Mmcp.market

offensive-bug-identification skill

by SnailSploit·SnailSploit/Claude-Red·7.0k stars·MIT

No description in the SKILL.md.

A94/100content scan

Is the offensive-bug-identification skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

  • lowSKILL.md:1

    The name should be 1 to 64 lowercase letters, digits or hyphens.

    (missing)
  • lowSKILL.md:1

    No description, so an agent cannot tell when to use the skill.

    (missing)

Install the offensive-bug-identification skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/SnailSploit/Claude-Red.git /tmp/Claude-Red
mkdir -p ~/.claude/skills
cp -r /tmp/Claude-Red/Skills/fuzzing/offensive-bug-identification ~/.claude/skills/offensive-bug-identification
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

SKILL: Bug Identification

Metadata

  • Skill Name: bug-identification
  • Folder: offensive-bug-identification
  • Source: https://github.com/SnailSploit/offensive-checklist/blob/main/bug-identification.md

Description

Systematic bug identification methodology: source code review patterns, black-box testing strategies, taint analysis, dangerous function hunting, data flow tracing, and automated scanning setup. Use for code audits, bug bounty triage, or building vulnerability identification pipelines.

Trigger Phrases

Use this skill when the conversation involves any of: bug identification, code review, taint analysis, dangerous functions, data flow, source audit, black box, vulnerability identification, static analysis, code audit, bug hunting

Instructions for Claude

When this skill is active:

  1. Load and apply the full methodology below as your operational checklist
  2. Follow steps in order unless the user specifies otherwise
  3. For each technique, consider applicability to the current target/context
  4. Track which checklist items have been completed
  5. Suggest next steps based on findings

Full Methodology

Bug Identification

Overview

Bug identification is the process of discovering potential vulnerabilities in software through various techniques including static analysis, dynamic analysis, and fuzzing. This document outlines methodologies and tools for effective vulnerability research.

For practical exploit development, see Exploit Development.

flowchart TD
    BugId["Bug Identification"]

    %% Main Methods
    Static["Static Analysis"]
    Dynamic["Dynamic Analysis"]
    Fuzzing["Fuzzing"]
    AI["AI-Assisted"]

    %% Static Analysis Methods
    CodeReview["Manual Code Review"]
    RevEng["Reverse Engineering"]
    PatchDiff["Patch Diffing"]
    StaticTools["Static Analysis Tools"]
    SBOM["Supply Chain Analysis"]

    %% Dynamic Analysis Methods
    DebugTrace["Debugging/Tracing"]
    DBI["Dynamic Binary Instrumentation"]
    Taint["Taint Analysis"]
    SymExec["Symbolic Execution"]
    Snapshot["Snapshot Analysis"]

    %% Fuzzing Methods
    DumbFuzz["Dumb Fuzzing"]
    SmartFuzz["Smart Fuzzing"]
    EvoFuzz["Evolutionary Fuzzing"]
    LLMFuzz["LLM-Guided Fuzzing"]

    %% AI Methods
    LLMTriage["LLM Crash Triage"]
    MLPattern["ML Pattern Recognition"]
    AutoVariant["Automated Variant Analysis"]

    %% Connections
    BugId --> Static
    BugId --> Dynamic
    BugId --> Fuzzing
    BugId --> AI

    Static --> CodeReview
    Static --> RevEng
    Static --> PatchDiff
    Static --> StaticTools
    Static --> SBOM

    Dynamic --> DebugTrace
    Dynamic --> DBI
    Dynamic --> Taint
    Dynamic --> SymExec
 

Vulnerability Research Methodology

Phase 1: Reconnaissance

  • Target Enumeration: Identify version, dependencies, configuration
  • Attack Surface Mapping: List all input vectors, APIs, protocols
  • Documentation Review: RFCs, specifications, developer docs
  • Prior Art Analysis: CVE database, exploit-db, bug trackers

Phase 2: Static Analysis

  • Source Review: If available, focus on parsing/validation code
  • Binary Analysis: Reverse engineering with Ghidra/IDA
  • Patch Diffing: Compare vulnerable vs patched versions
  • SBOM Analysis: Check third-party component vulnerabilities

