Skip to main content

Database

Browse 6,168 skills across 448 packs and 38 categories

Showing 1681–1740 of 1,758 skills
1,758 skills found in Technology & Engineering

red-team-operations

44L

Red team engagement methodology covering objective-based adversary simulation and stealth assessment for authorized operations

Technology & EngineeringPentest Methodology

web-app-pentest

46L

Web application penetration testing aligned with the OWASP Testing Guide for authorized security assessments

Technology & EngineeringPentest Methodology

wireless-pentest

44L

Wireless network penetration testing covering WPA/WPA2/WPA3 assessment and rogue access point detection for authorized engagements

Technology & EngineeringPentest Methodology

asn-ip-mapping

101L

ASN/IP range awareness, WHOIS lookups, and BGP route analysis for authorized security assessments

Technology & EngineeringRecon Agent

asset-discovery

98L

Asset discovery, DNS enumeration, and subdomain mapping for authorized security assessments

Technology & EngineeringRecon Agent

attack-surface-mapping

128L

External attack surface mapping, forgotten asset detection, and domain drift analysis for authorized assessments

Technology & EngineeringRecon Agent

certificate-analysis

130L

Certificate transparency analysis, SSL/TLS review, and cert chain validation for authorized assessments

Technology & EngineeringRecon Agent

osint-gathering

118L

Open source intelligence collection, data leak checks, and metadata extraction for authorized assessments

Technology & EngineeringRecon Agent

service-inventory

113L

Service inventory and technology fingerprinting for authorized security assessments

Technology & EngineeringRecon Agent

compliance-mapping

171L

Compliance framework alignment including CIS, NIST, ISO 27001, SOC 2, PCI DSS, and HIPAA

Technology & EngineeringReporting Agent

executive-summary

181L

Executive summary writing and non-technical security communication

Technology & EngineeringReporting Agent

findings-documentation

176L

Clear vulnerability findings documentation with reproducible steps and evidence handling

Technology & EngineeringReporting Agent

remediation-mapping

197L

Remediation mapping, fix prioritization, and timeline estimation

Technology & EngineeringReporting Agent

severity-scoring

185L

CVSS scoring, risk rating methodology, and business impact assessment

Technology & EngineeringReporting Agent

change-safety

179L

Change safety guardrails for security testing, do-not-touch asset protection, and rollback planning

Technology & EngineeringSafety Scope Guard

legal-authorization

169L

Legal authorization verification, rules of engagement compliance, and regulatory awareness for security testing

Technology & EngineeringSafety Scope Guard

proof-only-mode

152L

Non-destructive vulnerability validation, proof-of-concept without exploitation, and safe evidence collection

Technology & EngineeringSafety Scope Guard

rate-limiting-safety

152L

Safe testing rate limits, resource-aware scanning, and production disruption avoidance

Technology & EngineeringSafety Scope Guard

scope-enforcement

148L

Scope enforcement for penetration testing, authorized target validation, and boundary compliance

Technology & EngineeringSafety Scope Guard

awareness-gaps

192L

Security awareness gap assessment, training effectiveness measurement, and human risk quantification

Technology & EngineeringSocial Engineering Readiness

helpdesk-abuse

190L

Helpdesk abuse path identification, pretexting scenarios, and identity verification bypass testing

Technology & EngineeringSocial Engineering Readiness

phishing-simulation

175L

Phishing simulation campaign planning, pretext development, payload design, and metrics collection

Technology & EngineeringSocial Engineering Readiness

physical-security

210L

Physical security assessment, tailgating testing, badge cloning awareness, and facility access review

Technology & EngineeringSocial Engineering Readiness

process-weakness

184L

Business process weakness identification, verification flow testing, and social engineering attack path analysis

Technology & EngineeringSocial Engineering Readiness

awareness-program-design

56L

Build and measure security awareness programs with baseline assessments, simulated attacks, and behavior change metrics

Technology & EngineeringSocial Engineering

mfa-bypass-testing

54L

Test MFA resilience through authorized adversary-in-the-middle, push fatigue, and recovery code exposure assessments

Technology & EngineeringSocial Engineering

phishing-campaign-design

57L

Design and execute authorized phishing simulation campaigns with GoPhish and King Phisher

Technology & EngineeringSocial Engineering

physical-social-engineering

56L

Conduct authorized physical social engineering assessments including tailgating, impersonation, and USB drops

Technology & EngineeringSocial Engineering

pretexting

55L

Develop and deploy pretexts for authorized social engineering engagements using structured methodology

Technology & EngineeringSocial Engineering

smishing

55L

Design and execute authorized SMS phishing simulations with proper consent and opt-out controls

Technology & EngineeringSocial Engineering

social-engineering-reporting

56L

Report social engineering assessment findings with metrics, human factor analysis, and executive-ready remediation plans

