Skip to content

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

146.7K
listings
1
installs
0
reviews
40.4K
publishers
50 results
Skill

performing-aws-privilege-escalation-assessment

Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapp

by mukul975skills.sh
Not rated yet
Free
Skill

performing-gcp-penetration-testing-with-gcpbucketbrute

Performs authorized GCP security testing using GCPBucketBrute to enumerate publicly accessible storage buckets, combined with gcloud CLI IAM enumeration to find privilege escalation paths and audit se

by mukul975skills.sh
Not rated yet
Free
Skill

performing-privilege-escalation-assessment

Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations,

by mukul975skills.sh
Not rated yet
Free
Skill

performing-privilege-escalation-on-linux

Guides manual enumeration and automated tooling to escalate from a low-privilege Linux user to root by exploiting misconfigurations, vulnerable services, kernel exploits, and weak permissions, mapped

by mukul975skills.sh
Not rated yet
Free
Skill

relaying-ntlm-for-adcs-esc8

Uses Impacket's ntlmrelayx.py with a coercion tool (PetitPotam, Coercer, printerbug) to relay NTLM authentication from a coerced domain controller into the AD CS HTTP web-enrollment endpoint (ESC8), o

by mukul975skills.sh
Not rated yet
Free
Skill

testing-for-broken-access-control

Systematically tests web applications and APIs for broken access control (OWASP A01:2021), including privilege escalation, missing function-level checks, insecure direct object references, and multi-t

by mukul975skills.sh
Not rated yet
Free
Skill

cis-ubuntu1204-v110-12-11

Find SGID System Executables

by CyberStrikeusGitHub
Not rated yet
Free
Skill

prvlg-escltn-attempts

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.

by UndermybeltGitHub
Not rated yet
Free
Skill

detecting-privilege-escalation-attempts

Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.

by HenriqueMC17GitHub
Not rated yet
Free
Skill

detecting-privilege-escalation-attempts

Detect privilege escalation attempts across Windows and Linux, including access token manipulation, UAC bypass, unquoted service path abuse, kernel exploits, and sudo/doas abuse. Use when threat hunti

by gabrielmoreiraGitHub
Not rated yet
Free
Skill

detecting-t1548-abuse-elevation-control-mechanism

Detect abuse of elevation control mechanisms including UAC bypass, sudo exploitation, and setuid/setgid manipulation by monitoring registry modifications, process elevation flags, and unusual parent-c

by WorkNFlowGitHub
Not rated yet
Free
Skill

detecting-t1548-abuse-elevation-control-mechanism

Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry chan

by brianmcgillionGitHub
Not rated yet
Free
Skill

performing-active-directory-vulnerability-assessment

Assess Active Directory security posture using PingCastle, BloodHound, and Purple Knight to identify misconfigurations, privilege escalation paths, and attack vectors.

by HenriqueMC17GitHub
Not rated yet
Free
Skill

performing-privilege-escalation-assessment

Performs privilege escalation assessments on compromised Linux and Windows systems to identify paths from low-privilege access to root or SYSTEM-level control. The tester enumerates misconfigurations,

by rivaldiekaptrrrGitHub
Not rated yet
Free
Skill

testing-for-broken-access-control

Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.

by 26zlGitHub
Not rated yet
Free
Skill

testing-for-broken-access-control

Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.

by dimavenvGitHub
Not rated yet
Free
Skill

testing-for-broken-access-control

Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.

by henriquescastilhoGitHub
Not rated yet
Free
Skill

testing-for-broken-access-control

Systematically testing web applications for broken access control vulnerabilities including privilege escalation, missing function-level checks, and insecure direct object references.

by megawesley2015-langGitHub
Not rated yet
Free
Skill

ai-agent-tool-abuse-and-privilege-escalation

Test AI agent systems for tool abuse, unauthorized actions, privilege escalation through tool chaining, and safety bypass via agentic workflows. Use this skill when assessing autonomous AI agents that

by ShulkwiSECGitHub
Not rated yet
Free
Skill

exploiting-broken-function-level-authorization

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The teste

by SUEYTAMEGitHub
Not rated yet
Free
Skill

exploiting-broken-function-level-authorization

Tests APIs for Broken Function Level Authorization (OWASP API5:2023) by identifying admin and privileged endpoints, then reaching them with regular-user credentials via HTTP method switching, URL path

by costrict-plugins-repoGitHub
Not rated yet
Free
Skill

exploiting-broken-function-level-authorization

Tests APIs for Broken Function Level Authorization (BFLA) vulnerabilities where regular users can invoke administrative functions or access privileged API endpoints by directly calling them. The teste

by braydos-hGitHub
Not rated yet
Free
Skill

exploiting-broken-function-level-authorization

Tests APIs for Broken Function Level Authorization (OWASP API5:2023) by identifying admin and privileged endpoints, then reaching them with regular-user credentials via HTTP method switching, URL path

by bfoxhoundGitHub
Not rated yet
Free
Skill

exploiting-broken-function-level-authorization

Tests APIs for Broken Function Level Authorization (OWASP API5:2023) by identifying admin and privileged endpoints, then reaching them with regular-user credentials via HTTP method switching, URL path

by RanuK12GitHub
Not rated yet
Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.