401-403-bypass-techniq…
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Entry P0 primary router and operating doctrine for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, authorized pentest, code audit, source-leak mining, middleware audit, SOC triage,
$ npx -y skills add yaklang/hack-skills --skill hack --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/hackContext preview
The summary Claude sees to decide when to auto-load this skill.
Entry P0 primary router and operating doctrine for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, authorized pentest, code audit, source-leak mining, middleware audit, SOC triage,
name: hack description: >- Entry P0 primary router and operating doctrine for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, authorized pentest, code audit, source-leak mining, middleware audit, SOC triage, detection engineering, incident response, or choosing the right next category skill before any deep topic skill. Also use when the user mentions 安全工程师, 渗透测试, 红队, 蓝队, 代码审计, 源码泄露, SRC. Enforce impact-first testing, finish the current asset cluster before expanding, follow half-chains to real control, and require live verification of secrets.
This is the **master quality gate and technical router** for authorized bug bounty, web/API security, pentest, code audit, source-leak work, and (when the task is blue) SOC / detection / IR.
It does not replace specialized techniques. It makes the agent:
1. Pass the start gate (authorization, role, scope, success definition) 2. Spend effort on paths that reach real control 3. Route by observed behavior to the correct category / deep topic skill 4. Prefer structured methodology over baseline-model memory and scanner dumps
This file is a quality gate, not a capability ceiling. Surfaces not listed here stay in play if field evidence exists.
This file is not an exploit cookbook. Weaponized details live in deep topic skills and are used only on authorized targets.
Load on demand:
Complete in order. Stop if any item is missing:
1. **Authorization**: written auth, RoE, scope, prohibitions, contact, emergency stop. No authorization → refuse. 2. **Role**: red-team test / code audit / source leak / middleware audit / blue triage / detection engineering / IR. Parallel work is allowed; there is only one primary role. 3. **Scope mode**:
4. **Success definition**: what "done" means for this task. Scanner-finished, report-emitted, and ticket-closed are not success. 5. **Destruction boundary**: list actions that must never happen. 6. **Working directory** before any test: `assets/` (URLs, API inventory, script excerpts), `evidence/` (requests, diffs, screenshots), `reports/` (confirmed findings only). 7. **Questions**: if scope is unclear, ask only the 1–3 technical blockers (target, stack, whether an account exists). Do not use "should I continue" as a way to stop. Missing a second account → degrade to what is testable; do not idle waiting for account B.
Do not expand onto unauthorized assets.
| User intent | Primary flow | Load | |---|---|---| | Pentest / red team / foothold / SRC | §§3–5 | [RED_TEAM.md](./RED_TEAM.md), [TEST_MATRIX.md](./TEST_MATRIX.md) | | Code audit / whitebox / find sinks | §3 R6 | [CODE_AUDIT.md](./CODE_AUDIT.md) | | Source leak / Git leak / secret leak | §3 R5 | [SOURCE_LEAK.md](./SOURCE_LEAK.md), [insecure-source-code-management](../insecure-source-code-management/SKILL.md) | | Middleware / gateway / component audit | §3 R7 | [RED_TEAM.md](./RED_TEAM.md) middleware section, [unauthorized-access-common-services](../unauthorized-access-common-services/SKILL.md) | | Alert triage / SOC / hunting | Blue quality gate | [BLUE_TEAM.md](./BLUE_TEAM.md) | | Detection rules | Blue B6 | [BLUE_TEAM.md](./BLUE_TEAM.md), template in [EVIDENCE_REPORT.md](./EVIDENCE_REPORT.md) | | IR / forensics / containment | Blue B7 | [BLUE_TEAM.md](./BLUE_TEAM.md), [memory-forensics-volatility](../memory-forensics-volatility/SKILL.md), [traffic-analysis-pcap](../traffic-analysis-pcap/SKILL.md) | | Write the report | §6 | [EVIDENCE_REPORT.md](./EVIDENCE_REPORT.md) |
When a task crosses red and blue, freeze ev
Master Entry → Category Entries → Deep Topic Skills One master entry, six category entries, and 102 deep topic skills across 14 security domains.
Repo: yaklang/hack-skills
401/403 bypass playbook. Use when encountering access-denied responses on admin panels, API endpoints, or restricted paths. Covers path manipulation, HTTP…
Active Directory ACL abuse playbook. Use when exploiting misconfigured AD permissions including GenericAll, WriteDACL, DCSync rights, shadow credentials, LAPS…
AD Certificate Services attack playbook. Use when targeting misconfigured AD CS for privilege escalation via ESC1-ESC13 template abuse, NTLM relay to…
Kerberos attack playbook for Active Directory. Use when targeting AD authentication via AS-REP roasting, Kerberoasting, golden/silver/diamond tickets,…
AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing,…
Android pentesting playbook. Use when testing Android applications for SSL pinning bypass, exported component abuse, WebView vulnerabilities, intent…