SkillAgentSearch skills...
Home

uphiago

81 skills across 81 repos103.7k repo starsGitHub

Showing 1–60 of 81 skills · Page 1 of 2

uphiago / cors-chain-automation

1.3k

Use when a bounded list of authorized API endpoints needs consistent CORS triage before browser validation.

📄 SKILL.mdzed
skillapiautomation+1
90
Updated 29d ago

uphiago / deep-invade

1.3k

Deep pentest WP: SSRF, plugin CVE, JS mine, port scan chain.

📄 SKILL.mduniversal
skillpython
90
Updated 29d ago

uphiago / firebase-supabase-attack

1.3k

Exploit Firebase/Supabase for data via JS config leak probe.

📄 SKILL.mduniversal
skillapipython+2
90
Updated 29d ago

uphiago / xmlrpc-exploitation

1.3k

Exploit XMLRPC multicall, pingback for brute force and SSRF.

📄 SKILL.mduniversal
skillpython
90
Updated 29d ago

uphiago / api-noauth-hunt

1.3k

Use when an API may expose data or privileged operations without authentication.

📄 SKILL.mduniversal
skillapipython+1
89
Updated 29d ago

uphiago / asn-infrastructure-mapping

1.3k

Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.

📄 SKILL.mduniversal
skill
89
Updated 29d ago

uphiago / cache-attack

1.3k

Poison CDN cache or deceive when X-Cache header is detected.

📄 SKILL.mduniversal
skill
89
Updated 29d ago

uphiago / cloud-iam-deep

1.3k

GCP/AWS/Azure cloud exploitation -- Cloud Functions, Firestore, Cloud Run, S3, MinIO, Blob Storage, SA keys

📄 SKILL.mduniversal
skillapiaws+4
89
Updated 29d ago

uphiago / cms-detection

1.3k

Identify CMS, frameworks, and server technology stacks on live hosts.

📄 SKILL.mduniversal
skill
89
Updated 29d ago

uphiago / exchange-owa-attack

1.3k

Exchange/OWA NTLM AD leak, spray attack when mail subdomain.

📄 SKILL.mduniversal
skillpython
89
Updated 29d ago

uphiago / flask-werkzeug-attack

1.3k

Exploit Flask/Werkzeug debugger exposure for traceback and SECRET leaks.

📄 SKILL.mduniversal
skillpython
89
Updated 29d ago

uphiago / github-secret-hunting

1.3k

Find leaked API keys, tokens, and credentials in public GitHub repositories.

📄 SKILL.mduniversal
skillgitapi+2
89
Updated 29d ago

uphiago / hardcoded-credential-hunt

1.3k

Detect hardcoded passwords in HTML forms, JavaScript, and API responses.

📄 SKILL.mduniversal
skillapipython
89
Updated 29d ago

uphiago / http2-header-impersonation

1.3k

Spoof HTTP/2 SETTINGS frames and pseudo-header order per browser profile.

📄 SKILL.mduniversal
skillpython
89
Updated 29d ago

uphiago / humanize-automation

1.3k

Human-like mouse, keyboard and scroll behavior for behavioral bot bypass.

📄 SKILL.mduniversal
skillapiautomation+1
89
Updated 29d ago

uphiago / hunt-broken-function-level-auth

1.3k

Hunt broken function-level authorization via verb drift, route shadowing, and transport gaps.

📄 SKILL.mduniversal
skillapi
89
Updated 29d ago

uphiago / hunt-fastapi

1.3k

Hunt FastAPI-specific vulnerabilities: dependency injection gaps, Pydantic coercion, and OpenAPI mining.

📄 SKILL.mduniversal
skillapisql+2
89
Updated 29d ago

uphiago / hunt-information-disclosure

1.3k

Hunt error leakage, DVCS exposure, source maps, config files, and differential oracles.

📄 SKILL.mduniversal
skillpython
89
Updated 29d ago

uphiago / hunt-mass-assignment

1.3k

Hunt mass assignment via sensitive field injection and ORM framework exploitation.

📄 SKILL.mduniversal
skillapipython
89
Updated 29d ago

uphiago / hunt-mcp-security

1.3k

Hunt Model Context Protocol (MCP) vulnerabilities in AI-tool integration systems.

📄 SKILL.mduniversal
skillapimcp+3
89
Updated 29d ago

uphiago / hunt-nestjs

1.3k

Hunt NestJS-specific vulnerabilities: guard bypass, decorator gaps, and microservice auth drift.

📄 SKILL.mduniversal
skillapisecurity+3
89
Updated 29d ago

uphiago / hunt-prototype-pollution

1.3k

Hunt client-side and server-side prototype pollution for XSS, auth bypass, and RCE.

📄 SKILL.mduniversal
skillapipython
89
Updated 29d ago

uphiago / hunt-wordpress

1.3k

Use when an authorized target exposes WordPress core, plugin, theme, REST, or XML-RPC behavior.

