Karen Rebeca Ortiz ✨ avatar

Karen Rebeca Ortiz ✨

Community

@karenrebecag · Cuernavaca, Morelos

3Followers
|
58Public Repos
|
73Published Skills

I love diving into UI/UX design, building immersive frontend experiences, exploring fullstack architectures, and integrating AI to make nice and useful stuff.

Skills Distribution
DomainCybersecurit...Offensive Security.. (55%)Webflow & Frontend.. (20%)Application Securi.. (10%)Spec-Driven Delive.. (10%)

Agent Skills by Karen Rebeca Ortiz ✨

Showing 73 vetted skills indexed across 2 GitHub repositories.

karenrebecagkarenrebecag

accessibility-wcag

Implements WCAG 2.2 accessibility patterns for ARIA, keyboard navigation, and screen readers.

Community
Intermediate
karenrebecagkarenrebecag

oauth-attacks

Tests OAuth 2.0 implementations for redirect_uri bypass, CSRF, PKCE, and token leakage vulnerabilities.

Community
Intermediate
karenrebecagkarenrebecag

offensive-fuzzing

Guides fuzzing campaign setup, execution, and crash triage across binaries, kernels, and parsers.

Community
Advanced
karenrebecagkarenrebecag

fast-checking

Applies a rapid offensive security checklist for time-boxed web application assessments.

Community
Intermediate
karenrebecagkarenrebecag

open-redirect

Tests web applications for open redirect vulnerabilities using bypass techniques and exploitation checklists.

Community
Intermediate
karenrebecagkarenrebecag

pentest

Runs an authorized purple-team loop that exploits, patches, and re-tests vulnerabilities on owned assets.

Community
Advanced
karenrebecagkarenrebecag

security-audit-deep

Orchestrates multi-agent source-code security audits with coverage ledgers and validated findings.

Community
Advanced
karenrebecagkarenrebecag

ssrf

Tests web applications for Server-Side Request Forgery vulnerabilities using structured checklists and bypass techniques.

Community
Advanced
karenrebecagkarenrebecag

crash-analysis

Analyzes crash dumps and assesses exploitability using WinDbg, GDB, and sanitizers.

Community
Advanced
karenrebecagkarenrebecag

offensive-jwt

Tests JWT implementations for algorithm confusion, weak secrets, and header injection vulnerabilities.

Community
Advanced
karenrebecagkarenrebecag

offensive-osint

Guides OSINT reconnaissance workflows using curated tools for domains, people, infrastructure, and cryptocurrency.

Community
Intermediate
karenrebecagkarenrebecag

fuzzing-course

Teaches coverage-guided fuzzing methodology with AFL++, FuzzTest, and Honggfuzz for vulnerability discovery.

Community
Advanced
karenrebecagkarenrebecag

security-hardening

Implements input validation, authentication, security headers, and dependency auditing for web applications.

Community
Intermediate
karenrebecagkarenrebecag

offensive-graphql

Tests GraphQL APIs for vulnerabilities across the full offensive attack lifecycle.

Community
Advanced
karenrebecagkarenrebecag

security-audit

Audits an entire codebase for vulnerabilities and generates a prioritized security report.

Community
Advanced
karenrebecagkarenrebecag

race-condition

Tests web applications for race condition and TOCTOU vulnerabilities using concurrent request techniques.

Community
Advanced
karenrebecagkarenrebecag

file-upload

Tests web application file upload endpoints for validation bypasses and exploitation paths.

Community
Intermediate
karenrebecagkarenrebecag

osint-methodology

Guides structured OSINT investigations across cryptocurrency, imagery, threat actors, and social media.

Community
Advanced
karenrebecagkarenrebecag

offensive-iot

Tests IoT and embedded devices across hardware, firmware, wireless, and cloud attack surfaces.

Community
Advanced
karenrebecagkarenrebecag

offensive-reporting

Writes penetration test and red team reports with CVSS scoring, evidence hygiene, and executive summaries.

Community
Intermediate
karenrebecagkarenrebecag

idor

Tests web applications for IDOR vulnerabilities through object ID manipulation and access control bypass techniques.

Community
Advanced
karenrebecagkarenrebecag

cortex-implementation

Implements and migrates conversational agents on the Atom Cortex platform from Flowbuilder flows.

Community
Advanced
karenrebecagkarenrebecag

cortex-reference

Answers conceptual and functional questions about the Cortex conversational agent platform.

Community
Intermediate
karenrebecagkarenrebecag

clop-compress

Compress images, videos, PDFs, and audio files using the Clop CLI on macOS.

Community
Intermediate

Frequently Asked Questions About Karen Rebeca Ortiz ✨

FAQPage Schema
What tasks can I perform with karenrebecag's skills?▼

The registry covers authorized red team operations (phishing, Active Directory attacks, privilege escalation, C2 frameworks, cloud and Kubernetes exploitation, wireless/IoT attacks), Webflow site management and Code Component development, GSAP animation engineering, security audits, and spec-driven delivery loops like /discover, /spec, /ship, and /release.

Who are these skills designed for?▼

Primarily penetration testers, red team operators, and purple teams running authorized engagements with written scope, plus frontend engineers building Webflow sites with React Code Components and GSAP animations, and product engineers using Spanish-language spec-driven delivery and incident-management routines.

How do the offensive security skills handle authorization and scope?▼

Skills like offensive-phishing and offensive-social-engineering explicitly require written authorization and defined rules of engagement before execution. The pentest skill restricts targets to those listed in a .pentest-scope.json file and uses manual invocation, ensuring techniques run only against authorized assets.

What tools and frameworks do the security skills reference?▼

Documented tooling includes Cobalt Strike, Sliver, Mythic, Metasploit, BloodHound, mimikatz, impacket, Burp Suite, SQLmap, Frida, AFL++, hashcat, Kismet, HackRF, and Flipper Zero. Techniques map to MITRE ATT&CK technique IDs and CWE classifications throughout the methodology descriptions.

Are these skills open source and what do they cost?▼

The devops-engineer skill declares an MIT license; other skills in the manifest do not state explicit licensing. The skills themselves are prompt-based methodology documents with no stated cost, though referenced third-party tools like Cobalt Strike require separate commercial licenses.