type-juggling
Focuses on PHP type juggling and loose equality bypasses. Covers authentication, HMAC or signature checks, token validation, numeric coercion, and hash comparisons without strict types in legacy PHP or CTF code.
Your agent can do more. Find the skill that makes it happen.
Find your next superpower If you are an agent, refer to our llms.txt for full access.Focuses on PHP type juggling and loose equality bypasses. Covers authentication, HMAC or signature checks, token validation, numeric coercion, and hash comparisons without strict types in legacy PHP or CTF code.
Commits staged or unstaged changes when requested. Writes a clear message appropriate to the repository that communicates the value of the changes.
Instruments actions and features in a codebase with LaunchDarkly track() calls. Helps confirm that the resulting events reach LaunchDarkly for measurement.
Provides a Linux lateral movement playbook. Covers SSH hijacking, credential harvesting, internal pivoting, D-Bus exploitation, sudo token reuse, and shared filesystem abuse.
Provides a Windows local privilege escalation playbook. Covers token abuse, Potato exploits, service misconfigurations, DLL hijacking, UAC bypass, and registry autoruns.
Assesses contact forms, email APIs, password resets, and other features using user-controlled SMTP fields. Covers header CRLF injection, SPF/DKIM/DMARC bypass, and phishing amplification.
Use the grizzly CLI to create, search, and manage notes in Bear.
Provides a container escape playbook. Covers privileged mode, capabilities, Docker socket access, cgroup abuse, namespace techniques, and runtime vulnerabilities.
Uses Volatility 2/3 for memory forensics. Covers malware analysis, credential extraction, process investigation, code injection detection, and incident response timeline reconstruction.
Explains a selected file, function, or module in depth to support understanding of the codebase.
Covers substitution ciphers, Vigenere, transposition, XOR, and encoded text encountered in CTF challenges. Includes frequency analysis, Kasiski examination, and known-plaintext cryptanalysis.
Capture frames or video clips from RTSP/ONVIF cameras and local webcams. Supports pan, tilt, and zoom control for USB cameras.
Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.
A name only tells half the story. Search the full description and instructions to find the right fit.
Read the skill, visit its source, and see exactly what you’re adding to your agent.
Copy the install command from a skill page and run it in your project.
npx skillycli add owner/repo --skill name