offensive-tools/cryptography/cyberchef/SKILL.md
Auth/lab ref: Web-based data transformation and crypto analysis workbench. For rapidly decoding layered encodings, transforming binary/text formats, prototyping crypto/decode pipelines, or sharing reproducible recipes.
npx skillsauth add aeondave/malskill cyberchefInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
CyberChef is ideal for rapid transformation pipelines: decode, inspect, branch, and iterate without writing throwaway scripts first.
Magic before custom code.Magic and inspect suggestions.CyberChef supports URL recipes:
https://gchq.github.io/CyberChef/#recipe=<Ops>&input=<Base64Input>
This is useful for teammate handoff and agent reproducibility.
When recipe stabilizes and must be automated at scale:
chef.bake) or to Python equivalents.CyberChef is a web-first tool. If interactive browser steps are required and cannot be executed automatically in the current environment, request user-assisted interaction (e.g., upload input blob, verify candidate recipe output).
references/web-workflows.md — practical browser workflow, Magic usage, breakpoints, recipe sharing, and validation strategy.references/node-api-handoff.md — converting web recipes into programmatic Node API (chef, Dish, bake) for agentic automation.development
White-box auditing methodology for AI-generated ('vibe-coded') applications. Focuses on modern stack misconfigurations (Supabase, Next.js, Vercel).
development
Hybrid AI/Deterministic SAST methodology for discovering zero-day vulnerabilities in source code. Orchestrates structural search with AI-driven data flow and sink validation.
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
devops
Container methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.