marcboggs avatar

marcboggs

Community

@marcboggs

1Followers
|
7Public Repos
|
89Published Skills

Comprehensive offensive security skill registry for bug bounty hunting, red-team engagements, and vulnerability research across web, cloud, mobile, and AI targets.

Skills Distribution
DomainCybersecurit...Web Application Vu.. (35%)Red-Team Recon & O.. (20%)Cloud & Infrastruc.. (15%)AI/LLM & API Secur.. (15%)

Agent Skills by marcboggs

Showing 89 vetted skills indexed across 1 GitHub repositories.

marcboggsmarcboggs

hunt-llm-ai

Detect prompt injection, data exfiltration, and agentic AI vulnerabilities in LLM-backed applications.

Community
Intermediate
marcboggsmarcboggs

hunt-rag-vector

Tests RAG pipelines and vector databases for corpus poisoning, cross-tenant IDOR, and embedding-layer leakage.

Community
Advanced
marcboggsmarcboggs

hunt-cors

Tests web applications for exploitable CORS misconfigurations with browser-verified proof-of-concept methodology.

Community
Intermediate
marcboggsmarcboggs

hunt-xss

Guides detection and validation of reflected, stored, and DOM-based XSS vulnerabilities on web targets.

Community
Advanced
marcboggsmarcboggs

meme-coin-audit

Detects rug pulls and token vulnerabilities in EVM and Solana meme coins.

Community
Advanced
marcboggsmarcboggs

hunt-exceptional-conditions

Detect verbose error pages and fail-open behavior by sending malformed input to endpoints.

Community
Intermediate
marcboggsmarcboggs

hunt-csrf

Detects and validates CSRF vulnerabilities in web applications using bug bounty methodology.

Community
Advanced
marcboggsmarcboggs

hunt-dispatch

Loads mode-appropriate offensive security skill sets for the /hunt orchestrator based on target fingerprinting.

Community
Intermediate
marcboggsmarcboggs

hunt-nextjs

Tests Next.js applications for Server Actions abuse, middleware bypass, SSRF, and data leakage vulnerabilities.

Community
Advanced
marcboggsmarcboggs

hunt-captcha-bypass

Tests web applications for six CAPTCHA bypass patterns including field omission, token replay, and missing server-side validation.

Community
Intermediate
marcboggsmarcboggs

ios-redteam-pipeline

Extracts and analyzes iOS IPA binaries for secrets, ATS misconfigurations, and runtime attack surfaces.

Community
Advanced
marcboggsmarcboggs

hunt-ssti

Detects and exploits server-side template injection across Jinja2, Twig, Freemarker, ERB, and other engines.

Community
Intermediate
marcboggsmarcboggs

report-writing

Writes impact-first bug bounty reports for HackerOne, Bugcrowd, Intigriti, and Immunefi with CVSS scoring.

Community
Intermediate
marcboggsmarcboggs

hunt-idor

Detects and exploits IDOR vulnerabilities in APIs using authorization testing methodology from 26 bug bounty reports.

Community
Advanced
marcboggsmarcboggs

hunt-k8s

Tests Kubernetes and Docker infrastructure for misconfigurations, unauthenticated access, and container escape vulnerabilities.

Community
Advanced
marcboggsmarcboggs

hunt-fintech-graphql

Test fintech GraphQL APIs for money-movement, ledger, and authorization vulnerabilities.

Community
Advanced
marcboggsmarcboggs

hunt-cicd

Detect and validate CI/CD pipeline vulnerabilities across Jenkins, GitHub Actions, GitLab CI, and Terraform state.

Community
Advanced
marcboggsmarcboggs

bug-bounty

Guides end-to-end bug bounty workflows from recon through validated vulnerability reporting.

Community
Advanced
marcboggsmarcboggs

hunt-brute-force

Tests authentication endpoints for missing rate limiting, OTP brute force, and user enumeration vulnerabilities.

Community
Advanced
marcboggsmarcboggs

hunt-saml

Tests SAML and SSO implementations for signature wrapping, comment injection, and assertion manipulation vulnerabilities.

Community
Intermediate
marcboggsmarcboggs

hunt-race-condition

Detects race condition and TOCTOU vulnerabilities using parallel-request and HTTP/2 single-packet techniques.

Community
Advanced
marcboggsmarcboggs

mid-engagement-ir-detection

Detects SOC patches, attacker activity, and security-state changes during authorized red-team engagements.

Community
Advanced
marcboggsmarcboggs

hunt-mfa-bypass

Tests MFA and 2FA implementations for seven bypass patterns during authorized security assessments.

Community
Intermediate
marcboggsmarcboggs

recon-scope-triage

Validates asset ownership in ASM and recon output before authorized security testing.

Community
Intermediate

Frequently Asked Questions About marcboggs

FAQPage Schema
What tasks can I perform using marcboggs's skills?▼

You can run full bug bounty engagements: recon and subdomain enumeration, vulnerability hunting across 40+ classes (IDOR, SSRF, XSS, SSTI, JWT, CSRF, race conditions), exploit chaining, finding validation via a 7-Question Gate, and submission-ready report writing for HackerOne, Bugcrowd, Intigriti, and Immunefi.

Who are these skills designed for?▼

Bug bounty hunters, red-team operators, and penetration testers conducting authorized security assessments. The skills cover both WAPT-style testing and external red-team engagements, with dedicated methodology, mindset, and mid-engagement detection skills for operators working against monitored enterprise targets.

How do the hunt and recon skills work in practice?▼

Slash-command entry points orchestrate the workflow: /recon runs subdomain enum and crawling, /hunt dispatches Red Team or WAPT skill sets, /validate and /triage gate findings before reporting, /report generates platform-formatted submissions, and /autopilot chains the full loop with configurable checkpoints.

Do the skills cover AI and LLM security testing?▼

Yes. Dedicated skills cover prompt injection, indirect injection via documents, ASCII smuggling with Unicode tag blocks, tool-use exfiltration, system prompt extraction, and RAG vector-store weaknesses including corpus poisoning and cross-tenant vector-database IDOR against Pinecone, Weaviate, Chroma, Milvus, and Qdrant.

What platforms and tech stacks have dedicated hunting skills?▼

Framework-specific skills exist for Next.js, Spring Boot, Laravel, Node.js, ASP.NET, and SharePoint, plus infrastructure skills for Kubernetes, AWS/Azure/GCP IAM, vCenter, enterprise VPN appliances, Okta, and Microsoft 365/Entra. Mobile pipelines cover Android APK and iOS IPA red-team analysis.