Skip to content

Latest commit

 

History

History
87 lines (63 loc) · 2.88 KB

File metadata and controls

87 lines (63 loc) · 2.88 KB

offsec-exploit-research

Elite adaptive whitebox exploit research skill for Claude Code and OpenCode.

Not a scanner. Not a checklist. A reusable exploit research framework that classifies your target and loads the correct attack methodology.


Install

npx offsec-exploit-research

That's it. The skill is installed globally and available in every project.


Use

Open Claude Code or OpenCode in any project:

  1. Type /skills to see the skill
  2. Ask: "audit this repo" or "find vulnerabilities"

The skill will:

  1. Fingerprint the target — language, framework, architecture, trust model
  2. Classify it — kernel? browser? distributed? web app? CLI? (16 categories)
  3. Load the right methodology — domain-specific exploit research, not a generic checklist
  4. Map attack surfaces — entry points, trust boundaries, external interfaces
  5. Generate exploit hypotheses — ranked by impact × exploitability × confidence
  6. Trace code paths — from attacker input to exploitable behavior (not grep)
  7. Validate — verify exploitability through deep code tracing, generate detailed PoC steps
  8. Synthesize chains — combine findings into realistic multi-step exploits
  9. Suppress noise — reject unreachable, theoretical, or unexploitable issues
  10. Report — structured findings with exact files, root cause, PoC, and remediation

Supported Targets

The skill adapts to fundamentally different software classes:

Category Examples
Systems / Kernel Linux kernel, drivers, hypervisors
Browser / Sandbox Chromium, Electron, renderer engines
Native Memory-Safety C/C++ parsers, codecs, protocol handlers
Distributed Systems Kubernetes, service mesh, message brokers
Proxy / Gateway Zuul, Envoy, Nginx, HAProxy, Kong
Enterprise Backend Spring, Django, Rails, ASP.NET, Express
Java Platform Spring Boot, Jakarta EE, Apache middleware
.NET Platform ASP.NET Core, Blazor, Azure Functions
CLI / Dev Tooling Package managers, build tools, agents
PowerShell PS modules, DSC, Windows automation
CI/CD Jenkins, GitHub Actions, GitLab CI
Supply Chain Dependency resolution, plugin systems
Container Runtime runc, containerd, Docker, Podman
Cloud Control Plane IAM, API servers, IaC tooling
Parsers File formats, protocols, data formats
Serialization Java/Python/.NET deserialization surfaces
Sandbox Boundaries seccomp, namespaces, WASM, isolates

What This Is NOT

  • ❌ SAST / regex scanner
  • ❌ OWASP checklist bot
  • ❌ Generic security review prompt
  • ❌ Noisy static analysis wrapper

What This IS

  • ✅ Exploit researcher mindset
  • ✅ Architecture-aware analysis
  • ✅ Domain-specific methodology
  • ✅ Real exploitability validation
  • ✅ False positive suppression
  • ✅ Exploit chain synthesis

License

MIT