mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Headless browser exploitation and Chrome DevTools Protocol attacks. Use for browser automation testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Headless browser exploitation and Chrome DevTools Protocol attacks. Use for browser automation testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Hidden parameter discovery and exploitation techniques. Use for parameter fuzzing and enumeration.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
HTTP Parameter Pollution for server-side and client-side exploitation. Use when testing parameter handling.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Insecure Direct Object Reference exploitation for authorization bypass. Use when testing access controls.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Java RMI exploitation and deserialization attacks. Use when testing Java RMI services.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
JWT attacks - none algorithm, key confusion, brute force, header injection. Use for JWT security testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
LaTeX injection for file read, command execution, and XSS. Use when testing LaTeX/PDF generation.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
LDAP injection for authentication bypass and data extraction. Use when testing LDAP integration.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Local/Remote File Inclusion with PHP wrappers, log poisoning, RCE techniques. Use for file inclusion testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Insecure management interface exploitation - admin panels, debug endpoints. Use for admin access testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Mass assignment exploitation for privilege escalation via ORM. Use when testing API parameter binding.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
NoSQL injection for MongoDB, CouchDB with operator injection and auth bypass. Use for NoSQL database testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
OAuth misconfiguration exploitation - redirecturi, state bypass, token theft. Use for OAuth flow testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Open redirect bypass techniques for phishing and token theft. Use when testing redirect functionality.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
ORM leak exploitation for data exposure via object-relational mapping. Use when testing ORM implementations.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Directory/path traversal with encoding bypasses for file system access. Use when testing file operations.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
LLM prompt injection, jailbreaks, and AI security testing. Use when testing AI/LLM applications.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
JavaScript prototype pollution for XSS and RCE in Node.js. Use for JavaScript security testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Race condition exploitation with HTTP/2 single-packet attacks. Use for concurrency testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Insecure randomness exploitation - predictable tokens, weak seeds. Use when testing token generation.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Regular expression attacks - ReDoS, injection, bypass techniques. Use when testing regex validation.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
HTTP request smuggling - CL.TE, TE.CL, HTTP/2 desync attacks. Use for proxy/CDN testing.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
Reverse proxy misconfiguration exploitation for access bypass. Use when testing proxy configurations.
mohdhaji87/payloadsallthethings-skills
Skill Claude CodeCodex
SAML injection and signature bypass for SSO exploitation. Use when testing SAML authentication.