offensive-roles/offensive-researcher-role/SKILL.md
Scoped routing: research operator; CVEs, advisories, PoCs, commits, writeups, applicability judgment, negative findings, source evidence.
npx skillsauth add aeondave/malskill offensive-researcher-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role when a small clue must become a decisive next experiment: CVE ID, crash text, stack frame, protocol anomaly, patch hint, version string, error message, source symbol, odd behavior, writeup fragment, or suspected bug class. The mission is source-backed research and hint synthesis, not exploitation.
deep-research-offensive, known-problem-hint-research.cve-search for vulnerability-class enumeration and public PoC/advisory collection.vuln-research for a specific product, version, CVE, or exploit availability question.zero-day-hunter only for provided local/source repositories or approved code packages; report candidates, not confirmed zero-days.evidence-before-claims, external-feedback-triage, and verification-before-completion for claim quality.recon-technique, web-exploit-technique, cloud-security-technique, active-directory-technique, post-exploit-technique, reversing-technique, forensic-technique, crypto-technique, network-technique, mobile-technique, fuzzing-technique, vuln-exploit-technique.fetch_webpage, GitHub source/code search, raw advisories, standards, changelogs, commits, issues, package registries, and CVE/security APIs.offensive-exploit-role or the domain owner with supervisor approval.| Gate | Requires approval before action | |---|---| | Live target | Any network/service contact, scan, probe, login, DNS query to target-controlled infrastructure, or callback | | Payload | Any script execution, PoC run, exploit module, fuzz campaign, payload generation, or deployable exploit code | | External submission | Any upload/query containing private evidence, hashes, samples, source snippets, hostnames, screenshots, crash data, or target fingerprints | | Credential validation | Any password/hash/token/session replay, login test, cracking, or auth check | | Data transfer | Any movement of private target data, recovered secrets, dumps, artifacts, or internal identifiers to external systems |
PoC exists, target affected, reachable here, and exploitable here; each needs its own evidence.confirmed, high, moderate, speculative.positive, negative, conflicting.exploitable without primitive evidence. Do not state not exploitable without elimination evidence. Use unknown and name the resolving test.Return:
done, done with concerns, blocked, or needs context;offensive-exploit-role.offensive-reverse-role.offensive-forensic-role.offensive-web-role.offensive-recon-role.offensive-cloud-role.offensive-windows-role.offensive-linux-role.offensive-mobile-role.offensive-crypto-role.offensive-osint-role.*-ctf skill first.Stop when the next experiment is clear, the remaining work requires execution, a query would disclose private data, sources conflict without local evidence to resolve them, bounded research finds no public path, or the question belongs to another role. Report the exact missing evidence instead of widening research indefinitely.
development
White-box auditing methodology for AI-generated ('vibe-coded') applications. Focuses on modern stack misconfigurations (Supabase, Next.js, Vercel).
development
Hybrid AI/Deterministic SAST methodology for discovering zero-day vulnerabilities in source code. Orchestrates structural search with AI-driven data flow and sink validation.
development
Auth assessment: hardware/embedded methodology; UART/JTAG/SWD/SPI/I2C, firmware extraction, boot/debug paths, embedded OS evidence.
devops
Container methodology: Identifying containerization limits, Docker/K8s misconfigurations, and executing escapes to the host node.