Wyl-cmd avatar

Wyl-cmd

Community

@Wyl-cmd

10Followers
|
24Public Repos
|
83Published Skills

Wyl-cmd maintains 152 offensive security skills covering bug bounty hunting, red-team recon, web/API exploitation, and vulnerability reporting for authorized testing.

Skills Distribution
DomainCybersecurit...Web & API Vulnerab.. (40%)Reconnaissance & O.. (25%)Red-Team Infrastru.. (15%)AI/LLM & Emerging .. (10%)

Agent Skills by Wyl-cmd

Showing 83 vetted skills indexed across 1 GitHub repositories.

Wyl-cmdWyl-cmd
6

gen-docs

Update CLI user documentation from git commits, staged changes, and changelogs.

Community
Intermediate
Wyl-cmdWyl-cmd
6

gen-rust

Ports Python code changes to Rust implementations while synchronizing tests and E2E verification.

Community
Advanced
Wyl-cmdWyl-cmd
6

release

Automates the version bump and release workflow for Kimi Code CLI packages.

Community
Intermediate
Wyl-cmdWyl-cmd
6

pull-request

Creates and submits a GitHub pull request using the gh CLI.

Community
Basic
Wyl-cmdWyl-cmd
6

gen-changelog

Generate changelog entries from git branch changes and sync them to documentation sites.

Community
Intermediate
Wyl-cmdWyl-cmd
6

codex-worker

Spawn and manage parallel Codex CLI agents in tmux sessions with isolated git worktrees.

Community
Intermediate
Wyl-cmdWyl-cmd
6

worktree-status

Audit git worktrees for dirty state and merge status before cleanup.

Community
Intermediate
Wyl-cmdWyl-cmd
6

translate-docs

Translate and synchronize bilingual Chinese-English documentation pages and changelogs.

Community
Basic
Wyl-cmdWyl-cmd
6

file-access-vuln

Routes file access and upload testing workflows to path traversal or upload vulnerability skills.

Community
Basic
Wyl-cmdWyl-cmd
6

hunt-llm-ai

Test LLM and agentic AI applications for prompt injection, exfiltration, and cross-tenant data leaks.

Community
Advanced
Wyl-cmdWyl-cmd
6

hunt-write-gap

Tests API endpoints for unauthorized write access when read access is properly protected.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-xss

Detect and validate reflected, stored, and DOM-based XSS vulnerabilities in web applications.

Community
Advanced
Wyl-cmdWyl-cmd
6

meme-coin-audit

Detect rug pulls and audit token contracts on EVM and Solana chains.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-csrf

Detects and validates CSRF vulnerabilities in web applications using browser-accurate exploitation models.

Community
Advanced
Wyl-cmdWyl-cmd
6

hunt-dispatch

Fingerprints targets and loads the matching red team or WAPT skill set for /hunt.

Community
Advanced
Wyl-cmdWyl-cmd
6

cross-wave-delta-analysis

Compare recon wave outputs to classify new, regressed, and persistent findings.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-mcp-security

Tests Model Context Protocol servers for tool access control, injection, and output poisoning vulnerabilities.

Community
Intermediate
Wyl-cmdWyl-cmd
6

auto-vuln-hunt

Automates reconnaissance, vulnerability scanning, and PoC verification against a target URL.

Community
Advanced
Wyl-cmdWyl-cmd
6

report-writing

Writes impact-first bug bounty reports for HackerOne, Bugcrowd, Intigriti, and Immunefi.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-idor

Detects IDOR vulnerabilities in APIs and web applications using authorization testing methodology.

Community
Advanced
Wyl-cmdWyl-cmd
6

ops-proxyns

Routes all process traffic through Tor using Linux network namespaces for pentest OPSEC.

Community
Intermediate
Wyl-cmdWyl-cmd
6

bug-bounty

Orchestrates bug bounty hunting from recon through validated vulnerability reporting.

Community
Advanced
Wyl-cmdWyl-cmd
6

github-secret-hunting

Detect leaked API keys, tokens, and credentials in public GitHub repositories.

Community
Intermediate
Wyl-cmdWyl-cmd
6

hunt-saml

Detects and exploits SAML/SSO vulnerabilities including XML Signature Wrapping, signature stripping, and parser differentials.

Community
Advanced

Frequently Asked Questions About Wyl-cmd

FAQPage Schema
What tasks can I perform using Wyl-cmd's skills?▼

You can run full bug bounty pipelines: recon and asset discovery, hunting 30+ vulnerability classes (XSS, SSRF, IDOR, SQLi, race conditions, ATO chains), AI/LLM prompt-injection testing, cloud and Kubernetes misconfiguration checks, and CVSS-scored report writing for HackerOne, Bugcrowd, Intigriti, and Immunefi.

Who are these skills designed for?▼

They target bug bounty hunters, penetration testers, and red-team operators conducting authorized security assessments. Skills like redteam-mindset, pentest-playbook, and bug-bounty orchestrator assume familiarity with Burp Suite, curl, nmap, and standard web exploitation methodology.

What are the runtime prerequisites and dependencies?▼

Most skills require Linux with curl, python3, nmap, masscan, subfinder, httpx, and nuclei. Specialized skills add playwright, ffuf, dnsx, shodan CLI, awscli, or gowitness. The ops-proxyns skill routes all traffic through Tor via Linux network namespaces before engagement start.

Are Wyl-cmd's skills open source and what do they cost?▼

The majority of skills carry an MIT license by author uphiago and are free to use. They are distributed as skill manifests for the KXNS/Kimi Code CLI environment, with no stated commercial licensing or usage fees in the manifest.

Do these skills cover AI and LLM security testing?▼

Yes. Dedicated skills cover prompt injection, indirect injection via documents, ASCII smuggling, tool-use exfiltration, system-prompt extraction, MCP vulnerabilities, and OWASP Agentic AI categories ASI01-ASI10, targeting chatbots, RAG pipelines, and agentic copilots.