claudemods

来源encod3d-sec/torch

encod3d-sec/torch 已索引

Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian

查看上游仓库

已索引 索引里有这个仓库的包记录。包数量是历史登记记录,不代表这些包现在仍可用。

仓库

规范名称
Encod3d-Sec/TORCH
GitHub 仓库 ID
1300153697
包记录
56 (历史登记记录,不代表现在仍可用)

发现与队列

首个记录来源
search:topic:claude-skills fork:false
发现于
队列状态
ok
记录的错误次数
0
最近完成的处理
下次检查资格
起具备资格

首个记录来源是队列第一次保存的来源,不是完整的发现历史。错误次数在处理以错误状态结束时增加,成功处理后清零,不是全部尝试次数。「最近完成的处理」是结束时间,不是开始时间。

资格按 计算。它不是排期:采集器每次运行只处理有限数量的来源,具备资格也不保证何时检查。

最近保存的扫描

仓库元数据读取于
扫描状态
complete
扫描保存于
识别器版本
2
续扫记录
没有

扫描记录与队列状态分开:队列状态说明处理进度,扫描记录说明最近一次保存了什么。有续扫记录只表示存有未完成的状态,没有剩余数量。

源文件证据覆盖

已存储的包版本在这个仓库中引用的固定源文件的原始计数。它反映已记录了什么,不代表仓库有多完整。

范围与限制

统计所有已存储版本(来自任何包)中指向本仓库规范名称的不同固定文件链接(仓库、提交、路径)。本仓库所拥有的包的文件,只有被某个版本在这里链接时才会计入。不合并别名,也不会根据当前名称推测历史。

「已知」表示已记录普通文件身份,不表示整个目录或包已被覆盖。不是有效固定文件 URL 的链接不计入。

引用了 56 个固定源文件

  • 56 已知
  • 0 提交中不存在
  • 0 文件列表截断
  • 0 不受支持
  • 0 尚无记录
  • 0 读取失败

按仓库、提交和路径去重;同一路径出现在两个提交中,按两个文件身份计数。不是组件组数。

读取失败的提交 0

尚无记录的文件没有对应的提交读取失败记录。

关联的包 56

按仓库的已验证身份关联。数量是历史登记记录,不是当前可用性。

第 1–20 条,共 56 条结果

  • arsenal技能

    Wiki-first "what do I use" lookup - pick the automated TOOL (wiki/tools/), then the PAYLOAD/technique (wiki/payloads/ + wiki/cheatsheets/), for a surface/service/vuln-class BEFORE hand-rolling or working from memory. Use for "tool for <ser…

  • bb-workflow技能

    Autonomous bug-bounty campaign driver. Runs a full programme end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action…

  • campaign-health技能

    Health check for the bb/pt/ctf workflow driver subsystem - verifies everything is in place so every machine runs the same. Checks vault-content consistency (scripts present, JSON valid, routing wired, all 69 tool pages carry phase:, the to…

  • chrome-devtools-browser技能

    Bring up a REAL, visible, interactive chromium on the Kali VM that the operator logs into (Smart-ID / Mobile-ID / any manual auth or MFA/CAPTCHA), while the agent drives and observes it live through the chrome-devtools MCP (navigate, DOM s…

  • claude-md-improver技能

    OFFLINE FALLBACK for the claude-md-management plugin - prefer that plugin when it is installed. Audit and improve CLAUDE.md files - scan for CLAUDE.md files, evaluate quality against templates, output a report, then make targeted updates. …

  • coverage技能

    Show per-asset vuln-class coverage gaps for the active engagement so nothing in scope is skipped. Use when asked "coverage", "what haven't we tested", "test gaps", "are we thorough", or before calling an engagement done.

  • ctf-box技能

    Boot-to-root methodology for a full machine (THM/HTB/PG/CTF box, "get user.txt+root.txt", "root the box", "foothold to root"). Enforces basic-tool recon (nmap, nc, ffuf, nuclei, dig) before anything custom, wiki-first lookups, and ALWAYS p…

  • ctf-category技能

    CTF challenge router - fingerprint a challenge (file type / prompt / artifacts) into its category (pwn, rev, crypto, forensics, stego, web, osint, hash) and route to the matching wiki page, tools, and first moves. Wiki-first.

  • ctf-workflow技能

    Autonomous CTF / boot-to-root campaign driver. Runs a box end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (S…

  • delegate技能

    Autonomous sub-agent hand-off for a fiddly, fully-specified exploit-compile / escalation RUN - the main agent stays on strategy and the board while a cheap sub-agent runs an exact copy-paste checklist behind a false-root/hostname guardrail…

  • disclosure技能

    Drive responsible disclosure of a proven finding to a CVE. Package the report, find the vendor contact, report privately, coordinate a timeline, request the CVE (vendor CNA / GitHub / MITRE), and publish an advisory. Closes the research lo…

  • evidence技能

    Evidence hygiene before any FIND moves to Completed or enters a report. Cookie redaction, PII black-bar, HAR sanitization, screenshot metadata strip. Run after /triage passes and before final report assembly.

  • fuzz技能

    Adaptive, targeted web fuzzing - deterministic wordlist selection (wl-pick.sh) plus judgment. Picks the right SecLists list per surface (content/vhost/api/params/artifacts) smallest-first, calibrates filters against soft-404s, recurses, es…

  • hunt-ad技能

    Active Directory attack hunting - enumeration to domain dominance. Spray-safe (lockout gate), AS-REP/Kerberoast, ACL + ADCS (ESC1-16), delegation, DCSync, lateral movement. Wiki-first, FIND schema output.

  • hunt-api技能

    API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. OWASP API Top 10. Wiki-first, FIND schema output.

  • hunt-auth技能

    Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /_vti_bin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation. Wiki-first, FIND schema output.

  • hunt-bizlogic技能

    Business-logic flaw hunting - workflow/state bypass, price/quantity tampering, negative/overflow values, coupon/refund abuse, mass assignment, and logic races. The top-paying bug class with no scanner coverage. Wiki-first, FIND schema outp…

  • hunt-burp技能

    Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe), then hand off to the matching vuln-class…

  • hunt-cache技能

    Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking. Wiki-first, FIND schema output.

  • hunt-cicd技能

    CI/CD pipeline attack hunting (GitHub Actions focus) - pwn requests (pull_request_target), script injection, self-hosted runner takeover, cache poisoning, OIDC-to-cloud token theft, poisoned pipeline execution. Wiki-first, FIND schema outp…

已保存的扫描说明 0

没有保存额外的扫描说明。

记录的别名 0

这些名称在上次记录时指向这个仓库。这是记录下来的解析结果,不是实时的 GitHub 检查;本站不会因此合并包或元数据。

没有记录到指向这个仓库的别名。

不支持的市场条目 0

这个仓库的市场清单里、本站暂不支持的条目。它们是原样保存的来源数据,不会被抓取或执行。

没有记录到不支持的条目。