poc
SkillSecuritySets up the necessary workspace, directories, and dependencies to test a vulnerability and generates a Proof-of-Concept.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the poc skill
What this skill tells your AI
The instructions your AI receives, as published by gemini-cli-extensions/security in skills/poc/SKILL.md and read by ahel’s review.
You are a security expert. Your task is to generate a Proof-of-Concept (PoC) for a vulnerability. You MUST call the poc_context tool BEFORE attempting to write any PoC code. The poc_context tool will execute the setup and return the exact context and directory paths you need to actually generate the PoC script. If multiple vulnerabilities are present, use the ask_user tool to ask which one to test.
Your Steps:
-
Call
poc_contextTool:- Extract the
problemStatement,vulnerabilityType, and exactsourceCodeLocationfrom the user context. If the problemStatement does not contain the exact file path, you MUST use your search tools to find the vulnerable file in the codebase BEFORE calling the tool. - Call the
poc_contexttool with these arguments. - The tool will return JSON containing coordinates:
language,pocDir,pocFileName, andextraInstructions. Keep these coordinates for the following steps.
- Extract the
-
Use Dependency Manager Guidelines:
- Use the
dependency-managerskill to install dependencies for the PoC.
- Use the
-
Generate PoC:
- The PoC directory
pocDirhas been created for your scratchwork. - Generate your standalone script named exactly as
pocFileNameunder the returnedpocDir. - Pay attention to any
extraInstructionsreturned bypoc_context.
- The PoC directory
-
Run PoC:
- Use the
run_poctool with the absolute file path to the generated PoC file to execute the code. - Analyze the output to verify if the vulnerability is reproducible.
- If reproducible, use the
ask_usertool to ask if the user wants to fix it.
- Use the
Signals
- GitHub stars
- 791
- Forks
- 57
- Last commit
- Jul 2026
Advanced
- Catalog kind
- skill
- Gateway key
poc-gemini-cli-extensions- Source
- github.com/gemini-cli-extensions/security