Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 2. **Read** `references/ctf-playbook.md` for the matching category section
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent cybersecurity skill, but it gives broad direct-execution guidance for live scanning, exploitation, and credential attacks with insufficient scoping in the playbooks.
Install only if you intend to use it for owned, lab, CTF, or explicitly authorized security work. Before running any generated command, confirm the target scope, authorization, rate limits, and potential network or account impact, especially for full-port scans, vulnerability scanners, brute force tools, and credential-cracking workflows.
Referenced artifact was not completely inspected
2. **Read** `references/ctf-playbook.md` for the matching category section
The skill includes a concrete example of running a full-port nmap service/script scan in the background against a target, which is active network reconnaissance and can be disruptive or unauthorized. In combination with direct exec support and broad offensive scope, this materially increases the risk of misuse, accidental scanning, or policy bypass through copy-pasteable commands.
tion If critical tools are missing, suggest install commands:
sudo apt install <package>pip3 install <package>go install <repo>@latestsudo apt install kali-tools-* for categoriesUse exec with background: true and yieldMs for scans that take minutes:
exec: nmap -sV -sC -p- <TARGET> -oA /tmp/full_scan
background: true, yieldMs: 30000
Check progress with process(action=poll).
The directory traversal examples explicitly instruct users to retrieve sensitive system files such as /etc/passwd, which is a classic unauthorized file disclosure technique. In the context of an offensive-security skill, this is more dangerous because it is presented as a practical attack payload rather than abstract discussion.
**Directory Traversal**: `../../../etc/passwd`, `....//....//etc/passwd`, `%2e%2e%2f`
**Authentication Bypass**: Default creds, JWT manipulation, cookie tampering, IDOR
The document includes direct credential-cracking workflows using john and hashcat with a common leaked-password wordlist, enabling password attacks against captured hashes. Because the surrounding skill is intended for offensive security use, these instructions lower the barrier to credential attacks and can facilitate unauthorized access.
echo "<TEXT>" | tr 'A-Za-z' 'N-ZA-Mn-za-m'john --wordlist=/usr/share/wordlists/rockyou.txt --format=<FORMAT> <HASHFILE>
hashcat -m <MODE> -a 0 <HASHFILE> /usr/share/wordlists/rockyou.txt
Common hashcat modes: 0=MD5, 100=SHA1, 1400=SHA256, 1800=sha512crypt, 3200=bcrypt, 1000=NTLM
file <BINARY>
checksec --file <BINARY>
strings -n 8 <BINARY> | head -50
objdump -d -M intel <BINARY> | head -100
readelf -a <BINARY> | grep -E "RELRO|STACK|NX|PIE"
The pwntools template provides a ready-made exploitation scaffold for connecting to a remote host and sending a crafted payload, which operationalizes binary exploitation rather than merely describing it. In a CTF-only document this could be educational, but the broader skill context explicitly includes pentesting and red-team tasks, making the capability more likely to be misused against real targets.
RIP → shellcode or ret2win
ROPgadget --binary <BIN> or ropper --file <BIN> --search "pop rdi"%p to leak stack, %n to write, %<offset>$p for specific positionsfrom pwn import *
context.binary = elf = ELF('./<binary>')
# p = process('./<binary>') # Local
p = remote('<host>', <port>) # Remote
# libc = ELF('./libc.so.6')
payload = b'A' * <OFFSET>
payload += p64(<ADDRESS>)
p.sendline(payload)
p.interactive()
file <FILE>
binwalk <FILE> # Identify embedded files
binwalk -e <FILE> # Extract embedded files
foremost -i <FILE> -o /tmp/output # Carve files
exiftool <FILE> # Metadata (GPS, author, timestamps, comments)
xxd <FILE> | head -20 # Hex dump — check magic bytes
stegh
This methodology provides detailed active reconnaissance, vulnerability scanning, web exploitation, and credential-attack procedures without any gating, authorization requirements, safety warning, or impact guidance. In a skill explicitly marketed for offensive security and red-team use, this materially lowers the barrier to misuse against unauthorized targets and normalizes disruptive actions such as brute forcing, mass scanning, and exploit-oriented testing.
