Back to authors
transilienceai

transilienceai

28 Skills published on GitHub.

ai-threat-testing

Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.

UncategorizedView skill →

authenticating

Authentication testing skill - automates signup, login, 2FA bypass, CAPTCHA solving, and bot detection evasion using Playwright MCP. Tests authentication security controls. Includes behavioral biometrics simulation, OTP handling, and automated account creation for security assessments.

UncategorizedView skill →

common-appsec-patterns

Application security testing coordinator for common vulnerability patterns including XSS, injection flaws, and client-side security issues. Orchestrates specialized testing agents to identify and validate common application security weaknesses.

UncategorizedView skill →

cve-testing

CVE vulnerability testing coordinator that identifies technology stacks, researches known vulnerabilities, and tests applications for exploitable CVEs using public exploits and proof-of-concept code.

UncategorizedView skill →

domain-assessment

Domain reconnaissance coordinator that orchestrates subdomain discovery and port scanning to build comprehensive domain attack surface inventory

UncategorizedView skill →

hackerone

HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents for each asset, validates PoCs, and generates platform-ready submission reports. Use when testing HackerOne programs or preparing professional vulnerability submissions.

UncategorizedView skill →

pentest

Penetration testing orchestrator that coordinates specialized attack agents. Provides attack indexes, methodology frameworks, and documentation. Execution delegated to specialized agents (SQL Injection, XSS, SSRF, etc.). Use for engagement planning and attack coordination.

UncategorizedView skill →

web-application-mapping

Comprehensive web application reconnaissance and mapping coordinator that orchestrates passive browsing, active endpoint discovery, attack surface analysis, and headless browser automation for complete application coverage.

UncategorizedView skill →

api-portal-discovery

Discovers public API portals, developer docs, and OpenAPI/Swagger endpoints

UncategorizedView skill →

backend-inferencer

Infers backend technologies including servers, languages, frameworks, databases, and CMS

UncategorizedView skill →

cdn-waf-fingerprinter

Identifies CDNs (Cloudflare, Akamai, Fastly) and WAFs

UncategorizedView skill →

certificate-transparency

Queries CT logs for certificates and extracts SANs for subdomain discovery

UncategorizedView skill →

cloud-infra-detector

Detects cloud providers (AWS, Azure, GCP) and PaaS platforms

UncategorizedView skill →

code-repository-intel

Scans GitHub/GitLab for public repos, dependencies, and CI configurations

UncategorizedView skill →

devops-detector

Detects CI/CD tools, containerization, and orchestration from public signals

UncategorizedView skill →

dns-intelligence

Extracts technology signals from DNS records (MX, TXT, NS, CNAME, SRV)

UncategorizedView skill →

domain-discovery

Discovers official company domain via web search, WHOIS, and common TLD patterns

UncategorizedView skill →

frontend-inferencer

Infers frontend technologies including React, Angular, Vue, jQuery, Bootstrap, etc.

UncategorizedView skill →

html-content-analysis

Parses HTML for meta tags, generator comments, and script URL patterns

UncategorizedView skill →

http-fingerprinting

Analyzes HTTP responses for technology signatures in headers, cookies, and error pages

UncategorizedView skill →

ip-attribution

Maps IP addresses to cloud providers, ASNs, and organizations via WHOIS

UncategorizedView skill →

javascript-dom-analysis

Detects frontend frameworks via global variables, DOM attributes, and bundle patterns

UncategorizedView skill →

job-posting-analysis

Extracts technology requirements from job postings and career pages

UncategorizedView skill →

security-posture-analyzer

Analyzes security headers, CSP, HSTS, WAF presence, and security.txt

UncategorizedView skill →

subdomain-enumeration

Enumerates subdomains using CT logs, passive DNS, and search engine dorks

UncategorizedView skill →

third-party-detector

Identifies third-party services including payments, analytics, auth, CRM, and support

UncategorizedView skill →

tls-certificate-analysis

Analyzes TLS certificates for issuer, SAN, and JARM fingerprints

UncategorizedView skill →

web-archive-analysis

Uses Wayback Machine to detect technology migrations over time

UncategorizedView skill →