Catalog pagination

Agent Skills catalog · page 142

Standard HTML pagination keeps the complete catalog discoverable. Use the main directory for search, filtering, and comparison.

Current page
142/209
Entries on page
24
URL status
Self-canonical
Computed 9367

brucesongs/kali-claw

email-security-deep

Phishing infrastructure and email gateway bypass covering AiTM MFA interception (evilginx2/modlishka/evilgophish), campaign platforms (gophish/King-Phisher), enterprise gateway evasion (Proofpoint/Mimecast/Cisco ESA/Microsoft Defender for Office), email bombing/DoS, sender reputation engineering, and full-stack campaign operations including landing pages, payload staging, and post-click telemetry — complementary to email-protocol-attack which handles protocol-level forgery.

Computed 9367

brucesongs/kali-claw

firmware-reverse

Firmware reverse engineering covers the full pipeline from raw firmware image acquisition through filesystem extraction, static and dynamic analysis, full-system emulation, and vulnerability/backdoor detection.

Computed 9367

brucesongs/kali-claw

kubernetes-attack

Kubernetes cluster attack and red team covering RBAC abuse, pod escape (privileged pods, hostPath, capabilities, hostPID/hostIPC, container runtime sockets, kernel CVEs), kubelet API abuse (10250/10255), etcd direct access, service account token theft (legacy and projected), RBAC privilege escalation chains, cloud-managed K8s (EKS/GKE/AKS) pivoting, and kubectl plugin ecosystem (peirates, CDK, kube-hunter, BOtB, kubeletctl, kubescape, stratus-red-team, kubernetes-goat).

Computed 9367

brucesongs/kali-claw

mcp-server-patterns

Building and security-testing MCP (Model Context Protocol) servers for Kali Linux security tools.

Computed 9367

brucesongs/kali-claw

quantum-crypto-attack

Post-quantum and modern national cryptography attack surface testing covering NIST PQC candidates (ML-KEM/ML-DSA/SLH-DSA), hybrid TLS analysis, QKD/BB84 protocol attacks, Chinese national crypto (SM2/SM3/SM4/SM9) implementation flaws, lattice/hashing signature probing, and quantum-vulnerable RSA/ECC asset discovery using liboqs, GmSSL, cloudflare/circl, OQS-OpenSSL, and PQCrypto-Break.

Computed 9367

brucesongs/kali-claw

scada-ics-security

SCADA/ICS security assessment covering industrial control system protocols including Modbus TCP, S7comm (Siemens), DNP3, EtherNet/IP (CIP), OPC UA, BACnet, and GOOSE.

Computed 9367

brucesongs/kali-claw

sdr-rf-attack

Software Defined Radio and RF signal attacks encompass a broad range of offensive techniques targeting wireless communication systems.

Computed 9367

brucesongs/kali-claw

social-engineering

Social engineering is the art of exploiting human psychological weaknesses rather than technical vulnerabilities to execute attacks. Attack vectors encompass Phishing, Pretexting, Baiting, Tailgating, Vishing, and other techniques.

Computed 9367

brucesongs/kali-claw

storage-san-attack

Storage/SAN/NAS/Object storage penetration testing — iSCSI, Fibre Channel, NFSv3/v4, SMB3, S3-compatible APIs, NetApp ONTAP, Dell EMC, Pure Storage, QNAP, Synology, TrueNAS, NDMP backup tape pilfering, and ransomware patterns targeting storage appliances. Distinct from database-attack (which targets RDBMS/NoSQL query protocols) and cloud-native-vuln-research (which focuses on CVE research rather than storage fabric and appliance pentest).

Computed 9367

brucesongs/kali-claw

web-xss

XSS (Cross-Site Scripting) is an attack that injects malicious scripts into trusted websites.

Computed 9367

harumiWeb/xlflow

xlflow

Use when Codex or another AI agent needs to edit, test, debug, or validate Excel VBA workbooks with xlflow. Provides the safe VBA development workflow for xlflow projects, including pull/push, lint, run, test, diff, XlflowUI dialog and file dialog wrapper guidance, headless dialog responses, failure handling, and final reporting rules.

Computed 9267

brucesongs/kali-claw

ai-security

Semantic-layer attack testing against AI systems and LLM-integrated applications.

Computed 9267

brucesongs/kali-claw

bluetooth-rfid-nfc

Near-field wireless penetration testing skills covering Bluetooth Classic device enumeration and exploitation, BLE GATT service attacks against IoT devices, RFID card cloning (MIFARE Classic/DESFire), NFC tag manipulation, and contactless payment probing.

Computed 9267

brucesongs/kali-claw

deception-honeypot

Defensive deception and honeypot deployment covering SSH/Telnet (Cowrie), web (OpenCanary), enterprise (HFish), ICS/SCADA (Conpot), all-in-one (T-Pot), AI-driven deception (Beelzebub), Thinkst Canarytokens (DNS, HTTP, file, AWS API key, SQL), Dionaea multi-protocol honeypot, notification pipelines (Slack/Teams webhooks), false positive tuning, and attacker engagement — including lure design, deployment OPSEC, IOC extraction, and attacker attribution.

Computed 9267

brucesongs/kali-claw

deep-research

Multi-source intelligence gathering through systematic web research — producing thorough, cited reports from diverse sources.

Computed 9267

brucesongs/kali-claw

hypervisor-introspection

Hypervisor introspection (VMI) and virtualization escape attacks — VMware ESXi, Hyper-V, KVM/QEMU, Xen, Proxmox, VirtualBox, LibVMI, DRAKVUF, VENOM CVE-2015-3456, hardware-assisted VT-x/EPT/AMD-V

Computed 9267

brucesongs/kali-claw

identity-provider-attack

Identity Provider (IdP) attack patterns covering OAuth 2.0/OIDC, SAML, JWT, token theft/replay, MFA fatigue, service principal abuse (Azure AD/Entra ID), Okta, Auth0, Keycloak, and modern identity-based attacks.

Computed 9267

brucesongs/kali-claw

password-attack

Password attacks encompass the complete attack chain from hash extraction, hash type identification, dictionary attacks, rule-based attacks, and bruteforcing to online service brute forcing.

Computed 9267

brucesongs/kali-claw

payload-generation

Payload generation covers the creation, encoding, and delivery of shellcode and executable payloads for initial access and command-and-control (C2) communication.

Computed 9267

brucesongs/kali-claw

pentest-reporting

Initialize Dradis for collaborative report authoring and Faraday for vulnerability correlation before testing begins.

Computed 9267

brucesongs/kali-claw

privilege-escalation

Privilege escalation is the process of elevating access from a low-privileged user context (standard user, service account, or limited shell) to root on Linux or SYSTEM/Administrator on Windows.

Computed 9267

brucesongs/kali-claw

terminal-ops

Evidence-first execution workflow for running security commands, inspecting system state, debugging tool failures, and making verified changes. This skill enforces a disciplined approach: inspect before acting, keep changes narrow, and report exact execution state.

Computed 9267

brucesongs/kali-claw

verification-loop

After discovering a potential vulnerability or exploit - Before submitting any finding to a report or bounty platform - When verifying that a remediation or patch is effective - When cross-checking automated scanner results - User says "verify", "confirm", "validate.

Computed 9267

brucesongs/kali-claw

vpn-attack

Virtual Private Networks (VPNs) are a critical component of enterprise network security, providing encrypted tunnels for remote access and site-to-site connectivity.