claudemods

Sourcesencod3d-sec/torch

encod3d-sec/torch Indexed

Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian

Open upstream repository

Indexed The index holds package records for this repository. The package count is historical registry records; it does not mean those packages are available now.

Repository

Canonical name
Encod3d-Sec/TORCH
GitHub repository ID
1300153697
Package records
56 (historical registry records, not current availability)

Discovery and queue

First recorded source
search:topic:claude-skills fork:false
Discovered
Queue state
ok
Recorded errors
0
Last settled processing
Next-check eligibility
Eligible from

The first recorded source is what the queue stored first, not the full discovery history. The error count increases when processing ends in the error state and resets after a successful settlement; it is not a count of all attempts. “Last settled processing” is when it finished, not when it started.

Eligibility is calculated as of . It is not a schedule: each collector run handles only a limited number of sources, and being eligible does not promise when a check happens.

Last saved scan

Repository metadata read
Scan status
complete
Scan saved
Extractor version
2
Continuation record
None

The scan record is separate from the queue state: the queue state shows processing progress, the scan record shows what was last saved. A continuation record only means unfinished state is stored; it has no remaining count.

Source-file evidence coverage

Raw counts of the pinned source files that stored package versions reference in this repository. They show what has been recorded, not how complete the repository is.

Scope and limits

Counts distinct pinned file links (repository, commit, path) across all stored versions, from any package, that name exactly this repository's canonical name. Files of packages owned by this repository are not counted unless some version links to them here. Alias names are not merged and no history is guessed from a current name.

“Known” means a regular-file identity is recorded. It does not mean a whole directory or package is covered. Links that are not valid pinned file URLs are not counted.

56 pinned source files referenced

  • 56 known
  • 0 absent at commit
  • 0 file listing truncated
  • 0 unsupported
  • 0 not recorded
  • 0 read failed

Deduplicated by repository, commit and path; the same path at two commits counts as two file identities. These are not component-group counts.

Failed source-commit reads 0

No source commit has a stored failed read for files that are still unrecorded.

Linked packages 56

Linked by verified repository identity. The count is historical registry records, not current availability.

Showing 1–20 of 56 results

  • arsenalSkill

    Wiki-first "what do I use" lookup - pick the automated TOOL (wiki/tools/), then the PAYLOAD/technique (wiki/payloads/ + wiki/cheatsheets/), for a surface/service/vuln-class BEFORE hand-rolling or working from memory. Use for "tool for <ser…

  • bb-workflowSkill

    Autonomous bug-bounty campaign driver. Runs a full programme end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action…

  • campaign-healthSkill

    Health check for the bb/pt/ctf workflow driver subsystem - verifies everything is in place so every machine runs the same. Checks vault-content consistency (scripts present, JSON valid, routing wired, all 69 tool pages carry phase:, the to…

  • chrome-devtools-browserSkill

    Bring up a REAL, visible, interactive chromium on the Kali VM that the operator logs into (Smart-ID / Mobile-ID / any manual auth or MFA/CAPTCHA), while the agent drives and observes it live through the chrome-devtools MCP (navigate, DOM s…

  • claude-md-improverSkill

    OFFLINE FALLBACK for the claude-md-management plugin - prefer that plugin when it is installed. Audit and improve CLAUDE.md files - scan for CLAUDE.md files, evaluate quality against templates, output a report, then make targeted updates. …

  • coverageSkill

    Show per-asset vuln-class coverage gaps for the active engagement so nothing in scope is skipped. Use when asked "coverage", "what haven't we tested", "test gaps", "are we thorough", or before calling an engagement done.

  • ctf-boxSkill

    Boot-to-root methodology for a full machine (THM/HTB/PG/CTF box, "get user.txt+root.txt", "root the box", "foothold to root"). Enforces basic-tool recon (nmap, nc, ffuf, nuclei, dig) before anything custom, wiki-first lookups, and ALWAYS p…

  • ctf-categorySkill

    CTF challenge router - fingerprint a challenge (file type / prompt / artifacts) into its category (pwn, rev, crypto, forensics, stego, web, osint, hash) and route to the matching wiki page, tools, and first moves. Wiki-first.

  • ctf-workflowSkill

    Autonomous CTF / boot-to-root campaign driver. Runs a box end to end with no operator approvals - the deterministic driver (scripts/campaign.py) owns pass state, generates the killchain board from recon, and prints the exact next action (S…

  • delegateSkill

    Autonomous sub-agent hand-off for a fiddly, fully-specified exploit-compile / escalation RUN - the main agent stays on strategy and the board while a cheap sub-agent runs an exact copy-paste checklist behind a false-root/hostname guardrail…

  • disclosureSkill

    Drive responsible disclosure of a proven finding to a CVE. Package the report, find the vendor contact, report privately, coordinate a timeline, request the CVE (vendor CNA / GitHub / MITRE), and publish an advisory. Closes the research lo…

  • evidenceSkill

    Evidence hygiene before any FIND moves to Completed or enters a report. Cookie redaction, PII black-bar, HAR sanitization, screenshot metadata strip. Run after /triage passes and before final report assembly.

  • fuzzSkill

    Adaptive, targeted web fuzzing - deterministic wordlist selection (wl-pick.sh) plus judgment. Picks the right SecLists list per surface (content/vhost/api/params/artifacts) smallest-first, calibrates filters against soft-404s, recurses, es…

  • hunt-adSkill

    Active Directory attack hunting - enumeration to domain dominance. Spray-safe (lockout gate), AS-REP/Kerberoast, ACL + ADCS (ESC1-16), delegation, DCSync, lateral movement. Wiki-first, FIND schema output.

  • hunt-apiSkill

    API attack hunting (REST / GraphQL / gRPC) - BOLA/IDOR, BFLA, mass assignment, excessive data exposure, auth/JWT, introspection + batching, rate-limit abuse. OWASP API Top 10. Wiki-first, FIND schema output.

  • hunt-authSkill

    Auth bypass and ATO hunting - legacy protocol matrix (XMLRPC, SharePoint /_vti_bin/, EWS, Citrix, etc.), JWT manipulation, password reset poisoning, SAML auth bypass, session fixation. Wiki-first, FIND schema output.

  • hunt-bizlogicSkill

    Business-logic flaw hunting - workflow/state bypass, price/quantity tampering, negative/overflow values, coupon/refund abuse, mass assignment, and logic races. The top-paying bug class with no scanner coverage. Wiki-first, FIND schema outp…

  • hunt-burpSkill

    Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe), then hand off to the matching vuln-class…

  • hunt-cacheSkill

    Web cache poisoning + cache deception hunting - unkeyed input poisoning, cache-key analysis, path-confusion deception, header/parameter cloaking. Wiki-first, FIND schema output.

  • hunt-cicdSkill

    CI/CD pipeline attack hunting (GitHub Actions focus) - pwn requests (pull_request_target), script injection, self-hosted runner takeover, cache poisoning, OIDC-to-cloud token theft, poisoned pipeline execution. Wiki-first, FIND schema outp…

Saved scan notes 0

No additional scan notes are stored.

Recorded aliases 0

When last recorded, these names pointed to this repository. This is a recorded resolution, not a live GitHub check; packages and metadata are never merged because of it.

No aliases pointing to this repository are recorded.

Unsupported marketplace entries 0

Entries in this repository's marketplace that this registry does not support yet. They are preserved source data and are never fetched or executed.

No unsupported entries are recorded.