★ ★ ★LIVE51 SPECIALIZED SKILLS ACROSS 8 ATTACK DOMAINS · BUGGY AI·VIEW SKILLS →★ ★ ★
BUGGY
buggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leaked
SKILLS/API-INFRA
> 4 SKILLS ACTIVE

API & Infrastructure SECURITY DOMAIN

Mass assignment, JWT/CORS flaws, GraphQL introspection, prototype pollution, cloud misconfiguration, and NTLM leak patterns.

4 SKILLS IN DOMAIN
⚙️ CATEGORY
← All 8 Domains
/hunt-api-misconfig
API & Infrastructure
API Misconfig HunterAPI security misconfiguration — mass assignment, JWT attacks, prototype pollution, CORS wildcard with cre...
claude "/hunt-api-misconfig https://target.com" → trigger: auto-loaded
/hunt-cloud-misconfig
API & Infrastructure
Cloud Misconfig HunterCloud storage and service misconfiguration — S3 bucket ACL, GCS bucket enumeration, Azure blob public acc...
claude "/hunt-cloud-misconfig https://target.com" → trigger: auto-loaded
/hunt-graphql
API & Infrastructure
GraphQL Deep DiveGraphQL security deep dive — introspection bypass, batching amplification, field-level authorization bypa...
claude "/hunt-graphql https://target.com" → trigger: auto-loaded
/hunt-ntlm-info
API & Infrastructure
NTLM Info HunterNTLM information disclosure — internal hostname/domain leak via 401 challenges on web-exposed endpoints, ...
claude "/hunt-ntlm-info https://target.com" → trigger: auto-loaded