Security Arsenal

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, or to check if a finding is submittable. Also use when asked about what NOT to submit.

xiaolai cf649f7 28.3 KB Updated

File contents

xiaolai/claude-bughunter/tree/main/skills/security-arsenal commit cf649f7b0e

Frequently asked questions

npx skillmds@latest add xiaolai/security-arsenal