K. Madhura Nadh
Community@mccleod1290
K. Madhura Nadh maintains a 52-skill registry spanning offensive web security testing, bug bounty reconnaissance, and document/design artifact generation.
Agent Skills by K. Madhura Nadh
Showing 51 vetted skills indexed across 1 GitHub repositories.
caido-mode
Controls Caido via SDK CLI to search, edit, replay, and fuzz HTTP traffic.
theme-factory
Applies curated color and font themes to slides, documents, and HTML artifacts.
doc-coauthoring
Guides collaborative document creation through context gathering, iterative drafting, and reader testing.
claude-api
Build, debug, and migrate applications using the Claude API and Anthropic SDKs.
xlsx
Create, edit, and validate Excel spreadsheets with formulas using openpyxl and pandas.
Extract, merge, split, create, and fill PDF documents using Python libraries and command-line tools.
algorithmic-art
Create generative art with p5.js using seeded randomness and interactive parameter controls.
internal-comms
Write internal communications like 3P updates, newsletters, and FAQs using company formats.
skill-creator
Create, evaluate, and iteratively improve Claude skills with benchmarked test runs.
canvas-design
Create original visual art and design philosophies as PNG and PDF documents.
pptx
Create, edit, and validate PowerPoint .pptx presentations via XML manipulation and pptxgenjs.
slack-gif-creator
Create animated GIFs optimized for Slack emoji and message requirements using PIL.
webapp-testing
Automate browser testing of local web applications using Python Playwright scripts.
frontend-design
Generate distinctive production-grade frontend interfaces with cohesive aesthetic direction and polished code.
mcp-builder
Guides building and evaluating MCP servers in Python or TypeScript.
brand-guidelines
Applies Anthropic brand colors and typography to documents and visual artifacts.
docx
Create, edit, and validate Word .docx documents using docx-js and OOXML manipulation.
web-artifacts-builder
Builds and bundles React, Tailwind, and shadcn/ui projects into single-file HTML artifacts.
offensive-jwt
Tests JWT implementations for algorithm confusion, weak secrets, and header injection vulnerabilities.
ssrf
Tests web applications for Server-Side Request Forgery using a structured checklist of discovery, bypass, and escalation techniques.
fingerprint-web-server
Fingerprint web servers via raw-socket HTTP probes per OWASP WSTG-INFO-02.
hypothesis-generator
Generate invariant-based vulnerability hypotheses from mapped web and API attack surface.
cookie-flags-analysis
Analyze Set-Cookie flags and cookie types on in-scope URLs for security leads.
csp-analysis
Analyze Content-Security-Policy headers and meta tags to flag weak directives on authorized targets.
Frequently Asked Questions About K. Madhura Nadh
FAQPage SchemaWhat tasks can I perform with mccleod1290's security skills?▼
You can run authorized web penetration tests covering SSRF, XSS, IDOR/BOLA, JWT attacks, OAuth/OIDC flaws, open redirects, HTTP parameter pollution, 403 bypass, and WAF evasion. Supporting skills handle recon (crawling, spidering, content discovery, search-engine dorking), threat modeling (STRIDE, attack vectors), and pre-submission finding validation.
Who are these skills designed for?▼
Bug bounty hunters, penetration testers, and security engineers conducting authorized web application assessments. Skills like bb-validator, hail-mary, and cartographer assume familiarity with HTTP proxies (Caido, Burp, gori), OWASP WSTG methodology, and rules of engagement for in-scope targets.
How do the reconnaissance and testing skills work together in practice?▼
A typical flow starts with fingerprint-web-server, content-discovery, crawl, or spider for mapping, then cartographer and entry-point-mapping inventory the attack surface. Hypothesis-generator and intelligence-driven characterize endpoints before bug-class skills (ssrf, xss, idor) execute, and bb-validator gates findings before reporting.
Are these skills free and open source?▼
Licensing varies per skill. Document skills (xlsx, docx, pptx, pdf) are proprietary with terms in LICENSE.txt, while most security and design skills reference complete terms in their own LICENSE.txt files. Several security skills carry no explicit license field, so review each skill folder before redistribution.
What prerequisites and dependencies do the security skills require?▼
Many skills expect specific local tooling: Caido with PAT authentication for caido-mode, gori on 127.0.0.1:8070, pinchtab's Chrome control plane on :9867, Go-based scanners (ffuf, feroxbuster, gobuster, hakrawler), and Playwright for webapp-testing. All offensive skills require an authorized, in-scope target.