The file contains numerous references to widely used offensive tools and ready-to-run commands, including sqlmap and hydra, alongside scanning and exploitation workflows. While tool names alone are not always harmful, here they appear in an operational pentest playbook that enables immediate offensive action, increasing the likelihood of unauthorized exploitation.
transparency curl -s "https://crt.sh/?q=%.&output=json" | jq -r '.[].name_value' | sort -u
theHarvester -d -b all -l 500
## Phase 2: Active Reconnaissance
### Port Scanning
```bash
# Fast initial scan
rustscan -a <TARGET> --ulimit 5000 -- -sV -sC -oN rustscan.txt
# OR
masscan <TARGET> -p1-65535 --rate 1000 -oG masscan.txt
# Targeted follow-up with nmap
nmap -sV -sC -p <PORTS> -oA nmap_detailed <TARGET>
# Full comprehensive
nmap -sV -sC -A -T4 -p- -oA nmap_full <TARGET>
# UDP scan (top ports)
nmap -sU --top-ports 50 -sV <TARGET>
# Vulnerability scan
nmap --script vuln -p <PORTS> <TARGET>
HTTP/HTTPS (80, 443, 8080, 8443)
httpx -u <TARGET> -probe -tech-detect -status-code -title -content-length -follow-redirects
whatweb -v -a 3 <URL>
wafw00f <URL> # WAF detection
nuclei -u <URL> -severity critical,high -t cves/ -t exposures/ -t misconfiguration/
SMB (445)
enum4linux-ng <TAR
The finding is triggered by explicit references to well-known offensive security tools, including tools for vulnerability scanning and password cracking. In isolation, naming tools is not inherently unsafe, but here the file supplies operational syntax for their immediate use, making the content practically actionable for offensive misuse.
# Tool Quick Reference
Condensed syntax for 80+ security tools, organized by category.
## Network Scanning
| Tool | Quick Usage |
|------|------------|
| nmap | `nmap -sV -sC -p- -T4 <TARGET>` |
| rustscan | `rustscan -a <TARGET> --ulimit 5000 -- -sV -sC` |
| masscan | `masscan <TARGET> -p1-65535 --rate 1000` |
| autorecon | `autorecon <TARGET> -o /tmp/autorecon` |
## Subdomain & DNS
| Tool | Quick Usage |
|------|------------|
| amass | `amass enum -d <DOMAIN>` (active) / `-passive` |
| subfinder | `subfinder -d <DOMAIN> -silent` |
| fierce | `fierce --domain <DOMAIN>` |
| dnsenum | `dnsenum <DOMAIN>` |
| dnsrecon | `dnsrecon -d <DOMAIN> -t std,brt,axfr` |
| theHarvester | `theHarvester -d <DOMAIN> -b all -l 500` |
## Web Content Discovery
| Tool
The skill advertises direct execution of network-capable security tooling via exec but does not declare any explicit tool scope or permission boundary. In a high-risk offensive-security skill, missing least-privilege constraints increases the chance of unintended network access, unsafe command execution, or invocation in contexts where users did not intend live scanning behavior.
The trigger list is extremely broad and includes common terms such as exploit, vulnerability, recon, and security audit, making accidental or unintended invocation likely. Because this skill is designed to run offensive and network-active tools directly, overbroad matching raises the risk that benign discussions are escalated into hazardous operational guidance or command execution.
The skill explicitly promotes direct execution of 150+ security tools through exec and emphasizes no middleware or control layer, which reduces opportunities for policy enforcement, logging, and safety interlocks. In the context of pentesting, recon, brute force, and exploitation workflows, this creates a meaningful risk of system or network-impacting actions being launched too easily.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
### Tool Installation
If critical tools are missing, suggest install commands:
- **Debian/Ubuntu**: `sudo apt install <package>`
- **pip tools**: `pip3 install <package>`
- **Go tools**: `go install <repo>@latest`
- **Kali Linux**: Most tools pre-installed; `sudo apt install kali-tools-*` for categories
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
### Tool Installation
If critical tools are missing, suggest install commands:
- **Debian/Ubuntu**: `sudo apt install <package>`
- **pip tools**: `pip3 install <package>`
- **Go tools**: `go install <repo>@latest`
- **Kali Linux**: Most tools pre-installed; `sudo apt install kali-tools-*` for categories
This playbook provides step-by-step offensive scanning, exploitation, credential cracking, and post-exploitation guidance with no authorization, scope, or safety framing. In a skill explicitly marketed for pentesting, red teaming, and offensive security, that omission materially increases the risk that users will be guided into unauthorized or harmful activity.
