Karen Rebeca Ortiz ✨
Community@karenrebecag · Cuernavaca, Morelos
I love diving into UI/UX design, building immersive frontend experiences, exploring fullstack architectures, and integrating AI to make nice and useful stuff.
Agent Skills by Karen Rebeca Ortiz ✨
Showing 73 vetted skills indexed across 2 GitHub repositories.
accessibility-wcag
Implements WCAG 2.2 accessibility patterns for ARIA, keyboard navigation, and screen readers.
oauth-attacks
Tests OAuth 2.0 implementations for redirect_uri bypass, CSRF, PKCE, and token leakage vulnerabilities.
offensive-fuzzing
Guides fuzzing campaign setup, execution, and crash triage across binaries, kernels, and parsers.
fast-checking
Applies a rapid offensive security checklist for time-boxed web application assessments.
open-redirect
Tests web applications for open redirect vulnerabilities using bypass techniques and exploitation checklists.
pentest
Runs an authorized purple-team loop that exploits, patches, and re-tests vulnerabilities on owned assets.
security-audit-deep
Orchestrates multi-agent source-code security audits with coverage ledgers and validated findings.
ssrf
Tests web applications for Server-Side Request Forgery vulnerabilities using structured checklists and bypass techniques.
crash-analysis
Analyzes crash dumps and assesses exploitability using WinDbg, GDB, and sanitizers.
offensive-jwt
Tests JWT implementations for algorithm confusion, weak secrets, and header injection vulnerabilities.
offensive-osint
Guides OSINT reconnaissance workflows using curated tools for domains, people, infrastructure, and cryptocurrency.
fuzzing-course
Teaches coverage-guided fuzzing methodology with AFL++, FuzzTest, and Honggfuzz for vulnerability discovery.
security-hardening
Implements input validation, authentication, security headers, and dependency auditing for web applications.
offensive-graphql
Tests GraphQL APIs for vulnerabilities across the full offensive attack lifecycle.
security-audit
Audits an entire codebase for vulnerabilities and generates a prioritized security report.
race-condition
Tests web applications for race condition and TOCTOU vulnerabilities using concurrent request techniques.
file-upload
Tests web application file upload endpoints for validation bypasses and exploitation paths.
osint-methodology
Guides structured OSINT investigations across cryptocurrency, imagery, threat actors, and social media.
offensive-iot
Tests IoT and embedded devices across hardware, firmware, wireless, and cloud attack surfaces.
offensive-reporting
Writes penetration test and red team reports with CVSS scoring, evidence hygiene, and executive summaries.
idor
Tests web applications for IDOR vulnerabilities through object ID manipulation and access control bypass techniques.
cortex-implementation
Implements and migrates conversational agents on the Atom Cortex platform from Flowbuilder flows.
cortex-reference
Answers conceptual and functional questions about the Cortex conversational agent platform.
clop-compress
Compress images, videos, PDFs, and audio files using the Clop CLI on macOS.
Frequently Asked Questions About Karen Rebeca Ortiz ✨
FAQPage SchemaWhat tasks can I perform with karenrebecag's skills?▼
The registry covers authorized red team operations (phishing, Active Directory attacks, privilege escalation, C2 frameworks, cloud and Kubernetes exploitation, wireless/IoT attacks), Webflow site management and Code Component development, GSAP animation engineering, security audits, and spec-driven delivery loops like /discover, /spec, /ship, and /release.
Who are these skills designed for?▼
Primarily penetration testers, red team operators, and purple teams running authorized engagements with written scope, plus frontend engineers building Webflow sites with React Code Components and GSAP animations, and product engineers using Spanish-language spec-driven delivery and incident-management routines.
How do the offensive security skills handle authorization and scope?▼
Skills like offensive-phishing and offensive-social-engineering explicitly require written authorization and defined rules of engagement before execution. The pentest skill restricts targets to those listed in a .pentest-scope.json file and uses manual invocation, ensuring techniques run only against authorized assets.
What tools and frameworks do the security skills reference?▼
Documented tooling includes Cobalt Strike, Sliver, Mythic, Metasploit, BloodHound, mimikatz, impacket, Burp Suite, SQLmap, Frida, AFL++, hashcat, Kismet, HackRF, and Flipper Zero. Techniques map to MITRE ATT&CK technique IDs and CWE classifications throughout the methodology descriptions.
Are these skills open source and what do they cost?▼
The devops-engineer skill declares an MIT license; other skills in the manifest do not state explicit licensing. The skills themselves are prompt-based methodology documents with no stated cost, though referenced third-party tools like Cobalt Strike require separate commercial licenses.