CAT
/
Skills
Skills
MCP
Marketplaces
Digest
Tools
Advertise
yaklang/hack-skills
102 skills
·
91.8k total installs
·
GitHub
npx -y skills add yaklang/hack-skills --agent claude-code
hack
1k
sqli-sql-injection
993
xss-cross-site-scripting
986
code-obfuscation-deobfuscation
979
ssrf-server-side-request-forgery
974
api-sec
964
api-recon-and-docs
963
recon-and-methodology
956
api-auth-and-jwt-abuse
955
android-pentesting-tricks
950
recon-for-sec
949
websocket-security
949
business-logic-vulnerabilities
945
jwt-oauth-token-attacks
944
authbypass-authentication-flaws
943
auth-sec
942
injection-checking
941
idor-broken-object-authorization
939
waf-bypass-techniques
937
api-authorization-and-bola
933
401-403-bypass-techniques
931
csrf-cross-site-request-forgery
927
oauth-oidc-misconfiguration
927
business-logic-vuln
924
cors-cross-origin-misconfiguration
924
path-traversal-lfi
922
traffic-analysis-pcap
921
xxe-xml-external-entity
919
heap-exploitation
917
race-condition
917
cmdi-command-injection
914
open-redirect
914
ssti-server-side-template-injection
914
crlf-injection
913
deserialization-insecure
913
file-access-vuln
913
graphql-and-hidden-parameters
913
http-parameter-pollution
911
insecure-source-code-management
911
request-smuggling
911
web-cache-deception
910
csv-formula-injection
907
format-string-exploitation
907
jndi-injection
907
saml-sso-assertion-attacks
906
kubernetes-pentesting
904
clickjacking
903
expression-language-injection
903
prototype-pollution
903
dependency-confusion
900
kernel-exploitation
900
type-juggling
900
xslt-injection
900
llm-prompt-injection
899
binary-protection-bypass
892
ios-pentesting-tricks
891
http-host-header-attacks
890
active-directory-acl-abuse
888
browser-exploitation-v8
888
subdomain-takeover
884
active-directory-certificate-services
883
active-directory-kerberos-attacks
883
arbitrary-write-to-rce
882
csp-bypass-advanced
882
http2-specific-attacks
881
memory-forensics-volatility
880
symbolic-execution-tools
880
vm-and-bytecode-reverse
880
windows-av-evasion
880
hash-attack-techniques
879
stack-overflow-and-rop
879
anti-debugging-techniques
878
dangling-markup-injection
878
classical-cipher-analysis
875
upload-insecure-files
875
email-header-injection
874
windows-privilege-escalation
874
ai-ml-security
873
mobile-ssl-pinning-bypass
873
dns-rebinding-attacks
872
linux-lateral-movement
872
linux-privilege-escalation
872
network-protocol-attacks
871
smart-contract-vulnerabilities
871
tunneling-and-pivoting
871
prototype-pollution-advanced
870
container-escape-techniques
869
defi-attack-patterns
868
linux-security-bypass
868
steganography-techniques
868
nosql-injection
867
symmetric-cipher-attacks
866
lattice-crypto-attacks
864
windows-lateral-movement
864
rsa-attack-techniques
863
sandbox-escape-techniques
862
ntlm-relay-coercion
855
unauthorized-access-common-services
855
macos-process-injection
850
macos-security-bypass
849
reverse-shell-techniques
835
ghost-bits-cast-attack
617