The reconnaissance patterns include enumeration and scanning commands such as DNS recon, mass scanning, and service discovery. In isolation these can be legitimate for security assessment, but in this skill's offensive-security context and without any authorization safeguards, they facilitate broad target discovery and pre-attack mapping.
setfinder | sort -u > assetfinder.txt
cat amass_passive.txt subfinder.txt assetfinder.txt | sort -u > all_subs.txt
cat all_subs.txt | waybackurls > wayback.txt cat all_subs.txt | gau > gau.txt cat wayback.txt gau.txt | sort -u | uro > all_urls.txt
dig any +noall +answer dig axfr # Zone transfer attempt dnsrecon -d -t std,brt,axfr fierce --domain dnsenum
whois
curl -s "https://crt.sh/?q=%.&output=json" | jq -r '.[].name_value' | sort -u
theHarvester -d -b all -l 500
## Phase 2: Active Reconnaissance
### Port Scanning
```bash
# Fast initial scan
rustscan -a <TARGET> --ulimit 5000 -- -sV -sC -oN rustscan.txt
# OR
masscan <TARGET> -p1-65535 --rate 1000 -oG masscan.txt
# Targeted follow-up with nmap
nmap -sV -sC -p <PORTS> -oA nmap_detailed <TARGET>
# Full comprehensive
nmap -sV -
This reference file provides concise, ready-to-run commands for scanning, enumeration, and credential attacks without any authorization, safety, or rate-limiting guidance. In a skill explicitly designed for offensive security and red-team tasks, this materially lowers the barrier to misuse and can facilitate unauthorized reconnaissance or brute-force activity.
This finding captures network reconnaissance and enumeration commands that can be used to map targets and identify attack surface. Because the skill’s stated purpose includes pentesting, recon, and offensive security, the presence of directly usable recon syntax increases the likelihood of unauthorized scanning if the skill is misapplied.
# Tool Quick Reference
Condensed syntax for 80+ security tools, organized by category.
## Network Scanning
| Tool | Quick Usage |
|------|------------|
| nmap | `nmap -sV -sC -p- -T4 <TARGET>` |
| rustscan | `rustscan -a <TARGET> --ulimit 5000 -- -sV -sC` |
| masscan | `masscan <TARGET> -p1-65535 --rate 1000` |
| autorecon | `autorecon <TARGET> -o /tmp/autorecon` |
## Subdomain & DNS
| Tool | Quick Usage |
|------|------------|
| amass | `amass enum -d <DOMAIN>` (active) / `-passive` |
| subfinder | `subfinder -d <DOMAIN> -silent` |
| fierce | `fierce --domain <DOMAIN>` |
| dnsenum | `dnsenum <DOMAIN>` |
| dnsrecon | `dnsrecon -d <DOMAIN> -t std,brt,axfr` |
| theHarvester | `theHarvester -d <DOMAIN> -b all -l 500` |
## Web Content Discovery
| Tool | Quick Usage |
|------|------------|
| gobuster | `gobuster dir -u <URL> -w <WORDLIST> -x php,htm
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
ory="${1:-all}"
found=0; missing=0
check_tools() {
local label="$1"; shift
echo -e "\n${YELLOW}── $label ──${NC}"
for tool in "$@"; do
if check "$tool"; then ((found++)); else ((missing++)); fi
done
}
if [[ "$category" == "all" || "$category" == "network" ]]; then
check_tools "Network Scanning" nmap rustscan masscan autorecon
check_tools "DNS & Subdomain" amass subfinder fierce dnsenum dnsrecon dig whois
check_tools "SMB/Windows" enum4linux smbmap rpcclient nbtscan netexec evil-winrm
fi
if [[ "$category" == "all" || "$category" == "web" ]]; then
check_tools "Web Discovery" gobuster feroxbuster ffuf dirsearch dirb
check_tools "Web Scanning" nuclei nikto sqlmap dalfox wpscan wafw00f
check_tools "Web Crawling" httpx katana whatweb
check_tools "Parameters" arjun paramspider
fi
if [[ "$category" == "all" || "$category" == "crypto" ]]; then
check_tools "Crypto/Cracking" hashcat john hash-identifier hashid openssl gpg
fi
if [[ "$category" == "all" || "
No suspicious patterns detected.