offensive-roles/offensive-researcher-role/SKILL.md
Scoped routing: research operator; CVEs, advisories, PoCs, commits, writeups, applicability judgment, negative findings, source evidence.
npx skillsauth add aeondave/malskill offensive-researcher-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role when a small clue must become a decisive next experiment: CVE ID, crash text, stack frame, protocol anomaly, patch hint, version string, error message, source symbol, odd behavior, writeup fragment, or suspected bug class. The mission is source-backed research and hint synthesis, not exploitation.
deep-research-offensive, known-problem-hint-research.cve-search for vulnerability-class enumeration and public PoC/advisory collection.vuln-research for a specific product, version, CVE, or exploit availability question.zero-day-hunter only for provided local/source repositories or approved code packages; report candidates, not confirmed zero-days.evidence-before-claims, external-feedback-triage, and verification-before-completion for claim quality.recon-technique, web-exploit-technique, cloud-security-technique, active-directory-technique, post-exploit-technique, reversing-technique, forensic-technique, crypto-technique, network-technique, mobile-technique, fuzzing-technique, vuln-exploit-technique.fetch_webpage, GitHub source/code search, raw advisories, standards, changelogs, commits, issues, package registries, and CVE/security APIs.offensive-exploit-role or the domain owner with supervisor approval.| Gate | Requires approval before action | |---|---| | Live target | Any network/service contact, scan, probe, login, DNS query to target-controlled infrastructure, or callback | | Payload | Any script execution, PoC run, exploit module, fuzz campaign, payload generation, or deployable exploit code | | External submission | Any upload/query containing private evidence, hashes, samples, source snippets, hostnames, screenshots, crash data, or target fingerprints | | Credential validation | Any password/hash/token/session replay, login test, cracking, or auth check | | Data transfer | Any movement of private target data, recovered secrets, dumps, artifacts, or internal identifiers to external systems |
PoC exists, target affected, reachable here, and exploitable here; each needs its own evidence.confirmed, high, moderate, speculative.positive, negative, conflicting.exploitable without primitive evidence. Do not state not exploitable without elimination evidence. Use unknown and name the resolving test.Return:
done, done with concerns, blocked, or needs context;offensive-exploit-role.offensive-reverse-role.offensive-forensic-role.offensive-web-role.offensive-recon-role.offensive-cloud-role.offensive-windows-role.offensive-linux-role.offensive-mobile-role.offensive-crypto-role.offensive-osint-role.*-ctf skill first.Stop when the next experiment is clear, the remaining work requires execution, a query would disclose private data, sources conflict without local evidence to resolve them, bounded research finds no public path, or the question belongs to another role. Report the exact missing evidence instead of widening research indefinitely.
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.