Phase 3: Dynamic Analysis

  • Behavioral Analysis: Monitor syscalls, network, file I/O
  • Debugging: Trace execution paths with controlled input
  • Instrumentation: Coverage-guided exploration
  • Taint Analysis: Track input propagation

Phase 4: Fuzzing

  • Corpus Generation: Create valid seed inputs
  • Harness Development: Isolate target functionality
  • Coverage Monitoring: Identify untested code paths
  • Crash Triage: Classify and prioritize findings

Phase 5: Exploitation

  • Primitive Development: Convert bug to reliable primitives
  • Mitigation Bypass: Defeat ASLR, DEP, CFG, etc.
  • Payload Development: Create working exploit
  • Weaponization: Package for real-world use (if authorized)

Attack Surface Identification

Before diving into specific bug hunting techniques, it's essential to understand where to look for vulnerabilities.

Windows User Mode

  • Shared Memory
  • RPC
  • Named Pipes
  • File & Network IO
  • Windows Messages
  • For authentication-related vulnerabilities, see Windows Auth

Kernel

  • Device Drivers
  • Many third-party software with drivers to target
  • Can accept arbitrary user input via the IOCTL interface
  • Also performs actions when we open,close handles to it
  • OS
  • Drivers that handle hardware and user input
  • Intercepts/transitions from user to kernel
  • Modern Linux interfaces (hotspots)
  • iouring**: SQE size/offset confusions, submission/completion race windows, kernel copy‑sizes derived from user buffers
  • userfaultfd: cross‑thread write‑what‑where and TOCTOU primitives during fault handling
  • seccomp user‑notifier: confused‑deputy patterns in broker processes; notifier time‑of‑check vs time‑of‑use gaps
  • Hyper-V & VTL Interfaces – On many modern Windows 11 systems (especially 24H2 on supported hardware), Virtualization‑Based Security and VTL1 are enabled or easily enabled by policy. Treat the hypervisor surface (e.g., hvix64.exe and synthetic MSRs) as a common kernel target, and verify VBS/HVCI status on the host before assuming defaults.

Drivers

  • DriverEntry: registers for any callbacks, setup structure, etc
  • I/O Handlers: handlers that get called when a process attempts to open,close,etc the driver, IOCTL allows driver functionality to be called from user processes
  • Practical triage example (CVE‑2025‑8061):
  • IOCTL handlers that accept a fixed‑size struct and pass a user‑controlled PHYSICAL_ADDRESS directly to MmMapIoSpace
  • then memcpy out/in mapped memory (sometimes via wrappers that swap src/dst) indicate physical memory read/write primitives.
  • Similarly, unguarded MSR read/write paths yield RDMSR/WRMSR primitives.
  • See the Lenovo LnvMSRIO.sys case study in windows-kernel.md

eBPF & XDP

  • BPF helpers and verifier: pointer leaks, verifier bypass, JIT bugs
  • User‑entry vectors: bpf() syscall, privileged pods in Kubernetes, Cilium datapath
  • Tooling: bpftool, verifier logs, bpftrace scripts for quick triage
  • CO‑RE skeletons (bpftool gen skeleton) simplify packaging portable tracing probes.
  • BPF LSM hooks allow low‑overhead coverage feedback on security‑critical kernel paths; export events with trace_pipe.

Container & Micro‑VM Surface

  • Namespace/cgroup escapes, device‑mapper abuse, races in snapshotting backends (e.g., overlayfs)
  • Micro‑VM hypercalls in Firecracker, CloudHypervisor, Kata Containers
  • For detailed container exploitation techniques, see Container

Cloud‑Native & IAM Bugs

  • Misconfigured IAM policies, privilege‑escalating API actions (AWS sts:AssumeRole, Azure Golden SAML)
  • SSRF paths into metadata services (169.254.169.254, IMDSv2 bypass techniques)
  • Race conditions in managed control‑plane components (Kubernetes API server, AWS Lambda workers)
  • Kubernetes Attack Vectors: look at kubernetes for a deeper checklist
  • Serverless Vulnerabilities:
  • Lambda layer poisoning
  • Function URL authentication bypass
  • Event injection through SQS/SNS/EventBridge
  • Cold start race conditions

