# hack-skills

Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 101 deep topic skills across 14 security domains.

- Tier: Indexed (plain plugin)
- Category: Security
- Page: https://www.flowy.sh/listings/yaklang-hack-skills
- Source: https://github.com/yaklang/hack-skills
- Price: free and open source

## Summary
hack-skills is a Claude Code plugin with 102 hand-picked skills for security work, indexed on Flowy. Install it with the command on its page. It includes 401-403-bypass-techniques, active-directory-acl-abuse, active-directory-certificate-services. Its skills do not fire on their own yet. Request auto-invocation to have Flowy route them as you prompt. Free and open source.

## Install (Claude Code)
```
npx -y skills add yaklang/hack-skills --agent claude-code
```

## Skills
- 401-403-bypass-techniques
- active-directory-acl-abuse
- active-directory-certificate-services
- active-directory-kerberos-attacks
- ai-ml-security
- android-pentesting-tricks
- anti-debugging-techniques
- api-auth-and-jwt-abuse
- api-authorization-and-bola
- api-recon-and-docs
- api-sec
- arbitrary-write-to-rce
- auth-sec
- authbypass-authentication-flaws
- binary-protection-bypass
- browser-exploitation-v8
- business-logic-vuln
- business-logic-vulnerabilities
- classical-cipher-analysis
- clickjacking
- cmdi-command-injection
- code-obfuscation-deobfuscation
- container-escape-techniques
- cors-cross-origin-misconfiguration
- crlf-injection
- csp-bypass-advanced
- csrf-cross-site-request-forgery
- csv-formula-injection
- dangling-markup-injection
- defi-attack-patterns
- dependency-confusion
- deserialization-insecure
- dns-rebinding-attacks
- email-header-injection
- expression-language-injection
- file-access-vuln
- format-string-exploitation
- ghost-bits-cast-attack
- graphql-and-hidden-parameters
- hack
- hash-attack-techniques
- heap-exploitation
- http-host-header-attacks
- http-parameter-pollution
- http2-specific-attacks
- idor-broken-object-authorization
- injection-checking
- insecure-source-code-management
- ios-pentesting-tricks
- jndi-injection
- jwt-oauth-token-attacks
- kernel-exploitation
- kubernetes-pentesting
- lattice-crypto-attacks
- linux-lateral-movement
- linux-privilege-escalation
- linux-security-bypass
- llm-prompt-injection
- macos-process-injection
- macos-security-bypass
- memory-forensics-volatility
- mobile-ssl-pinning-bypass
- network-protocol-attacks
- nosql-injection
- ntlm-relay-coercion
- oauth-oidc-misconfiguration
- open-redirect
- path-traversal-lfi
- prototype-pollution-advanced
- prototype-pollution
- race-condition
- recon-and-methodology
- recon-for-sec
- request-smuggling
- reverse-shell-techniques
- rsa-attack-techniques
- saml-sso-assertion-attacks
- sandbox-escape-techniques
- smart-contract-vulnerabilities
- sqli-sql-injection
- ssrf-server-side-request-forgery
- ssti-server-side-template-injection
- stack-overflow-and-rop
- steganography-techniques
- subdomain-takeover
- symbolic-execution-tools
- symmetric-cipher-attacks
- traffic-analysis-pcap
- tunneling-and-pivoting
- type-juggling
- unauthorized-access-common-services
- upload-insecure-files
- vm-and-bytecode-reverse
- waf-bypass-techniques
- web-cache-deception
- websocket-security
- windows-av-evasion
- windows-lateral-movement
- windows-privilege-escalation
- xslt-injection
- xss-cross-site-scripting
- xxe-xml-external-entity

## FAQ

### What is hack-skills?
Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 101 deep topic skills across 14 security domains.

### How do I install hack-skills?
Run these in Claude Code: npx -y skills add yaklang/hack-skills --agent claude-code. Then prompt normally.

### Does hack-skills auto-invoke its skills?
Not yet. It is indexed on Flowy as a plain plugin. Request auto-invocation on its page and Flowy will route its skills for you as you prompt.

### Is hack-skills free?
Yes. Flowy is free and open source, with nothing gated. You can read every skill in full before you install.
