Skill4Agent
Skill4Agent
All SkillsSearchTools
|
Explore
Skill4Agent
Skill4Agent

AI Agent Skills Directory with categorization, English/Chinese translation, and script security checks.

Sitemap

  • Home
  • All Skills
  • Search
  • Tools

About

  • About Us
  • Disclaimer
  • Copyright

Help

  • FAQ
  • Privacy
  • Terms
Contact Us:osulivan147@qq.com

© 2026 Skill4Agent. All rights reserved.

All Skills

Total 39,884 skills

Categories

Showing 12 of 39884 skills

Per page
Downloads
Sort
Security & Complianceyaklang/hack-skills

http-parameter-pollution

HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when filters and application layers disagree on which value wins, enabling bypass, SSRF second URL, logic abuse, or CSRF token confusion.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

authbypass-authentication-flaws

Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

api-recon-and-docs

API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

api-auth-and-jwt-abuse

API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

expression-language-injection

Expression Language injection playbook. Use when Java EL, SpEL, OGNL, or MVEL expressions may evaluate attacker-controlled input in Spring, Struts2, Confluence, or similar frameworks.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

sqli-sql-injection

SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

open-redirect

Open redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users to attacker-controlled destinations.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

subdomain-takeover

Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned cloud resources, expired third-party services, or unclaimed SaaS tenants that an attacker can register to serve content under the victim's domain.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

dangling-markup-injection

Dangling markup injection playbook. Use when HTML injection is possible but JavaScript execution is blocked (CSP, sanitizer strips event handlers, WAF blocks script tags) — exfiltrate CSRF tokens, session data, and page content by injecting unclosed HTML tags that capture subsequent page content.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

rsa-attack-techniques

RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to recover plaintext by exploiting weak keys, small exponents, shared factors, or padding oracles.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

hash-attack-techniques

Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios.

🇺🇸|EnglishTranslated
1
Security & Complianceyaklang/hack-skills

container-escape-techniques

Container escape playbook. Use when operating inside a Docker container, LXC, or Kubernetes pod and need to escape to the host via privileged mode, capabilities, Docker socket, cgroup abuse, namespace tricks, or runtime vulnerabilities.

🇺🇸|EnglishTranslated
1
1...33203321332233233324
Page