Web Exploitation

Web application exploitation skill — offensive kill chain for confirming and exploiting vulnerabilities discovered during web recon. Activate when the user mentions exploiting, testing, or confirming vulnerabilities such as SQLi, XSS, LFI, RFI, SSRF, SSTI, XXE, broken access control, IDOR, JWT attacks, OAuth abuse, file upload bypass, deserialization, RCE, CSRF, or any variation of "exploit this endpoint", "test this param", or "web exploitation" after a recon phase. Picks up where web-recon leaves off — reuses recon output when available.

DouglasRao Updated

File contents

DouglasRao/Claude-Pentest-Skills/tree/main/skills/web-exploitation commit 9fe51c3474

Frequently asked questions

npx skillmds@latest add douglasrao/web-exploitation