Deep Eye — Red Team Skill
SkillDev toolsLets your agent simulate attacker techniques against web apps and APIs for authorized security testing.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Deep Eye — Red Team Skill skill
About this capability
Red team / adversary simulation with Deep Eye for web/API footholds. Use for red team, adversary simulation, ATT&CK mapping, kill chain, /red-team. Authorized engagements only.
What this skill tells your AI
The instructions your AI receives, as published by zakirkun/deep-eye in .agents/skills/red-team/SKILL.md and read by ahel’s review.
Goal-driven simulation. Deep Eye = web/API recon and foothold sensor.
Preconditions
RoE (objectives, crown jewels, no-go, detection expectations), legal auth, OPSEC plan.
Kill chain (web-heavy)
Recon → Initial access (app) → Session/token abuse → Lateral (SSRF/cloud) → Objective
| Phase | Deep Eye |
|---|---|
| Recon | enable_recon, OpenAPI, crawl |
| Access | Core inject, file_upload |
| Authz | idor, api_bola_deep, jwt_deep |
| Pivot | ssrf_cloud, cloud_misconfig |
| Mobile | mobile.enabled + Frida/static modules |
python deep_eye.py -u https://APP --scope-nl "SCOPE" -v --formats json
Purple handoff
| TTP | Deep Eye evidence | Telemetry expected | Gap | Fix |
|---|
Rules
Stay in RoE; no third-party pivots; no destructive malware; log for debrief.
Signals
- GitHub stars
- 2k
- Forks
- 421
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
red-team-zakirkun- Source
- github.com/zakirkun/deep-eye