offensive-security▌
113 indexed skills · max 10 per page
ai-asset-scanner
whyashthakker/beam-cli · ai-asset-scanner
### ai-asset-scanner - Discover and review AI assets in a supplied repository or exported inventory, including agents, model dependencies, prompts, MCP integration - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
browser-agent-security
whyashthakker/beam-cli · browser-agent-security
### browser-agent-security - Review agents that control a browser or GUI (clicking, typing, navigating, screenshotting) for prompt injection from page content, dangerous - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
multi-agent-trust-review
whyashthakker/beam-cli · multi-agent-trust-review
### multi-agent-trust-review - Review systems where one agent spawns, delegates to, or consumes output from other agents or sub-agents — orchestrators, planner/worker patt - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
prompt-injection-review
whyashthakker/beam-cli · prompt-injection-review
### prompt-injection-review - Review an agent application, prompt assembly, retrieved content, or supplied incident trace for prompt injection and unsafe tool effects. Us - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
secrets-egress-review
whyashthakker/beam-cli · secrets-egress-review
### secrets-egress-review - Trace how AI agents and their applications can read secrets or sensitive data and send it to logs, tools, model providers, files, or network - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
tool-schema-review
whyashthakker/beam-cli · tool-schema-review
### tool-schema-review - Review tool and function definitions exposed to a model — names, descriptions, parameter schemas, and return shapes — for embedded instructi - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
webhook-callback-security
whyashthakker/beam-cli · webhook-callback-security
### webhook-callback-security - Review inbound webhooks and callbacks that trigger agent actions — signature verification, replay protection, payload trust, and the authori - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
skill-scanner
whyashthakker/beam-cli · skill-scanner
### skill-scanner - Review agent skill folders, archives, repository references, or updates before installation for instruction abuse, executable behavior, perm - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-oauth
SnailSploit/Claude-Red · auth
### offensive-oauth - - **Skill Name**: oauth-attacks - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.
offensive-edr-evasion
SnailSploit/Claude-Red · infrastructure
### offensive-edr-evasion - - **Skill Name**: edr-evasion - Practical, repeatable guidance for authorized security work. - Includes procedures, checks, and references for this skill.