Technology & EngineeringSocial Engineering

spear-phishing

54L

Execute targeted spear-phishing simulations for authorized red team engagements with OSINT-driven pretexts

Technology & EngineeringSocial Engineering

vishing

54L

Conduct authorized voice phishing assessments against helpdesks and personnel targets

Technology & EngineeringSocial Engineering

watering-hole-assessment

54L

Simulate watering hole attacks in controlled environments to test browser security and web filtering controls

Technology & EngineeringSocial Engineering

adversary-emulation

46L

Map adversary behaviors to ATT&CK, emulate tactics, and validate detection coverage

Technology & EngineeringThreat Intel Agent

ioc-management

46L

IOC collection, enrichment, scoring, lifecycle management, and sharing via STIX/TAXII

Technology & EngineeringThreat Intel Agent

malware-triage

47L

Static and behavioral malware triage, config extraction, family clustering, and sandbox analysis

Technology & EngineeringThreat Intel Agent

threat-actor-tracking

48L

Track threat actors, campaigns, infrastructure patterns, and targeting trends

Technology & EngineeringThreat Intel Agent

threat-landscape

46L

Threat landscape analysis, trend reporting, and strategic risk forecasting

Technology & EngineeringThreat Intel Agent

access-control

140L

Authorization testing, privilege escalation, and IDOR detection for authorized security assessments

Technology & EngineeringWeb Appsec Agent

api-security-testing

162L

API auth flows, rate limiting, schema validation, and GraphQL security testing for authorized assessments

Technology & EngineeringWeb Appsec Agent

auth-testing

144L

Authentication review, credential handling, and session management testing for authorized assessments

Technology & EngineeringWeb Appsec Agent

business-logic

165L

Business logic flaw detection, race conditions, and workflow bypass testing for authorized assessments

Technology & EngineeringWeb Appsec Agent

input-validation

146L

XSS, SQLi, command injection, and template injection testing for authorized security assessments

Technology & EngineeringWeb Appsec Agent

Next.js Security

113L

Use this skill when securing or reviewing a Next.js application. Activate when users mention next.js typescript security, App Router security, server actions, server components, middleware auth, NEXT_PUBLIC env leaks, SSRF in image optimization, CVE-2025 middleware bypass, route handler validation, or hardening a Vercel/self-hosted Next deployment.

Technology & EngineeringWeb Appsec Agent

web-config-review

155L

Security headers, CORS, CSP, cookie flags, and TLS configuration review for authorized assessments

Technology & EngineeringWeb Appsec Agent

bluetooth-review

141L

Bluetooth and BLE security assessment, pairing weakness analysis, sniffing, and device enumeration

Technology & EngineeringWireless IoT Agent

guest-network

135L

Guest network isolation testing, captive portal bypass, and visitor network security assessment

Technology & EngineeringWireless IoT Agent

home-network

139L

Home and small business network security assessment, router posture, smart device review, and WFH security

Technology & EngineeringWireless IoT Agent

iot-exposure

136L

IoT device exposure assessment, default credential testing, firmware review, and protocol analysis

Technology & EngineeringWireless IoT Agent

wifi-assessment

133L

Wi-Fi security configuration review, WPA enterprise testing, rogue AP detection, and wireless attack surface analysis

Technology & EngineeringWireless IoT Agent

brand-mention-monitoring

45L

Monitor mentions of brands, domains, and employee emails across dark web sources

Technology & EngineeringDark Web Monitoring

leak-site-monitoring

45L

Ransomware leak-site monitoring, extortion workflow tracking, and victim notification

Technology & EngineeringDark Web Monitoring

tor-ecosystem-awareness

45L

Onion service structure, abuse patterns, hosting indicators, and scam typologies

Technology & EngineeringDark Web Monitoring

underground-market-research

47L

Study productized crime trends including access sales, stealer logs, and fraud services (research-only)

Technology & EngineeringDark Web Monitoring

credential-leak-detection

45L

Detect credential leaks, stealer-log references, and breach monitoring for organizational accounts

Technology & EngineeringLeak Exposure Monitoring

data-exposure-analysis

45L

Detect customer data mentions, PII exposure, and data dump analysis for breach assessment

Technology & EngineeringLeak Exposure Monitoring

executive-exposure-review

47L

Assess doxxing risk, credential reuse, and public digital footprint for high-risk individuals

Technology & EngineeringLeak Exposure Monitoring

source-code-exposure

46L

Detect source code exposure, config dumps, and secret leaks in public repositories

Technology & EngineeringLeak Exposure Monitoring

supply-chain-monitoring

47L

Monitor for typosquat packages, dependency abuse, malicious updates, and fake repositories

Technology & EngineeringLeak Exposure Monitoring