Express Attack Probe

Authorized self-pentest probe targeting Express.js-specific weaknesses. Tests prototype pollution via merge/clone middlewares, HPP (HTTP parameter pollution) via body-parser, x-forwarded-for spoofing when trust proxy is loose, qs depth/array bombs, sendFile path traversal, and known unsafe middleware patterns. Use when the user asks to "pentest" or "attack-test" their own Express app.

Dolphinllc ee73758 4.9 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/offensive/web/express-attack-probe commit ee73758bb8

Frequently asked questions

npx skillmds@latest add dolphinllc/express-attack-probe