Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By Esonhugh
Perform macOS security audits and exploitation including sandbox escape, TCC bypass, dylib injection, XPC attacks, kernel exploitation, and threat intelligence queries. Also debug interactive terminal-based tests using tmux.
npx claudepluginhub esonhugh/marketplace --plugin detectiveThis skill should be used when a user asks to debug an interactive CLI, REPL, TUI, prompt loop, shell wizard, watch mode, long-running terminal process, or any command that hangs, waits for input, redraws incorrectly, needs multiple inputs, behaves differently in a real terminal, or requires comparing tmux panes. Trigger on phrases like “it hangs after Continue?”, “the prompt never appears,” “my curses UI breaks in a small terminal,” “the watcher only fails after I answer the prompt,” or “inspect pane 2.”
macOS offensive security assistant — helps engineers audit applications for security vulnerabilities, identify bypass vectors in macOS security controls, and learn macOS internals through real-world case studies (CVEs). Covers: app vulnerability assessment (entitlement/injection/sandbox/TCC analysis), system internals, binary analysis, shellcode crafting (x64/ARM64), dylib injection, Mach IPC exploitation, function hooking, XPC attacks, sandbox escapes, TCC bypasses, symlink/hardlink attacks, kernel code execution, persistence mechanisms, Gatekeeper/XProtect bypass, AMFI/MACF internals, launch constraints, application-runtime injection (Electron/Chromium/NIB/.NET/Java/Python), IOKit/DriverKit driver attacks, MDM/DEP exploitation, keychain attacks, dangerous entitlements, and full penetration testing workflows. Use this skill whenever the user asks about: checking macOS apps for security issues, auditing entitlements or sandbox profiles, learning macOS security internals, macOS security research, macOS privilege escalation, bypassing SIP/TCC/Sandbox/Gatekeeper/AMFI, dylib injection or hijacking, Mach-O binary analysis, macOS shellcode (x64 or ARM64 Apple Silicon), XPC service vulnerabilities, KEXT loading exploits, macOS pentesting, Objective-C runtime exploitation, function interposing/hooking on macOS, Electron/Chromium/app injection on macOS, macOS persistence mechanisms, MDM/DEP attacks, keychain exploitation, IOKit driver attacks, or any CVE analysis related to macOS. Also trigger when the user mentions: codesign, entitlements, DYLD_INSERT_LIBRARIES, hardened runtime, __RESTRICT segment, AMFI, task_for_pid, Mach ports, method swizzling, SBPL sandbox profiles, TCC.db, LaunchDaemons/LaunchAgents, macOS kernel debugging, Gatekeeper, XProtect, quarantine, com.apple.quarantine, notarization, MAP_JIT, svc #0x1337, Dirty NIB, Electron fuses, MACF, launch constraints, trust cache, MDM, DEP, JAMF, keychain ACL, IOKit, DriverKit, EndpointSecurity, System Extensions, NVRAM boot-args, authorization database, BTM bypass, QuickLook generator, Automator workflow, or macOS red teaming. Even if the user doesn't explicitly mention "macOS security", trigger when they discuss topics like hooking system calls on macOS, analyzing Apple frameworks, reverse engineering macOS binaries, building exploits targeting Darwin/XNU systems, macOS malware analysis, Apple Silicon security, or when they want to understand how a specific macOS CVE works as a learning exercise.
微步在线威胁情报查询工具。支持IP、域名、文件哈希威胁情报查询,漏洞情报查询,资产测绘等功能。支持微信登录自动化和X语言高级搜索。当用户需要查询威胁情报、进行资产测绘或使用微步在线平台时,应使用此技能。
Share bugs, ideas, or general feedback.
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Generate minimal macOS Seatbelt sandbox configurations for applications
macOS-specific automation, sandbox workarounds, and system integration
Binary reverse engineering, malware analysis, firmware security, and software protection research for authorized security research, CTF competitions, and defensive security
macOS security hardening for Claude Code — PreToolUse/PostToolUse hooks that block secret exfiltration, prompt injection, persistence, and self-tampering.
