QuanNGo avatar

QuanNGo

Community

@hhjkjkjk

0Followers
|
6Public Repos
|
38Published Skills

QuanNGo provides offensive security skills for bug bounty hunting, red-team engagements, web3 audits, and vulnerability reporting across web, cloud, and identity attack surfaces.

Skills Distribution
DomainCybersecurit...Web Application Vu.. (35%)Red-Team Recon & O.. (20%)Cloud & Identity A.. (15%)Bug Bounty Reporti.. (15%)

Agent Skills by QuanNGo

Showing 38 vetted skills indexed across 1 GitHub repositories.

hhjkjkjkhhjkjkjk

hunt-llm-ai

Detect prompt injection, data exfiltration, and tool-abuse vulnerabilities in LLM-powered features.

Community
Intermediate
hhjkjkjkhhjkjkjk

hunt-api-misconfig

Detect API misconfigurations including mass assignment, JWT flaws, prototype pollution, CORS, and OData bypasses.

Community
Advanced
hhjkjkjkhhjkjkjk

hunt-xss

Detect and validate reflected, stored, and DOM-based XSS vulnerabilities on web targets.

Community
Advanced
hhjkjkjkhhjkjkjk

meme-coin-audit

Detects rug pull vectors and authority risks in EVM and Solana token contracts.

Community
Advanced
hhjkjkjkhhjkjkjk

hunt-csrf

Detects and validates CSRF vulnerabilities across web applications using bug bounty methodology.

Community
Advanced
hhjkjkjkhhjkjkjk

hunt-dispatch

Loads mode-specific offensive security skill sets for authorized red team and web application penetration testing engagements.

Community
Intermediate
hhjkjkjkhhjkjkjk

hunt-ssti

Detects and exploits server-side template injection across Jinja2, Twig, Freemarker, ERB, and other engines.

Community
Intermediate
hhjkjkjkhhjkjkjk

report-writing

Generates platform-specific bug bounty report templates with CVSS scoring and severity guidance.

Community
Intermediate
hhjkjkjkhhjkjkjk

hunt-idor

Detects IDOR vulnerabilities in APIs and web applications using two-account authorization testing.

Community
Advanced
hhjkjkjkhhjkjkjk

hunt-race-condition

Detects race condition vulnerabilities using parallel request attacks and HTTP/2 single-packet techniques.

Community
Advanced
hhjkjkjkhhjkjkjk

mid-engagement-ir-detection

Detects SOC patches, attacker activity, and security-state changes during authorized red-team engagements.

Community
Intermediate
hhjkjkjkhhjkjkjk

hunt-xxe

Detects and exploits XXE vulnerabilities across XML endpoints, file uploads, and SAML services.

Community
Advanced
hhjkjkjkhhjkjkjk

bugcrowd-reporting

Guides Bugcrowd submissions with VRT mapping, severity overrides, and OOS rebuttals.

Community
Intermediate
hhjkjkjkhhjkjkjk

hunt-subdomain

Detect and verify subdomain takeover vulnerabilities across cloud and SaaS provider fingerprints.

Community
Advanced
hhjkjkjkhhjkjkjk

redteam-report-template

Generates client-facing red-team engagement reports in a six-section finding format with DOCX export.

Community
Intermediate
hhjkjkjkhhjkjkjk

supply-chain-attack-recon

Maps external software supply-chain attack surface across GitHub orgs, package registries, and CI/CD pipelines.

Community
Advanced
hhjkjkjkhhjkjkjk

hunt-http-smuggling

Detect and validate HTTP request smuggling vulnerabilities across proxy and origin server stacks.

Community
Intermediate
hhjkjkjkhhjkjkjk

hunt-business-logic

Detects business logic vulnerabilities in payment, verification, and checkout flows using bug bounty methodologies.

Community
Advanced
hhjkjkjkhhjkjkjk

hunt-aspnet

Detect ASP.NET ViewState deserialization, machineKey, and disclosure vulnerabilities in authorized engagements.

Community
Advanced
hhjkjkjkhhjkjkjk

hunt-rce

Detect and validate remote code execution vulnerabilities during bug bounty hunting.

Community
Advanced
hhjkjkjkhhjkjkjk

hunt-sharepoint

Enumerate and assess on-prem SharePoint Server farms for anonymous endpoints and known CVE preconditions.

Community
Advanced
hhjkjkjkhhjkjkjk

bb-methodology

Orchestrates bug bounty hunting sessions using a 5-phase workflow and critical thinking framework.

Community
Advanced
hhjkjkjkhhjkjkjk

redteam-mindset

Enforces persistent testing discipline and scope decisions for authorized red-team engagements.

Community
Advanced
hhjkjkjkhhjkjkjk

offensive-osint

Provides probe paths, regexes, dorks, and scoring rubrics for authorized external reconnaissance.

Community
Advanced

Frequently Asked Questions About QuanNGo

FAQPage Schema
What tasks can I accomplish with QuanNGo's skills?▼

You can run full bug bounty engagements: recon and subdomain enumeration, vulnerability hunting across 20+ classes (IDOR, SSRF, XSS, SSTI, XXE, CSRF, OAuth, SAML, HTTP smuggling, cache poisoning), LLM/AI security testing, cloud IAM privilege escalation, smart contract audits, and CVSS-scored report writing for HackerOne, Bugcrowd, and Immunefi.

Who are these skills designed for?▼

Bug bounty hunters, red-team operators, and penetration testers running authorized engagements. Dedicated skills cover external red-team mindset and client deliverables, while hunt-* skills serve WAPT and bounty hunters targeting specific vulnerability classes with patterns built from hundreds of disclosed public reports.

How do the hunting skills work in practice?▼

Start with bb-methodology or bug-bounty to fingerprint the target and plan phases; hunt-dispatch loads the right skill set for redteam or WAPT mode. Each hunt-* skill provides detection probes, bypass tables, and validation gates. Finish with triage-validation, evidence-hygiene, and report-writing before submission.

What prerequisites and targets do these skills assume?▼

Skills assume authorized targets: bug bounty scopes or signed red-team engagements. They reference standard operator tooling such as Burp Suite extensions, subfinder, httpx, ffuf, jadx, and Frida, plus familiarity with Burp Repeater, JWT decoding, and cloud CLIs for AWS, Azure, and GCP IAM enumeration.

Do the skills cover AI and blockchain security testing?▼

Yes. hunt-llm-ai covers prompt injection, indirect injection, ASCII smuggling, tool-use exfiltration, and the ASI01-ASI10 agentic framework. web3-audit covers 10 DeFi bug classes with Foundry PoC templates, and meme-coin-audit handles Solana SPL token analysis, Token-2022 risks, and rug-pull detection.