Public Agent Skills by yaklang on Lightlines.
Provides a structured playbook for testing 401/403 bypasses through path, method, header, protocol, and combined techniques.
Guides testing of API authentication and JWT trust boundaries, including claims, headers, rate limits, and API keys.
Discovers reachable API entrypoints, schemas, role differences, versions, mobile paths, GraphQL endpoints, and undocumented parameters.
Routes API security issues to a deeper testing workflow based on the issue type.
Guides identification, classification, and removal of obfuscation from native binaries.
Routes authorized security work through an impact-first quality gate and observed-behavior methodology.
Tests applications and APIs for IDOR, BOLA, BFLA, and related authorization flaws.
Guides testing of JWT trust, signing, key handling, claims, bearer flows, and OAuth account binding.
Maps a target's assets, endpoints, technologies, and likely testing priorities for bug bounty work.
Guides advanced SQL injection validation, database-specific exploitation, data exfiltration, filter evasion, and operating-system escalation.
Guides advanced XSS testing with context-specific payloads, bypass techniques, and post-exploitation methods.