Black-box binary analysis with Ghidra/IDA/Binary Ninja for in-scope closed-source targets. Use when performing defensive security research, vulnerability analysis, or coordinated…
Mobile (Android + iOS) application penetration testing methodology. Covers static analysis (apktool/jadx for Android, class-dump/Hopper/IDA for iOS), dynamic instrumentation with…
Search, score, scan, and import agent skills from GitHub repositories that contain SKILL.md, CLAUDE.md, .cursorrules, and similar agent skill files.
Malware analizi — triage, static analiz, dynamic sandbox, IOC extract, YARA imza yazimi advisory. Triggers on malware analiz, malware triage, sandbox, Cuckoo, IDA, Ghidra, dynamic…
Observe suspicious content in a disposable, instrumented environment. Use when execution, process ancestry, file changes, persistence, network behavior, configuration decryption,…
Analyze a suspicious artifact for capabilities without executing it. Use for binaries, apps, packages, archives, scripts, libraries, extensions, firmware, or embedded payloads…
Deploy and operate CAPEv2 sandbox for automated malware analysis with behavioral monitoring, payload extraction,
Performs interactive dynamic malware analysis using the ANY.RUN cloud sandbox to observe real-time execution
Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers,
Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection
Enrich malware file hashes using the VirusTotal API to retrieve detection rates, behavioral analysis, YARA matches,
Malware IOC extraction is the process of analyzing malicious software to identify actionable indicators of compromise
Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives
Performs rapid malware triage and classification using YARA rules to match file patterns, strings, byte sequences,
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware
Executes a structured ransomware incident response from initial detection through containment, forensic analysis,
Plans and facilitates tabletop exercises simulating ransomware incidents to test organizational readiness, decision-making,
Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file
Use YARA pattern-matching rules to hunt for malware, suspicious files, and indicators of compromise across filesystems
Develop precise YARA rules for malware detection by identifying unique byte patterns, strings, and behavioral
Windows persistence mechanism scanner. Scans all autorun vectors: Registry Run/RunOnce keys (T1547.001), Startup folders (T1547.004), Scheduled Tasks (T1053.005), and WMI Event…
Banking-App-Malware (Anubis, Cerberus, BRATA): Trojaner uebernimmt App und pushTAN, Overlay-Attacke. Forensische Hinweise: ungewoehnliche App-Berechtigungen, beobachtete SMS.
Security-first wrapper for installing agent skills. Scans for malware, prompt injection, and suspicious patterns before installation.
Scan a project or machine for the PolinRider DPRK/Lazarus supply-chain malware (March–April 2026 npm + VS Code campaign).
Proje kapanışında lessons learned oturumu, sprint sonu retrospektifi veya incident sonrası postmortem kolaylaştırır.
Comprehensive techniques for capturing, analyzing, and documenting network protocols for security research, interoperability, and debugging.
Rakiplerin içeriklerini (Instagram, TikTok) ve reklam stratejilerini (Meta Ads vb.) analiz ederek içerik boşluklarını (content gap) bulmaya yarayan araştırma motoru.
Handle the first hour of a suspected ransomware or malware infection calmly and correctly — contain it, preserve options, and avoid the moves that make it worse.
Prüft Ransomware-Entscheidungen und Grenzen von Zahlungen im Nis2 Cybersecurity Compliance.
Meta-Skill für die komplette Roblox-Spieleentwicklung mit Rojo — der Einstiegspunkt, der die drei Spezialskills `/rojo` (Filesystem→Studio-Sync, Projekt-Setup), `/rbx-stu — from…
Bedienung von Roblox Studio für die Spieleentwicklung — der visuelle Editor, in dem die 3D-Szene gebaut, getestet und veröffentlicht wird.
Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment
Detailed reverse-engineering pack for binaries, loaders, anti-analysis, deobfuscation, and exploitability clues.
Statically scan a public GitHub repo for supply-chain malware BEFORE an agent installs or runs it (a dependency, a Claude/MCP skill, an MCP server).
Report suspicious or malicious URLs discovered during web exploration. Trigger proactively when: encountering phishing, malware, scam sites, suspicious redirects, or data…
Analyze and guide security incident response, investigation, and remediation processes. Use when you need to handle security breaches, classify incidents, develop response…
Pipeline automatica di reverse engineering per APK Android (Flutter e nativi). Fa preflight dei tool, scarica l'app dal device con adb, rileva se è Flutter o nativa, lancia il…
Reverse engineers malicious Android APK files using JADX decompiler to analyze Java/Kotlin source code, identify
Reverse engineers .NET malware using dnSpy decompiler and debugger to analyze C#/VB.NET source code, identify
Reverse engineers malware binaries using NSA''s Ghidra disassembler and decompiler to understand internal logic,
Reverse engineer ransomware encryption routines to identify cryptographic algorithms, key generation flaws, and
Reverse engineer Rust-compiled malware using IDA Pro and Ghidra with techniques for handling non-null-terminated
Führt die Risikobewertung eines Datenschutzvorfalls anhand der EDSA-Leitlinie 9/2022 zu Beispielen für die Meldung von Datenschutzverletzungen durch.
Interprets rl-protect JSON reports (rl-protect.report.json). Use when the user asks about vulnerabilities, malware, indicators, policy violations, overrides, governance,…
Meta-Skill für die komplette Roblox-Spieleentwicklung mit Rojo — der Einstiegspunkt, der die drei Spezialskills `/rojo` (Filesystem→Studio-Sync, Projekt-Setup), `/roblox- — from…
Bedienung von Roblox Studio für die Spieleentwicklung — der visuelle Editor, in dem die 3D-Szene gebaut, getestet und veröffentlicht wird.
Apply Florian Roth's detection engineering methodology with YARA and Sigma rules. Emphasizes portable detection logic, community sharing, and signature quality.
Give agents a routing pack for authorized APK, binary, mobile, API, malware, CTF, and penetration-test analysis with tool checks and case structure.
Route an ambiguous cybersecurity request before tools run. Use for suspicious files, links, messages, host behavior, malware questions, vulnerability reports, authorized pentests,…
Sade hukuk dili: karmaşık dilekçe, karar ve sözleşmeleri müvekkilin anlayacağı yalın Türkçeye çevirme; hukuki doğruluğu koruyarak özetleme, terim açıklama ve bilgilendirme metni…
Retrieve active cyber-threat intelligence — malware IOCs, C2 infrastructure, and CISA known-exploited vulnerabilities — filterable by type, source, and severity.
Check repositories and CI surfaces for Shai-Hulud 2.0 compromise indicators when the task is targeted supply-chain triage, not generic malware scanning.
Use SafeDep Vet as a pre-adoption gate when an agent, maintainer, or CI pipeline is about to add a new dependency or import a skill repository and needs malware and policy signals…
Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage…
Document security research, CTF solutions, and malware analysis. Includes REPORT.md and STATUS.md templates.
Launch a Windows background process (.bat, node, python, .exe) with no visible console window — no black console flash on login or restart.
Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets,…
Security-audit Agent Skills and plugins — vet a new skill before installing it, scan everything already installed on this machine, or harden your own skill before publishing.
Scan OpenClaw skills for malware, prompt injection, reverse shells, wallet theft, supply chain attacks, and data exfiltration.
Security scanner for OpenClaw/ClawHub skills. Detects malware, reverse shells, credential theft, prompt injection, memory poisoning, typosquatting, and suspicious prerequisites…