Attack Test

Fires abuse/hack paths over HTTP against a running stack (local/SIT) after the happy path works. Hunts money-moves, authz bypass, proof forge, and idempotency leaks; reports each finding with reproduce steps plus a fix that names the file/check to enforce. Use when the user says try hack, attack-test, probe the flow, security probe HTTP, or asks whether skipping step X still transfers or completes a protected action. Not for static latent hunts (`bug-hunter`), gate audits (`falsifying`), diff review (`code-review`), or AC-driven e2e (`e2e-playwright`).

witooh 9075fce 8.1 KB Updated

File contents

witooh/neo-plugin/tree/main/skills/attack-test commit 9075fceb0d

Frequently asked questions

npx skillmds@latest add witooh/attack-test