopaya22/go-rest-template, 172 stars), Debug Grpc Connection (GetBindu/Bindu, 10k stars) and Aspnet Core (fanslead/ReverseProxy.Store, 161 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.