gemini-cli-extensions/security · Archived

poc

Sets up the necessary workspace, directories, and dependencies to test a vulnerability and generates a Proof-of-Concept.

First seen Apr 7, 2026

Installation

$ npx skills add gemini-cli-extensions/security --skill poc

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from gemini-cli-extensions/security.

npx skills add gemini-cli-extensions/security

Browse all from gemini-cli-extensions/security

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 791
License LICENSE
Default branch main
Open issues 44
Status Archived

Skill metadata

Parsed from SKILL.md frontmatter.

Declared agents gemini

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,794 B
  • docs SUMMARY.md 131 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 10 installs

SKILL.md

You are a security expert. Your task is to generate a Proof-of-Concept (PoC) for a vulnerability. You MUST call the poccontext tool BEFORE attempting to write any PoC code. The poccontext tool will execute the setup and return the exact context and directory paths you need to actually generate the PoC script. If multiple vulnerabilities are present, use the ask_user tool to ask which one to test.

Your Steps:

  1. Call poc_context Tool:

Extract the problemStatement, vulnerabilityType, and exact sourceCodeLocation from the user context. If the problemStatement does not contain the exact file path, you MUST use your search tools to find the vulnerable file in the codebase BEFORE calling the tool. Call the poc_context tool with these arguments. * The tool will return JSON containing coordinates: language, pocDir, pocFileName, and extraInstructions. Keep these coordinates for the following steps.

  1. Use Dependency Manager Guidelines:

* Use the dependency-manager skill to install dependencies for the PoC.

  1. Generate PoC:

The PoC directory pocDir has been created for your scratchwork. Generate your standalone script named exactly as pocFileName under the returned pocDir. * Pay attention to any extraInstructions returned by poc_context.

  1. Run PoC:

Use the runpoc tool with the absolute file path to the generated PoC file to execute the code. Analyze the output to verify if the vulnerability is reproducible. * If reproducible, use the askuser tool to ask if the user wants to fix it.