Traction scoreGitHub stars can be faked, so popularity alone can be misleading. Traction Score looks for broader signs of real attention, adoption, and active maintenance.
This collection provides structured methodologies for security researchers and bug bounty hunters to test APIs, authentication mechanisms, and client-side applications. It transforms raw vulnerability hunting into a systematic process by detailing specific attack techniques for GraphQL, REST, and Web-LLM interfaces.
Beyond individual vulnerability testing, the tools enable the construction of attack path graphs to visualize multi-hop exploits across organizational assets. The repository also includes a design system for generating standardized threat intelligence reports.
WHO IT'S FOR
Bug bounty hunters
identifying vulnerabilities in APIs and client-side apps
Penetration testers
mapping multi-hop attack paths across organizations
Compatible AgentsThe repository documents support for these agents. The skills may also work with other agents that can load SKILL.md files, but they may need some setup or small changes.