ok-helloworld
Review Skills published by ok-helloworld, their source repositories, maintenance signals, and identity status.
- Skills
- 3
- Repository stars
- 282
- Identity status
- Source-linked
Provenance
Source and identity
- Profile type
- Creator
- Canonical name
- ok-helloworld
- Public sources
- 1
- License context
- AGPL-3.0
Source entries
Agent Skills from ok-helloworld
Repository stars and maintenance signals provide context, but do not automatically become an individual Skill's quality score.
ok-helloworld/vibe-pentest
business-logic-vulnerabilities
Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.
ok-helloworld/vibe-pentest
ghost-bits-cast-attack
Java "Ghost Bits" / Cast Attack playbook (Black Hat Asia 2026). Use when attacking Java services where 16-bit char is silently narrowed to 8-bit byte to bypass WAF/IDS for SQL injection, deserialization RCE, file upload (Webshell), path traversal, CRLF injection, request smuggling, and SMTP injection. Affects Tomcat, Spring, Jetty, Undertow, Vert.x, Jackson, Fastjson, Apache Commons BCEL, Apache HttpClient, Angus Mail, JDK HttpServer, Lettuce, Jodd, XMLWriter and re-enables many "patched" CVEs t
ok-helloworld/vibe-pentest
sqli-sql-injection
SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.
Pinned paths
Every entry links to a specific source path and commit when available.
Repository context
Activity, license, and repository-level popularity are shown as context.
Open the source
Inspect the public repository