web-pentest
FeaturedUse when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-metadata, HTTP desync & cache poisoning, SSTI/prototype-pollution/deserialization, JWT/OAuth/GraphQL/IDOR, business logic & single-packet race
Install
Quality Score: 95/100
Skill Content
Details
- Author
- hypnguyen1209
- Repository
- hypnguyen1209/offensive-claude
- Created
- 4 months ago
- Last Updated
- 5 days ago
- Language
- Python
- License
- MIT
Integrates with
Bundled in these plugins
Similar Skills
Semantically similar based on skill content — not just same category
awesome-pentest
Runs a penetration test (web app, API, network, cloud, mobile) per PTES and OWASP: scoping, recon, testing, proof, CWE/CVSS findings, retest; every active probe needs written authorization. Use for a pentest or red team engagement.
security-testing
Use for authorized security/penetration testing of web apps and APIs — OWASP Top 10 checks, auth/session testing, header/config audits, and vulnerability triage. Only for systems the user owns or has explicit authorization to test.
pentest-lyan
Perform dynamic security validation on explicitly authorized web targets, covering authentication, authorization, object ownership, tenant isolation, state transitions, and business rules, and reach strict conclusions using reproducible evidence, verified impact, and structured state. Use when the user provides an authorized web target and asks for penetration testing, a vulnerability assessment, or validation of web security boundaries. Do not use for unauthorized targets, social engineering, mobile-only testing, infrastructure scanning, or general security advice without a concrete authorized web target.