csrf-testing
73Skill Claude CodeCodex
CSRF testing covering token bypass, SameSite cookies, CORS misconfigurations, and state-changing request abuse.
Skill Claude CodeCodex
CSRF testing covering token bypass, SameSite cookies, CORS misconfigurations, and state-changing request abuse.
Skill Claude CodeCodex
Exhaustive security assessment with maximum coverage, depth, and vulnerability chaining.
Skill Claude CodeCodex
Insecure deserialization testing for Java, Python, PHP, .NET, Ruby, and Node.js covering gadget chains, type confusion, and safe validation.
Skill Claude CodeCodex
Security testing playbook for Django applications covering ORM injection, middleware gaps, auth/session flaws, and template issues.
Skill Claude CodeCodex
Rules of engagement, scope definition, and authorized penetration test planning.
Skill Claude CodeCodex
Security testing playbook for FastAPI applications covering ASGI, dependency injection, and API vulnerabilities.
Skill Claude CodeCodex
Skill "ffuf-tooling" from xAmirHamza77/PenKit51, covering ffuf tooling, deep exploitation guide, ffuf cli playbook, platform methodology and ffuf tooling.
Skill Claude CodeCodex
File upload security testing covering extension bypass, content-type manipulation, and path traversal.
Skill Claude CodeCodex
Firebase/Firestore security testing covering security rules, Cloud Functions, and client-side trust issues.
Skill Claude CodeCodex
GraphQL security testing covering introspection, resolver injection, batching attacks, and authorization bypass.
Skill Claude CodeCodex
HTTP header injection testing covering CRLF / response splitting, cache poisoning, Host-header confusion, cookie fixation, and proxy / forwarding header smuggling.
Skill Claude CodeCodex
HTTP request smuggling testing covering CL.TE, TE.CL, H2.CL, H2.TE, and HTTP/2 desync techniques with practical detection and exploitation methodology.
Skill Claude CodeCodex
ProjectDiscovery httpx probing syntax, exact probe flags, and automation-safe output patterns.
Skill Claude CodeCodex
IDOR/BOLA testing for object-level authorization failures and cross-account data access.
Skill Claude CodeCodex
A set of methods for responding to cybersecurity incidents, such as suspected attacks or other security events. The description does not specify particular tools or procedures.
Skill Claude CodeCodex
Information disclosure testing covering error messages, debug endpoints, metadata leakage, and source exposure.
Skill Claude CodeCodex
Katana crawler syntax, depth/js/known-files behavior, and stable concurrency controls.
Skill Claude CodeCodex
Kubernetes cluster security testing - RBAC, API exposure, container escapes, network policies, secrets, and supply chain.
Skill Claude CodeCodex
A guide to testing for LDAP injection vulnerabilities, where untrusted input changes a directory-service query. LDAP is a protocol commonly used to look up users and groups.
Skill Claude CodeCodex
Testing LLM-backed features for prompt injection, jailbreaks, system-prompt leakage, tool/agent abuse, and unsafe output handling.
Skill Claude CodeCodex
Mass assignment testing for unauthorized field binding and privilege escalation via API parameters.
Skill Claude CodeCodex
A set of methods for testing the security of mobile apps, such as apps for phones and tablets.
Skill Claude CodeCodex
Naabu port-scanning syntax with host input, scan-type, verification, and rate controls.
Skill Claude CodeCodex
Security testing playbook for NestJS applications covering guards, pipes, decorators, module boundaries, and multi-transport auth.