SkillMD SkillMD
Skills
All skills Official skills Leaderboard Saved
Categories
Coding & Dev Tools9772AI & ML5011DevOps & Infra2864Integrations & APIs2327Productivity2190Security1976 All categories →
Plugins Docs
menu-rounded
Skills Categories Plugins Docs My skills Saved
light-dark-mode
Profile My skills Saved Collections Edit profile Submit a skill
All Skills 25,791 ✦ Verified
Categories
AI & ML 5,011 Coding & Dev Tools 9,772 Data & Analytics 1,725 Design & Media 983 DevOps & Infra 2,864 Docs & Writing 1,294 Finance & Business 347 Integrations & APIs 2,327 Marketing & Growth 1,430 Product & Planning 1,037 Productivity 2,190 Research & Search 928 Security 1,976
Compliance & Privacy 210 Incident Response 321 Penetration Testing 283 Secrets Management 62 Secure Coding 300 Vulnerability Scanning 481
Web & Frontend 1,639

Results for “burp-suite”

75 skills
shulkwisec
authz-bypass
Test horizontal and vertical authorization bypass via session ID swapping between accounts, IDOR through parameter manipulation (invoice=, user=, menuitem=, EventID=), and special header injection (X-Original-URL, X-Rewrite-URL, X-Forwarded-For, X-Remote-IP, X-Client-IP with 127.0.0.1/localhost/RFC1918 values). Tools: Burp Suite with Autorize/AuthMatrix extensions, OWASP ZAP Access Control Testing add-on.
21
shulkwisec
xss-stored
Stored XSS (persistent XSS) occurs when attacker-supplied input is saved server-side and later rendered unencoded to other users. Common injection points include profile fields, comments, forum posts, file upload filenames, and application logs. Detect via PHP `$_GET/$_POST/$_REQUEST/$_FILES`, ASP `Request.Form`, JSP `request.getParameter`, and BeEF hook injection. Tools: Burp Suite, OWASP ZAP, BeEF, PHP Charset Encoder, Hackvertor.
21
shulkwisec
cors-misconfig
CORS misconfiguration allows attacker-controlled origins to read sensitive cross-origin responses when servers echo the `Origin` header in `Access-Control-Allow-Origin` or set it to `*` with `Access-Control-Allow-Credentials: true`. Detect via `Origin: https://attacker.com` reflection in `Access-Control-Allow-Origin` response header, wildcard `*` on credentialed endpoints, and null origin acceptance. Tools: OWASP ZAP, Burp Suite, manual `fetch()` with `credentials: include`.
21
← Prev
123
Next →
SKILLMD.com

The open registry of AI Agent Skills: safety-reviewed SKILL.md files for Claude, Cursor, Codex & 60+ agents.

$ npm i skillmds

Explore

All Skills Categories Agents Plugins New & Latest Leaderboard

Support

About Contact npm Terms Privacy

Learn

Docs Blog Stats FAQ Submit a Skill
© 2026 SkillMD.com Skills attributed to their authors under their original licenses.
SKILLMD