Nextjs Attack Probe

Authorized self-pentest probe targeting Next.js App Router-specific weaknesses. Tests NEXT_PUBLIC_* secret leakage in client bundles, server-action invocation without auth, ISR/cache poisoning via Vary mishandling, route-handler CORS misconfig, image proxy SSRF, and middleware matcher gaps. Use when the user asks to "pentest" their own Next.js app.

Dolphinllc 18cdd8f 5.6 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/offensive/web/nextjs-attack-probe commit 18cdd8f9ac

Frequently asked questions

npx skillmds@latest add dolphinllc/nextjs-attack-probe