📄 SKILL.mdzed
skillapisecurity+1
89
Updated 29d ago

uphiago / js-secrets-extraction

1.3k

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

📄 SKILL.mduniversal
skillapireact+1
89
Updated 29d ago

uphiago / origin-ip-discovery

1.3k

Discover origin IPs behind CDN/WAF via favicon hash, DNS history, and SSL certs.

📄 SKILL.mduniversal
skillpython
89
Updated 29d ago

uphiago / port-service-discovery

1.3k

Nmap scan for MySQL, Redis, FTP, SSH, internal API services.

📄 SKILL.mduniversal
skillapisql+2
89
Updated 29d ago

uphiago / recon-playbook

1.3k

Use when starting or restructuring an authorized external web and API assessment.

📄 SKILL.mdzed
skillapirest
89
Updated 29d ago

uphiago / s3-minio-content-type-xss

1.3k

Exploit public bucket Content-Type override for stored XSS on target origin.

📄 SKILL.mduniversal
skillpythonfirebase
89
Updated 29d ago

uphiago / scada-hikvision-isapi

1.3k

Enumerate Hikvision ISAPI endpoints on SCADA and IoT web interfaces.

📄 SKILL.mduniversal
skillapisecurity+1
89
Updated 29d ago

uphiago / stealth-browser-launch

1.3k

Launch stealth Chromium with C++ fingerprint patches for anti-bot bypass.

📄 SKILL.mduniversal
skillautomationpython
89
Updated 29d ago

uphiago / tls-fingerprint-impersonation

1.3k

Spoof TLS ClientHello and JA4 fingerprints for browser impersonation.

📄 SKILL.mduniversal
skillautomationpython
89
Updated 29d ago

uphiago / unauth-api-flow-hijack

1.3k

Exploit unauthenticated multi-step API flows without credentials.

📄 SKILL.mduniversal
skillapipython
89
Updated 29d ago

uphiago / visual-recon

1.3k

Screenshot all live hosts for rapid visual triage and technology fingerprinting.

📄 SKILL.mduniversal
skillapipython
89
Updated 29d ago

uphiago / web-enumeration

1.3k

Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

📄 SKILL.mduniversal
skillgit
89
Updated 29d ago

uphiago / pentest-playbook

1.3k

7-phase pentest pipeline from passive recon to exploitation.

📄 SKILL.mduniversal
skillapipython+1
87
Updated 29d ago

uphiago / google-dorks-catalog

1.3k

High-precision Google dorks for exposed configs, secrets, and credentials -- real-world validated

📄 SKILL.mduniversal
skill
86
Updated 29d ago

uphiago / hunt-django

1.3k

Hunt Django-specific vulnerabilities: DRF permission gaps, ORM injection, and admin exploitation.

📄 SKILL.mduniversal
skillsqlsecurity+2
86
Updated 29d ago

uphiago / subdomain-takeover-hunt

1.3k

Detect and verify subdomain takeover via dangling CNAME to unclaimed services.

📄 SKILL.mduniversal
skillpythonazure
86
Updated 29d ago

uphiago / vhost-enumeration

1.3k

Discover hidden virtual hosts via Host header fuzzing and SSL certificate parsing.

📄 SKILL.mduniversal
skill
86
Updated 29d ago

uphiago / bb-local-toolkit

1.3k

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning, vuln hunting (30+ classes), A-to-B chaining, AI/LLM testing, bypass tables, language-specific grep, reporting. Use for ANY bug bounty task.

📄 SKILL.mduniversal
skilltesting
85
Updated 29d ago

uphiago / bug-bounty

1.3k

Master bug bounty orchestrator — full pipeline: recon, pre-hunt learning, vulnerability hunting (30+ classes), A-to-B chaining, AI/LLM testing (ASI01-ASI10), language-specific grep, bypass tables, and reporting (7-question gate, CVSS 3.1, human-tone templates).

📄 SKILL.mduniversal
skilltesting
85
Updated 29d ago

uphiago / hunt-api-misconfig

1.3k

Hunt API security misconfiguration — mass assignment, JWT attacks, prototype pollution, HTTP verb tampering. Mass assignment: send {is_admin:true, role:admin, verified:true} on profile/account/reset endpoints — server blindly applies.

📄 SKILL.mduniversal
skillapisecurity
85
Updated 29d ago

uphiago / hunt-brute-force

1.3k

Hunt Missing/Weak Rate Limiting — login brute force, OTP/2FA brute force (10^6 keyspace), password-reset-token brute, credential stuffing, username/email enumeration via error-string / status-code / timing differences, weak password policy, missing CAPTCHA, IP-based rate-limit bypass via X-Forwarded…

📄 SKILL.mduniversal
skill
85
Updated 29d ago

uphiago / hunt-firebase

1.3k

Hunt Firebase / Firestore / GCP exploitation — Firebase API key discovery in JS bundles, anonymous auth via signUp endpoint, Firestore collection enumeration with anon key, Realtime Database read/write without auth, Firebase Storage bucket listing, Firebase Hosting detection, GCP service account JSO…

📄 SKILL.mduniversal
skillapigcp+3
85
Updated 29d ago

uphiago / hunt-llm-ai

1.3k

Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration viatool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10).

