By SummerSec
Exploits Apache Shiro-550 (CVE-2016-4437) rememberMe deserialization vulnerability via CLI: automates key brute-force, gadget chain detection, command execution, memory shell injection, and key modification for single targets.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub summersec/shiroattack2 --plugin shiro-attack-cliShiroAttack2 — Shiro-550 漏洞利用工具:密钥爆破、Gadget 链探测、命令执行、内存马注入、Key 修改。
Makes Claude Code sessions expose a visible Inner OS monologue layer in the format ▎InnerOS:...
Analyze codebases and recommend tailored Claude Code automations such as hooks, skills, MCP servers, and subagents.
Cloudflare temp mail agent skill for reading inbox messages, fetching parsed mail, and sending email with an Address JWT.
Tools to maintain and improve CLAUDE.md files - audit quality, capture session learnings, and keep project memory current.
ShiroAttack2 — Shiro-550 漏洞利用工具:密钥爆破、Gadget 链探测、命令执行、内存马注入、Key 修改。
Complete offensive security operator workspace: 27 specialist agents, 6 engagement commands, 5 reference skill libraries, scope-gated hooks, and evidence logging for professional penetration testing and red-team operations.
The AI pentest co-pilot that actually finds bugs. Phase-chained, evidence-gated offensive security skills for bug bounty and authorized pentesting.
Offensive security toolkit for Claude Code — Neo4j intel graph, strategic compaction, multi-agent orchestration, and post-engagement debriefs
Claude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflows
82-skill bug-hunting & external red-team bundle for Claude Code — 57 hunt-* web/vuln-class + framework skills, enterprise platform attack chains (M365/Entra, Okta, SharePoint, vCenter, SSL-VPN, APK/iOS), recon/OSINT, reporting & validation gates, and Burp MCP integration. Skills auto-load by topic; 15 slash commands included.