Skip to content

Built-in Skills

Dalang ships with 22 built-in security skills covering network, web, cloud, and container security.

Network Reconnaissance

SkillToolDescription
nmap_scannernmapPort scanning with service version detection
masscan_fastmasscanExtremely fast full-port scanning (requires root)
rustscan_auditrustscanModern fast port scanning with nmap service handoff

Web Application Security

SkillToolDescription
web-auditBrowser (CDP)Client-side DOM analysis and vulnerability detection
ffuf_fuzzerffufDirectory and file fuzzing for hidden endpoints
gobuster_dirgobusterDirectory and file brute-forcing for content discovery
sqlmap_testersqlmapAutomated SQL injection detection and validation
xss_strikeXSStrikeAdvanced cross-site scripting detection and fuzzing
nikto_scannerniktoComprehensive web server vulnerability scanner
header_analyzercurlHTTP security header analysis (HSTS, CSP, X-Frame-Options)
ssl_scansslscanTLS/SSL configuration audit (weak ciphers, protocol versions)
jwt_analysisBrowser (JS)JWT token extraction and security analysis

CMS & Framework Specific

SkillToolDescription
wpscan_auditwpscanWordPress vulnerability scanning

Credential Testing

SkillToolDescription
hydra_bruteforcehydraCredential strength testing for network protocols

Cloud & Infrastructure

SkillToolDescription
kubectl_auditkubectlKubernetes cluster permission and security review
aws_cli_enumaws-cliAWS resource enumeration (S3, IAM)
docker_escape_checkcapshContainer escape vulnerability and capability check

Discovery & Enumeration

SkillToolDescription
nuclei_vuln_scannucleiTemplate-based CVE and misconfiguration scanning
subdomain_enumsubfinderPassive subdomain enumeration for attack surface
smbclient_enumsmbclientSMB share and null session enumeration
snmpwalk_gathersnmpwalkSNMP misconfiguration information gathering

Utility

SkillToolDescription
testing-skillDummy skill for development testing

Released under the MIT License.