home / skills / jcastillotx

jcastillotx skills

Find 41 skills from 1 repo created by jcastillotx on GitHub.

1 repo
41 skills
GitHub

Sponsored

broken-authentication

jcastillotx/vibe-skeleton-app

This skill helps identify and exploit broken authentication and session management vulnerabilities in web apps, guiding password policy, token handling, and
red-team-tools

jcastillotx/vibe-skeleton-app

This skill helps security researchers automate reconnaissance, subdomain enumeration, and vulnerability discovery using red team methodologies.
shodan-reconnaissance

jcastillotx/vibe-skeleton-app

This skill helps you perform Shodan reconnaissance for penetration testing by guiding API/CLI usage to discover exposed devices and services.
claude-docs-consultant

jcastillotx/vibe-skeleton-app

This skill helps you efficiently consult Claude Code documentation by fetching only the relevant guides on demand for hooks, skills, or subagents.
linux-shell-scripting

jcastillotx/vibe-skeleton-app

This skill provides production-ready bash script templates to automate Linux tasks, backup data, monitor resources, and manage system administration.
wireshark-analysis

jcastillotx/vibe-skeleton-app

This skill helps you analyze and troubleshoot network traffic with Wireshark, capture packets, filter PCAPs, and reconstruct conversations for rapid insights.
wordpress-penetration-testing

jcastillotx/vibe-skeleton-app

This skill guides secure WordPress assessments by outlining enumeration, vulnerability scanning, credential testing, and safe exploitation techniques.
delegate

jcastillotx/vibe-skeleton-app

This skill automatically delegates tasks to specialized subagents, optimizing workload and accelerating delivery with clear context and parallel execution
laravel-best-practices

jcastillotx/vibe-skeleton-app

This skill enforces Laravel best practices to optimize security, Eloquent, performance, API design, and testing across applications.
mysql-best-practices

jcastillotx/vibe-skeleton-app

This skill helps you apply MySQL best practices for query optimization, security, and schema design to build robust, scalable databases.
nextjs-best-practices

jcastillotx/vibe-skeleton-app

This skill guides Next.js App Router best practices to optimize performance, server components, data fetching, and deployment across modern apps.
php-best-practices

jcastillotx/vibe-skeleton-app

This skill helps you write, review, and refactor PHP code by applying security, performance, and PSR-aligned best practices.
active-directory-attacks

jcastillotx/vibe-skeleton-app

This skill helps assess and map Active Directory security posture by outlining reconnaissance and credential exposure concepts for red team planning.
api-fuzzing-bug-bounty

jcastillotx/vibe-skeleton-app

This skill guides API fuzzing for bug bounty, detailing REST, GraphQL, and SOAP testing to uncover vulnerabilities efficiently.
aws-penetration-testing

jcastillotx/vibe-skeleton-app

This skill guides you through AWS security testing, IAM enumeration, and security finding generation to assess and improve cloud defenses.
windows-privilege-escalation

jcastillotx/vibe-skeleton-app

This skill guides systematic Windows privilege escalation, helping you enumerate defenses, harvest credentials, and obtain elevated access during authorized
burp-suite-testing

jcastillotx/vibe-skeleton-app

This skill guides you through Burp Suite Web Application Testing to intercept, modify, and analyze HTTP traffic for security testing.
cloud-penetration-testing

jcastillotx/vibe-skeleton-app

This skill helps perform cloud penetration testing across Azure, AWS, and GCP, delivering comprehensive assessments, resource discovery, and remediation
file-path-traversal

jcastillotx/vibe-skeleton-app

This skill helps you test for file path traversal vulnerabilities in web apps, guiding payloads, bypass techniques, and remediation recommendations.
pentest-checklist

jcastillotx/vibe-skeleton-app

This skill helps plan and execute pentest engagements with a structured checklist, ensuring defined scope, prepared environments, and actionable remediation.
html-injection-testing

jcastillotx/vibe-skeleton-app

This skill helps identify and test HTML injection vulnerabilities in web applications, enabling safe assessment of defacement and phishing risks.
idor-testing

jcastillotx/vibe-skeleton-app

This skill guides you to identify and remediate IDOR vulnerabilities in web apps through systematic testing, enumeration, and secure coding practices.
linux-privilege-escalation

jcastillotx/vibe-skeleton-app

This skill helps assess and exploit Linux privilege escalation paths by enumerating targets, identifying misconfigurations, and guiding safe remediation.
pentest-commands

jcastillotx/vibe-skeleton-app

This skill provides quick, actionable pentest command references for Nmap, Metasploit, Nikto, SQLMap, Hydra, John the Ripper, and related tools.
metasploit-framework

jcastillotx/vibe-skeleton-app

This skill guides you through using the Metasploit Framework for authorized penetration testing, from scanning to post-exploitation and payload generation.
network-101

jcastillotx/vibe-skeleton-app

This skill helps you set up and test HTTP, HTTPS, SNMP, and SMB services for penetration testing labs.
privilege-escalation-methods

jcastillotx/vibe-skeleton-app

This skill guides penetration testers through Linux and Windows privilege escalation techniques to obtain root or administrator access ethically and safely.
scanning-tools

jcastillotx/vibe-skeleton-app

This skill guides you through security scanning tool selection, configuration, and workflows to assess networks, apps, and cloud for vulnerabilities and
react-best-practices

jcastillotx/vibe-skeleton-app

React and Next.js performance optimization guidelines from Vercel Engineering. This skill should be used when writing, reviewing, or refactoring React/Next.js code to ensure optimal performance patterns. Triggers on tasks involving React components, Next.js pages, data fetching, bundle optimization, or performance improvements.
smtp-penetration-testing

jcastillotx/vibe-skeleton-app

This skill helps you assess SMTP server security by enumerating users, testing relays, and guiding remediation with actionable steps.
sql-injection-testing

jcastillotx/vibe-skeleton-app

This skill helps identify and document SQL injection vulnerabilities in web applications through controlled testing and remediation guidance.
ssh-penetration-testing

jcastillotx/vibe-skeleton-app

This skill guides you through SSH security testing, enumeration, credential attacks, tunneling, and post-exploitation with practical, step-by-step methods.
xss-html-injection

jcastillotx/vibe-skeleton-app

This skill helps you identify and demonstrate XSS vulnerabilities in web apps, guiding safe testing and remediation with client-side injection techniques.
orchestrate

jcastillotx/vibe-skeleton-app

This skill guides you through a 12-phase development lifecycle, validating quality gates and advancing or navigating phases to ensure project readiness.
javascript-best-practices

jcastillotx/vibe-skeleton-app

This skill helps you write and review JavaScript code by applying best-practice guidelines across performance, async patterns, security, and modern features.
mariadb-best-practices

jcastillotx/vibe-skeleton-app

This skill helps optimize MariaDB development by applying best-practice rules for queries, security, schema, storage engines, and Galera clusters.
supabase-best-practices

jcastillotx/vibe-skeleton-app

This skill enforces Supabase best practices across security, schema design, authentication, real-time, edge functions, and performance for robust apps.
wordpress-best-practices

jcastillotx/vibe-skeleton-app

This skill helps you apply WordPress best practices across plugins, themes, and blocks to improve security, performance, and reliability.
top-web-vulnerabilities

jcastillotx/vibe-skeleton-app

This skill helps you identify and explain web vulnerabilities across categories, providing definitions, root causes, impacts, and mitigations aligned with
ethical-hacking-methodology

jcastillotx/vibe-skeleton-app

This skill guides you through the complete ethical hacking lifecycle, teaching reconnaissance, scanning, exploitation, reporting, and professional security