Network / Transport Protocol Parsers

  • QUIC / HTTP/3: coalesced frames, reorder/timing corner cases; verify against RFC 9000 (QUIC) and RFC 9114 (HTTP/3)
  • HTTP/2: stream state machine desync; flow‑control integer edge cases (RFC 7540)
  • gRPC / Protobuf: length truncation across language FFI, map/list coercion; see gRPC framing and protobuf varint rules
  • GraphQL: input coercion and resolver recursion limits; check GraphQL spec for type coercion semantics

WebAssembly Runtimes

  • WASM JIT optimization bugs in V8, Wasmtime, Wasmer
  • WASI sandbox escapes through host‑call interfaces
  • Typed‑Func‑Refs, GC, Tail‑calls, Memory64 expand type/bounds confusion surface. See the WebAssembly proposals status page for current rollout and engine adoption.
  • Checklist:
  • validate table element types/import signatures/hostcall marshalling
  • fuzz mixed 32/64-bit memories.
  • Fuzzing tip: compile native libs to WASM for fast, deterministic mutation cycles

Browser / JS Engine Exploitation

Modern V8 Architecture (2024-2025)

V8 now uses a multi-tier JIT pipeline with distinct exploitation characteristics:

  • Ignition (Interpreter): Bytecode interpreter; rarely targeted directly
  • Maglev (Mid-tier JIT): Introduced Chrome 115+; simpler IR than TurboFan
  • TurboFan (Optimizing JIT): Aggressive optimization; traditional exploitation target
  • Turboshaft: New IR replacing TurboFan internals; different optimization patterns create new bug classes
  • Type lattice changes affecting confusion bugs
  • Maglev → Turboshaft transition paths expose state inconsistencies
  • Node-based to block-based IR transition

V8 Maglev Exploitation

  • Integer overflow in Maglev's fast-path arithmetic
  • Corrupted HeapNumber backing store via Maglev bounds check bypass
  • Map/ElementsKind confusion in polymorphic inline caches

WebAssembly JSPI (JavaScript Promise Integration)

  • Stack Heap Spray: Suspended WASM stacks allocated on heap; predictable layout
  • Type Confusion: WebAssembly.Suspending wrapper type mismatch
  • Info Leak: Stack pointers exposed through Promise resolution chains
  • Sandbox Escape: JSPI bridges JS/WASM boundary; bypass traditional WASM isolation

Spectre-BHB Browser Mitigations

  • Chrome 120+: Site Isolation per-frame; shared array buffer restrictions
  • Firefox 122+: Process-per-site with BHI fences in JIT trampolines
  • Safari 17.4+: WebKit JIT speculation guards on type checks

Site Isolation Plus

  • Frame-level process isolation: Each cross-origin frame in separate process
  • Cross-origin memory protection: Hardware-backed memory isolation
  • New IPC attack surface: Mojo interface exploitation required for escapes
  • Renderer → Browser requirements: Need Mojo race or type confusion
  • New Info-Leak Requirements:
  • Traditional SharedArrayBuffer + Atomics timing attacks less reliable
  • Need alternative side-channels: CSS timing, WebGL shader execution, AudioContext
  • Cross-origin info leaks require chaining multiple primitives

Practical Browser Exploitation Workflow

  1. Target Selection:
  • V8 Maglev for Chrome/Edge (faster development cycle = more bugs)
  • JSC for Safari (less scrutiny than V8)
  • SpiderMonkey for Firefox (IonMonkey/Warp still viable)

