hash-attack-techniques
Covers length extension, MD5 and SHA1 collisions, HMAC timing leaks, birthday attacks, and hash-based proof of work. Applies to CTF and authorized testing scenarios.
Your agent can do more. Find the skill that makes it happen.
Find your next superpower If you are an agent, refer to our llms.txt for full access.Covers length extension, MD5 and SHA1 collisions, HMAC timing leaks, birthday attacks, and hash-based proof of work. Applies to CTF and authorized testing scenarios.
Analyzes binary framing, HPACK compression, h2c upgrade smuggling, pseudo-header injection, and stream multiplexing abuse. Also covers downgrade translation flaws between HTTP/2 and HTTP/1.
Creates or updates privacy policies and data protection documentation. Covers data types, jurisdiction, GDPR and other compliance considerations, and highlights clauses needing legal review.
Installs dependencies, configures CSS variables through @theme inline, and connects a dark mode toggle. Also addresses colour failures, animation dependency errors, directive conflicts, and Tailwind v3-to-v4 migration issues.
Provides production deployment patterns for Next.js applications. Covers environment variables, standalone output, multi-stage Docker builds, GitHub Actions CI/CD, preview deployments, health checks, and OpenTelemetry instrumentation.
Generates investment reports for stocks and ETFs in response to market analysis or trading requests. Combines technical indicators, AI-powered insights, charts, and investment recommendations.
Provides an AD CS attack playbook covering ESC1–ESC13 template abuse, NTLM relay to enrollment, and CA officer abuse. Addresses privilege escalation and certificate-based persistence.
Assembles raw material into a progression of writing beats. Ensures a term is grounded before a later beat depends on it.
Covers profiling, flamegraphs, benchmarks, and criterion to investigate slow code. Includes allocation, caching, and SIMD optimization.
Combines frontend development with visual design, cinematic motion, AI-generated media, and conversion copywriting. Supports landing pages, marketing sites, product pages, dashboards, and generative art.
Examines Linux privilege escalation through SUID/SGID binaries, capabilities, cron abuse, kernel exploits, and misconfigurations. Also covers credential harvesting.
Provides a playbook for turning arbitrary writes from heap exploitation, format strings, or out-of-bounds writes into code execution. Covers targets including GOT entries, hooks, vtables, exit handlers, TLS destructors, and modprobe_path.
Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.
A name only tells half the story. Search the full description and instructions to find the right fit.
Read the skill, visit its source, and see exactly what you’re adding to your agent.
Copy the install command from a skill page and run it in your project.
npx skillycli add owner/repo --skill name