PoC / exploit development (authorized targets)

SkillSecurity

Turn a known/1-day vulnerability or a raw bug into a working, reliable PoC for an authorized target. Load when a CVE/advisory needs weaponizing, a public PoC needs adapting, or "write an exploit/PoC". Signals: a versioned service with a known CVE, a crash/primitive to develop, searchsploit hits.

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the PoC / exploit development (authorized targets) skill

What this skill tells your AI

The instructions your AI receives, as published by noorqureshi/sploitagent in skills/exploit-dev/exploit-poc-development/SKILL.md and read by ahel’s review.

When it applies

You've identified a vulnerability (a versioned CVE, or your own discovered bug) and need a reliable proof-of-concept to demonstrate impact on an authorized target.

Why it works

A version+advisory tells you the root cause and the primitive; a methodical build turns that into repeatable code. For 1-days, most of the work is understanding and adapting, not inventing.

Method

  1. Identify precisely: exact product+version → advisory/CVE → root cause and affected code path. searchsploit <product version>; read the advisory and any public PoC.
  2. Understand before running: never fire an unread exploit at a target — read the code, know what it does (esp. anything destructive), and check it matches your exact version.
  3. Set up a local mirror when possible (same version in a VM/container) to develop safely.
  4. Build incrementally: reach the vulnerable code → trigger the primitive (leak/overwrite/ inject) → stabilize → deliver payload. For web, a clean scripted request chain; for binaries, pwntools with the leak→control→shell steps.
  5. Make it reliable & minimal: parameterize target/port, add checks, remove noise; it must reproduce for a report/triager.

Gotchas

  • Public PoCs are often broken, version-specific, or backdoored — read every line before running.
  • Match the exact version/build; an off-by-one minor version silently fails or crashes the service.
  • On live bug-bounty targets, prove the primitive without destructive payloads (no DoS/data loss).

Verify success

The PoC reproducibly demonstrates the vulnerability's impact (shell, read, auth bypass) against the authorized target/version, with clear steps.

References

Exploit-DB/searchsploit; pwntools docs; the vendor advisory/CVE for the specific bug.

Signals

GitHub stars
20
Forks
7
Last commit
Sep 2026
Advanced
Item type
skill
Key
exploit-poc-development
Source
github.com/noorqureshi/sploitagent