More skills from SnailSploit/Claude-Red

  • Aoffensive-active-directoryActive Directory attack methodology for internal network red team engagements. Covers reconnaissance (BloodHound, PowerView, ADExplorer), credential abuse (Kerberoasting, ASREProasting, NTLM relay, LLMNR/NBT-NS poisoning), privilege escalation (ACL abuse, GPO abuse, unconstrained/constrained delegation), lateral movement (Pass-the-Hash, Pass-the-Ticket, Overpass-the-Hash, WMI/WinRM/PsExec), persistence (Golden/Silver/Diamond Tickets, DCSync, DCShadow, AdminSDHolder, Skeleton Key), forest trust attacks, ADCS abuse (ESC1-ESC15), and modern MDI/Defender for Identity evasion. Use when assessing on-prem AD, hybrid AD/Entra ID environments, or ADCS deployments.
  • Aoffensive-advanced-redteamComprehensive red team operations methodology covering full engagement lifecycle from planning through reporting. Addresses engagement scoping and rules of engagement negotiation, multi-tier C2 infrastructure design with redirectors and domain fronting, malleable traffic profiles and beacon tradecraft, OPSEC discipline including attribution avoidance and indicator management, EDR and AMSI evasion techniques using direct syscalls and unhooking, data collection with chain-of-custody controls, and structured reporting with purple team debrief workflows. Covers assumed-breach, external-to-internal, insider threat, and hybrid physical-cyber engagement scenarios with MITRE ATT&CK mapping throughout. Targets operators planning or executing adversary simulation engagements against mature defenders.
  • Coffensive-ai-security
  • Aoffensive-anti-forensicsAnti-forensics and evidence destruction techniques for red team operators conducting authorized engagements. Covers log clearing on Windows (wevtutil, Clear-EventLog, ETW provider patching) and Linux (journal truncation, utmp/wtmp binary editing, syslog manipulation), timestamp manipulation via Timestomp and SetMACE to defeat timeline analysis, filesystem-level anti-forensics including NTFS Alternate Data Streams for payload hiding and secure deletion with sdelete/shred, memory artifact removal to counter live forensics, disk artifact manipulation targeting MFT entries and USN journal records, network forensics evasion through encrypted C2 channels and DNS-over-HTTPS tunneling, and anti-VM/sandbox detection to avoid dynamic analysis environments. Tools: Timestomp, wevtutil, sdelete, shred, MimiPenguin, Invoke-Phant0m. Aligns to MITRE ATT&CK T1070 (Indicator Removal), T1027 (Obfuscated Files or Information), T1497 (Virtualization/Sandbox Evasion). Each technique includes the forensic artifact it targets, the destruction or manipulation method, and the defender perspective so operators understand detection gaps they must account for.
  • Aoffensive-api-abuseAdvanced API exploitation methodology focused on business logic abuse and sophisticated attack patterns that bypass traditional security controls. Covers business logic bypass through API call chaining and workflow manipulation. Addresses GraphQL-specific attacks including batching for credential brute-force, query depth exploitation, and introspection abuse. Includes pagination exploitation for data exfiltration, webhook hijacking for SSRF and data interception, and resource exhaustion through algorithmic complexity attacks. Covers race conditions in API transactions using parallel request techniques. Provides comprehensive JWT manipulation including algorithm confusion, kid injection, jku/x5u abuse, and claim tampering. Details API key leakage detection across source repositories, client-side code, and error messages. Covers undocumented endpoint discovery through predictable naming, debug routes, and source map analysis. Tooling includes Arjun, ParamSpider, jwt_tool, and GraphQL Voyager. Designed for authorized penetration testers targeting business logic layers that automated scanners miss.
  • Aoffensive-api-securityComprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. Addresses the full OWASP API Security Top 10 2023 including BOLA/IDOR, broken authentication, excessive data exposure, rate limiting bypass, BFLA, mass assignment, SSRF, and security misconfiguration. Includes REST-specific attacks such as HTTP verb tampering, content-type switching, and parameter pollution. Covers gRPC exploitation through protobuf interception, reflection API enumeration, and metadata injection. Addresses WebSocket vulnerabilities including origin bypass, message injection, and cross-site WebSocket hijacking. Provides tooling guidance for Burp Suite, Postman, grpcurl, websocat, and mitmproxy. Each technique includes detection signatures and defensive indicators so you understand what artifacts your testing leaves behind. Designed for authorized penetration testing engagements against API-driven architectures.
