All skills
simota avatar

/breach

@35ffd55
by shingo imotasimota/agent-skills85 stars
15

Designing red team attack scenarios, threat models, MITRE ATT&CK/OWASP application, Purple Team exercises, and AI/LLM red teaming. Use when adversarial security validation is needed.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/breach

This session only. Nothing lands on disk.

referencerecipes-index.md

≈540 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Breach Recipe Registry

The full Recipe table for breach. breach/SKILL.md carries only the dispatch allowlist; this file holds what is needed to execute a Recipe — activation condition and the files to read first.

Read this when a subcommand matched and you need its row, or when scanning what Recipes exist at all.


Recipe Subcommand Default? When to Use Read First
Attack Scenario scenario ✓ Attack scenario and kill-chain design — signals attack scenario / kill chain / pentest plan / WAF bypass / control validation reference/attack-playbooks.md
Threat Model threat-model STRIDE / PASTA / Attack Trees — signals threat model / attack surface / entry point / exposure. Per-engagement models; never reuse templates reference/threat-modeling.md
Purple Team purple Red/Blue coordination — signals purple team / detection validation / blue team; outputs exercise plan + detection rules reference/attack-playbooks.md
AI/LLM Red Team ai-red AI/LLM red team — signals prompt injection / jailbreak / agentic risk / RAG poisoning / prompt leakage / MAESTRO / agent skill / tool registry. Multi-turn chains against the deployed pipeline (RAG, tools, MCP, plugins) under OWASP LLM + Agentic Top 10, ATLAS, MAESTRO, NIST AI 100-2 E2025; Garak / PyRIT for automation reference/ai-red-teaming.md
Phishing Campaign phishing Authorized campaign design — pretexting, landing-page clones, MFA fatigue, quishing, OAuth consent phishing, SPF/DKIM/DMARC evasion, awareness-training integration reference/phishing-campaign-design.md
Supply Chain Attack supply Dependency confusion, typosquatting, build-tool compromise, SBOM analysis, SLSA provenance, in-toto attestation, registry pinning reference/supply-chain-attack-design.md
Social Engineering social Vishing, smishing, tailgating, OSINT pretexting, insider threat, BEC, deepfake voice/video; behavioral, not code-centric reference/social-engineering-design.md

Source: SKILL.md on GitHub

No alerts13d4 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a comprehensive security tool designed for red teaming, threat modeling, and adversarial simulation. It contains various examples of malicious patterns (such as prompt injections and social engineering pretexts) but these are explicitly presented as educational reference material and test cases for security professionals. No functional malicious code, unauthorized data access, or hidden exfiltration mechanisms were identified.

  • Socket13d

    No alerts

  • Snyk13d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 35ffd55. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/breach