860 on-demand security skills for CTF, pentest, bug bounty, DFIR, detection engineering, cloud, identity, and red/blue team work. Skills are plain Markdown and activate by task without permanently consuming context. Bundles vendored skills under mixed licenses (MIT, Apache-2.0, CC-BY-SA-4.0) — see per-source attribution in .claude/skills/SKILLS.md.
iOS/macOS app deployment via asc CLI — a lightweight fastlane alternative for TestFlight, App Store submission, signing, metadata, and analytics
Stealth browser automation skill using Pydoll, specialized in bypassing Cloudflare WAF, Turnstile CAPTCHA, and other bot detection systems.
Private Claude Code Plugin Marketplace by Esonhugh
English | 中文
This is Esonhugh's private Claude Code Plugin Marketplace — a curated collection of Claude Code plugins for security research, finance analysis, browser automation, reasoning frameworks, and productivity tools.
/plugin marketplace add Esonhugh/Marketplace
/plugin install <plugin-name>@Esonhugh-Marketplace
| Plugin | Category | Author | Source | Description |
|---|---|---|---|---|
| fofa-intel | Security | Esonhugh | local | FOFA cyberspace search engine — asset mapping & threat intel |
| threatbook-intel | Security | Esonhugh | skills | ThreatBook (微步) — IP/domain/hash threat intel with browser automation |
| macos-control-bypasser | Security | Esonhugh | skills | macOS offensive security — TCC bypass, sandbox escape, dylib injection |
| interactive-cli-systemic-debugging | Development | Esonhugh | skills | tmux workflow for debugging interactive CLI, REPL, TUI, and watch-mode processes |
| terminal-session-mcp | Development | Esonhugh | local | PTY terminal session MCP for long-running interactive CLI debugging and full transcript recording |
| pydoll-antibot-bypasser | Automation | Esonhugh | repo | Stealth browser automation bypassing Cloudflare WAF & CAPTCHA |
| ibkr-trade-analyzer | Finance | Esonhugh | repo | IBKR trading history analysis — P&L, portfolio, fees, Flex API + local import |
| detective | Reasoning | Esonhugh | local | Investigation-driven problem solving with evidence chains |
| video-extractor | Productivity | Esonhugh | repo | Video tutorial to Markdown — mlx-whisper + Vision OCR |
| tradingview | Finance | Esonhugh | repo | TradingView data access — quotes, options, screener, news, alerts |
| finance-market-analysis | Finance | himself65 | upstream | Earnings, correlation, ETF premium, SEPA strategy |
| document-skills | Productivity | Anthropic | upstream | Document processing — xlsx, docx, pptx, pdf |
| skill-creator | Development | Anthropic | upstream | Skill authoring and improvement tool |
| chrome-devtools-mcp | Development | Chrome DevTools Team | upstream | Chrome automation, debugging, network, console, and performance traces |
| frontend-design | Development | Anthropic | upstream | Production-grade frontend UI/UX design skill |
| superpowers | Development | Jesse Vincent | upstream | Brainstorming, TDD, debugging, code review, and skill authoring workflows |
| mattpocock-skills | Development | Matt Pocock | repo | Engineering and productivity skills including grill-me |
FOFA cyberspace search engine plugin. Bundles pre-compiled GoFOFA binaries for macOS/Linux/Windows — the fofa command is available immediately after installation with no manual PATH setup.
/plugin install fofa-intel@Esonhugh-Marketplace
Features:
| Capability | Command |
|---|---|
| Asset search by domain / IP / port / cert | fofa search |
| Bulk data export (millions of records) | fofa dump |
| Full host profile | fofa host |
| Field distribution statistics | fofa stats |
| Subdomain enumeration | fofa domains |
| Result count | fofa count |
Requirements: FOFA account + API Key (FOFA_KEY env var or ~/.config/gofofa/.env)