  • Aoffensive-bluetooth-bleBluetooth Low Energy (BLE) attack methodology — GATT enumeration, characteristic read/write without auth, pairing downgrade (Just Works forced), LE Secure Connections bypass, MITM via active relay, sniffing with Sniffle (TI CC1352) / Ubertooth / Frontline, encryption key extraction (LE Legacy Pairing crackable, LE Secure Connections strong), proximity authentication abuse (cars, locks), and companion-app trust analysis. Use for IoT BLE devices, smart locks, fitness trackers, medical devices, BLE beacons, or any device pairing over BLE.
  • Aoffensive-bluetooth-classicBluetooth Classic (BR/EDR) attack methodology — device discovery, service enumeration via SDP, LMP/L2CAP layer attacks, legacy PIN cracking (BlueBorne / KNOB), Bluetooth file-transfer abuse (BlueSnarfing legacy), unauthenticated profile abuse (HSP, HFP, OPP), and modern relevance against older industrial / automotive / accessory targets. Use when in-scope devices use Bluetooth Classic (Bluetooth ≤ 4.0 BR/EDR) — common in legacy car kits, industrial sensors, older medical devices, and audio accessories.
  • Aoffensive-business-logicBusiness logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.
  • Aoffensive-c2-frameworksCommand and Control framework deployment, configuration, and operational tradecraft for red team engagements. Covers Cobalt Strike (malleable C2 profiles, Beacon types HTTP/HTTPS/DNS/SMB, Beacon Object Files for in-memory execution, sleep and jitter tuning, named pipe pivoting), Sliver (implant generation across mTLS/WireGuard/DNS transport, operator multiplayer mode, armory extensions), Mythic (agent ecosystem with Apollo/Poseidon/Medusa, C2 profile configuration, translation containers), Havoc (Demon agent with sleep obfuscation via Ekko/Zilean, indirect syscalls, dotnet inline execution), Metasploit (msfvenom payload generation, multi/handler staging, Meterpreter post-exploitation modules), redirector architecture using Apache mod_rewrite and Nginx, domain fronting through CDN providers, DNS-based C2 for restrictive network egress, and TLS certificate management for infrastructure OPSEC. Tools: Cobalt Strike, Sliver, Mythic, Havoc, Metasploit Framework. Aligns to MITRE ATT&CK T1071 (Application Layer Protocol), T1573 (Encrypted Channel), T1090 (Proxy/Connection Proxy).
  • Doffensive-cicd-pipelineComprehensive CI/CD pipeline exploitation methodology covering GitHub Actions injection vectors (expression injection via PR titles and issue bodies, workflow_run event abuse, GITHUB_TOKEN over-scoping, composite action supply chain compromise), Jenkins attack paths (Groovy sandbox escapes, script console remote code execution, Java remoting deserialization, credential store dumping, shared library injection), GitLab CI exploitation (YAML anchor injection, runner registration token abuse, CI variable extraction, protected branch bypass via merge request pipelines), and Azure DevOps pipeline agent compromise with service connection theft. Includes artifact poisoning techniques across all platforms, tooling guidance for gato and jenkins-attack-framework, and maps to MITRE ATT&CK T1195.002 (Supply Chain Compromise: Compromise Software Supply Chain). Covers enumeration of pipeline configurations, privilege escalation from contributor to code execution, lateral movement through pipeline trust boundaries, and persistence via modified workflow definitions. Each technique section provides working exploitation code, detection indicators, and defensive countermeasures.
  • Coffensive-cicd-secretsComprehensive secrets extraction methodology targeting CI/CD environments across all major platforms. Covers environment variable extraction from build contexts, exploitation of vault and secrets-manager misconfigurations (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager), runner and agent token abuse for lateral movement, OIDC federation attacks exploiting trust relationships between CI/CD providers and cloud platforms, build log leakage analysis for inadvertently exposed credentials, cache poisoning techniques for credential exfiltration, platform-specific credential store exploitation (GitHub Actions secrets, GitLab CI variables, Jenkins credential providers), service connection and service account abuse in Azure DevOps and GCP, and Docker registry credential theft from build environments. Maps to MITRE ATT&CK T1552 (Unsecured Credentials) and its sub-techniques. Each section provides enumeration procedures, extraction techniques, and post-exploitation pivoting guidance for using recovered secrets to expand access.

All agent skills → · MCP servers