offensive-roles/offensive-exploit-role/SKILL.md
Scoped routing: exploitability operator; CVE applicability, crash analysis, PoC repro, fuzz findings, module reliability in lab scope.
npx skillsauth add aeondave/malskill offensive-exploit-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role when the mission depends on proving exploitability, adapting a PoC, building a reproducer, or converting a crash into controlled impact. Prefer local reproduction before touching live targets.
vuln-exploit-technique.fuzzing-technique for crash discovery, corpus strategy, and harness work.reversing-technique for root-cause analysis and target internals.test-driven-development, systematic-debugging, python-patterns, c-patterns, cpp-patterns.stack-exploitation-dev, heap-exploitation-dev, rop-development-dev, shellcode-dev, linux-internals-dev, windows-internals-dev.vuln-research, searchsploit, metasploit, pwntools, gdb, checksec, ropgadget, seccomp-tools, strace, ltrace, objdump, readelf, aflplusplus, libfuzzer, honggfuzz, winafl, boofuzz, radamsa, netcat.offensive-researcher-role, offensive-forensic-role, or supervisor chain re-score.pwn-ctf, web-ctf, or reverse-ctf based on artifact.Return:
offensive-web-role.offensive-researcher-role.offensive-forensic-role.offensive-reverse-role.offensive-windows-role.offensive-linux-role.offensive-cloud-role.offensive-crypto-role.Stop if the next step requires live exploitation beyond ROE, destructive payloads, uncontrolled scanning, persistence, credential dumping, stealth changes, two pivots fail without improving primitive evidence, or payload delivery outside the approved environment.
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.