📄 SKILL.mduniversal
skillsecurityimage
85
Updated 29d ago

uphiago / hunt-schema-enumeration

1.3k

Enumerate hidden tables, fields, and endpoints via API error hints. Agnostic across PostgREST, Zod, FastAPI, GraphQL, and REST.

📄 SKILL.mduniversal
skillapigraphql+2
85
Updated 29d ago

uphiago / hunt-supabase

1.3k

Hunt Supabase exploitation — Supabase anon key discovery in JS bundles, REST API table enumeration with anon key, Row Level Security (RLS) bypass via missing organization_id check, RPC function abuse returning cross-organization data, Storage bucket listing, Auth signUp/signIn with anon key, multi-t…

📄 SKILL.mduniversal
skillapisecurity+1
85
Updated 29d ago

uphiago / hunt-write-gap

1.3k

Hunt read-protected write-gaping endpoints. PATCH/POST/DELETE without authorization while GET is protected. Agnostic: Supabase, Firebase, REST, GraphQL.

📄 SKILL.mduniversal
skillapifirebase+2
85
Updated 29d ago

uphiago / llm-prompt-injection

1.3k

Use when testing an authorized LLM application for prompt injection, system-prompt exposure, unsafe tool use, or RAG data-boundary failures.

📄 SKILL.mdzed
skilltestingapi+1
85
Updated 29d ago

uphiago / ops-proxyns

1.3k

Kernel-level proxy protection via proxy-ns — forces ALL traffic (TCP/UDP/DNS) through Tor using Linux network namespaces. Unlike proxychains, this works with Go/Rust/static binaries, prevents DNS leaks, and is impossible for applications to bypass.

📄 SKILL.mduniversal
skillrust
85
Updated 29d ago

uphiago / password-spray-methodology

1.3k

End-to-end password spray playbook. User enumeration, lockout detection, password pattern generation, spray execution across all protocols, error code differentials, and engagement discipline.

📄 SKILL.mduniversal
skill
85
Updated 29d ago

uphiago / recon-sector-expansion

1.3k

Multi-sector batch domain expansion — identify untested/under-tested sectors, generate candidate company domains (national chains, franchises, regionals), filter against existing test coverage, probe alive domains, and run the full testing pipeline across 20+ new targets in a single session.

📄 SKILL.mduniversal
skilltesting
85
Updated 29d ago

uphiago / wp-plugin-automation

1.3k

Scripts and workflows to batch-test popular WordPress plugin CVEs across hundreds of domains. Covers automated plugin detection, version extraction from readme.txt, CVE matching against a curated matrix of high-impact plugin vulnerabilities (ElementsKit, Revslider, WPDM, Gravity Forms, Contact Form…

📄 SKILL.mduniversal
skillautomation
85
Updated 29d ago

uphiago / wp-plugin-cve-hunt

1.3k

Systematic approach to finding and testing CVEs for identified WordPress plugins. Covers plugin discovery, version extraction from multiple sources (readme.txt, assets, inline JS), CVE database cross-referencing with WPScan/Patchstack/NVD/NVD API, version-based vulnerability matching, exploitation P…

📄 SKILL.mduniversal
skilltestingapi+1
85
Updated 29d ago

uphiago / wp-plugin-rest-auth-bypass

1.3k

Scan WordPress REST API plugin endpoints for unauthenticated state-changing operations — discover write endpoints (POST/PUT/PATCH/DELETE) exposed without auth, enumerate all plugin routes, and test for unauthorized content publishing, settings modification, and data leakage.

📄 SKILL.mdzed
skillapipython+2
85
Updated 29d ago

uphiago / wstg-web-pentest

1.3k

Full WSTG-aligned web application pentest — 12-phase methodology from information gathering through reporting, with concrete commands, expected outputs, pitfalls, and verification per phase.

📄 SKILL.mduniversal
skillsqlpython
85
Updated 29d ago

uphiago / cross-attack-chains

1.3k

Use when two or more verified findings may combine into a higher-impact authorized attack path.

📄 SKILL.mdzed
skillsecurity
84
Updated 29d ago

uphiago / cross-wave-delta-analysis

1.3k

Compare recon waves to find NEW, REGRESSED, PERSISTENT findings.

📄 SKILL.mduniversal
skill
84
Updated 29d ago

uphiago / email-security

1.3k

DMARC/SPF/DKIM check, email spoofing, SMTP test, and security header analysis

📄 SKILL.mduniversal
skillsecurity
84
Updated 29d ago

uphiago / hunt-metrics-exposure

1.3k

Hunt public /metrics, /health, and actuator endpoints leaking AI usage, DB pools, and operational intelligence.

📄 SKILL.mduniversal
skill
84
Updated 29d ago