Pentest Fuzz Skill

Help with authorized Web pentest, Web fuzzing, and CTF-style vulnerability analysis. Use this skill whenever the user wants payload ideas, fuzz dictionaries, quick probe strings, test methodology, response-difference heuristics, or per-vulnerability checklists for common Web bugs such as SQL injection, XSS, SSTI, SSRF, XXE, file inclusion, IDOR, JWT weaknesses, deserialization, auth bypass, or command injection. Make sure to use it when the user asks how to test a Web bug, what characters or tokens to fuzz, how to organize notes by vulnerability type, or which vulnerability family a behavior most likely belongs to, even if they do not explicitly mention a skill.

m-sec-org 389123e 43 files · 22.8 KB Updated

File contents

m-sec-org/breachweave/tree/main/packages/core/src/config/skills/builtin/pentest-fuzz-skill commit 389123ee4c

Frequently asked questions

npx skillmds@latest add m-sec-org/pentest-fuzz-skill