All authors

Claude Skills by ajtazer
github.com/ajtazer207 skills4 installs326 views
- Offensive SstiSSTI exists wherever user-controlled input is concatenated into a server-sideVotes: 0GitHub stars: 2
- Offensive XssCross-Site Scripting testing checklist: stored/reflected/DOM/blind XSS discovery, polyglot payloads, CSP bypass, XSS filter bypass, event handler injection, DOM clobbering, mutation XSS, and impact escalation (session hijack, phishing, keylogging). Use for web app XSS testing and bug bounty.Votes: 0GitHub stars: 2
- Offensive XxeXML External Entity injection testing checklist: classic XXE, blind XXE (out-of-band), XXE via file upload (SVG/docx), XXE in SOAP/REST, error-based XXE, XInclude attacks, and XXE filter bypass. Use for web app XXE testing and bug bounty.Votes: 0GitHub stars: 2
- Web 2fa BypassYou are helping a penetration tester bypass two-factor authentication. TheVotes: 0GitHub stars: 2
- Web Ajp GhostcatYou are helping a penetration tester exploit Apache JServ Protocol (AJP)Votes: 0GitHub stars: 2
- Web Browser ExploitationYou are helping a penetration tester exploit browser-based attack surfaces. ThisVotes: 0GitHub stars: 2
- Web Command InjectionYou are helping a penetration tester exploit OS command injection. The targetVotes: 0GitHub stars: 2
- Web Cors MisconfigurationYou are helping a penetration tester exploit Cross-Origin Resource SharingVotes: 0GitHub stars: 2
- Web CsrfYou are helping a penetration tester exploit CSRF vulnerabilities. The targetVotes: 0GitHub stars: 2
- Web Deserialization DotnetYou are helping a penetration tester exploit .NET deserializationVotes: 0GitHub stars: 2
- Web Deserialization JavaYou are helping a penetration tester exploit Java deserializationVotes: 0GitHub stars: 2
- Web Deserialization PhpYou are helping a penetration tester exploit PHP deserializationVotes: 0GitHub stars: 2
- Web File Upload BypassYou are helping a penetration tester bypass file upload restrictions to achieveVotes: 0GitHub stars: 2
- Web IdorYou are helping a penetration tester exploit Insecure Direct Object ReferenceVotes: 0GitHub stars: 2
- Web Jwt AttacksYou are helping a penetration tester exploit JWT (JSON Web Token)Votes: 0GitHub stars: 2
- Web Ldap InjectionYou are helping a penetration tester exploit LDAP injection vulnerabilities.Votes: 0GitHub stars: 2
- Web LfiYou are helping a penetration tester exploit file inclusion vulnerabilities. TheVotes: 0GitHub stars: 2
- Web Nosql InjectionYou are helping a penetration tester exploit NoSQL injection vulnerabilities.Votes: 0GitHub stars: 2
- Web Oauth AttacksYou are helping a penetration tester exploit OAuth 2.0 and OpenID ConnectVotes: 0GitHub stars: 2
- Web Password Reset PoisoningYou are helping a penetration tester exploit password reset vulnerabilities.Votes: 0GitHub stars: 2
- Web Php Code InjectionYou are helping a penetration tester exploit PHP code injection where user inputVotes: 0GitHub stars: 2
- Web Python Code InjectionYou are helping a penetration tester exploit Python code injection via eval(),Votes: 0GitHub stars: 2
- Web Race ConditionYou are helping a penetration tester exploit race conditions and TOCTOUVotes: 0GitHub stars: 2
- Web Request SmugglingYou are helping a penetration tester exploit HTTP request smugglingVotes: 0GitHub stars: 2
- Web Smb Share WebshellYou are helping a penetration tester deploy webshells to web server documentVotes: 0GitHub stars: 2
- Web Source Code ReviewYou are a vulnerability researcher reviewing application source code forVotes: 0GitHub stars: 2
- Web Sql Injection BlindYou are helping a penetration tester exploit blind SQL injection. The targetVotes: 0GitHub stars: 2
- Web Sql Injection ErrorYou are helping a penetration tester exploit error-based SQL injection. TheVotes: 0GitHub stars: 2
- Web Sql Injection StackedYou are helping a penetration tester exploit stacked query SQL injectionVotes: 0GitHub stars: 2
- Web Sql Injection UnionYou are helping a penetration tester exploit UNION-based SQL injection. TheVotes: 0GitHub stars: 2
- Web SsrfYou are helping a penetration tester exploit server-side request forgery. TheVotes: 0GitHub stars: 2
- Web Ssti FreemarkerYou are helping a penetration tester exploit server-side template injection in aVotes: 0GitHub stars: 2
- Web Ssti Jinja2You are helping a penetration tester exploit server-side template injection in aVotes: 0GitHub stars: 2
- Web Ssti TwigYou are helping a penetration tester exploit server-side template injection in aVotes: 0GitHub stars: 2
- Web Tomcat Manager DeployYou are helping a penetration tester exploit authenticated access to ApacheVotes: 0GitHub stars: 2
- Web Web DiscoveryYou are helping a penetration tester discover vulnerabilities in a webVotes: 0GitHub stars: 2
- Web Xss DomYou are helping a penetration tester exploit DOM-based cross-site scripting. TheVotes: 0GitHub stars: 2
- Web Xss ReflectedYou are helping a penetration tester exploit reflected cross-site scripting. TheVotes: 0GitHub stars: 2
- Web Xss StoredYou are helping a penetration tester exploit stored (persistent) cross-siteVotes: 0GitHub stars: 2
- Web XxeYou are helping a penetration tester exploit XXE injection. The target applicationVotes: 0GitHub stars: 2
- Advisory MiningMine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.Votes: 0GitHub stars: 2
- Auth BypassDetect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.Votes: 0GitHub stars: 2
- Code Injection CodegenDetect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.Votes: 0GitHub stars: 2
- Command InjectionDetect OS command injection via shell execution sinks where user-controlled input reaches system commands without proper sanitization.Votes: 0GitHub stars: 2
- Cross PollinationCross-pollination multiplier technique: find a vulnerability in one package, then search for the same pattern across all similar packages to multiply findings.Votes: 0GitHub stars: 2
- Cve Hunting MethodologyCross-cutting methodology for the CVE-hunting pipeline (ported from find-cve-agent): when a bug is design-vs-real, false-positive avoidance, version checking before reporting, responsible disclosure norms, acceptance-rate expectations per vuln class, vulnerability chaining playbook, known false-positive patterns, maintainer-response patterns, secure-pattern reference (what NOT to flag), and a self-criticism checklist to run before claiming a finding. Use this alongside the cve-hunter/cve-expl...Votes: 0GitHub stars: 2
- Decompression BombDetect decompression bomb vulnerabilities where compressed input can expand to exhaust memory, targeting buffer-based decompression without size limits.Votes: 0GitHub stars: 2
- Entity ExpansionDetect XML/SVG/YAML entity expansion (Billion Laughs) vulnerabilities in parsers that allow unbounded entity definitions.Votes: 0GitHub stars: 2
- Fp CheckSystematic false positive elimination for security findings. 6-gate verification, 13-item checklist, devil's advocate questioning. MANDATORY before any CVE submission.Votes: 0GitHub stars: 2
- Method ClobberingDetect method clobbering via user-controlled object keys that overwrite built-in methods like toString, valueOf, or hasOwnProperty, causing crashes or logic bypass.Votes: 0GitHub stars: 2