csrf
49Skill Claude CodeCodex
Exploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.
Offensive security toolkit for Claude Code
This repository also configures its own agents. See what red-run tells them →
Skill Claude CodeCodex
Exploit Cross-Site Request Forgery (CSRF) vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Exploit .NET deserialization vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Exploit Java deserialization vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Exploit PHP deserialization vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Guide file upload restriction bypass during authorized penetration testing.
Skill Claude CodeCodex
Exploit Insecure Direct Object Reference (IDOR) and broken access control vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Exploit JWT (JSON Web Token) vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Exploit LDAP injection vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Guide Local File Inclusion (LFI) and Remote File Inclusion (RFI) exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide NoSQL injection exploitation during authorized penetration testing.
Skill Claude CodeCodex
Exploit OAuth 2.0 and OpenID Connect vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Exploit password reset vulnerabilities during authorized penetration testing.
Skill Claude CodeCodex
Exploit PHP code evaluation injection via eval(), assert(), pregreplace /e, createfunction(), calluserfunc(), usort() callbacks, and runtime function creation (runkit, uopz). Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct PHP code evaluation of user input.
Skill Claude CodeCodex
Exploit Python eval(), exec(), and compile() injection in web applications. Distinct from OS command injection (shell operators) and SSTI (template engines) — this targets direct Python code evaluation of user input.
Skill Claude CodeCodex
Exploit race conditions and TOCTOU vulnerabilities in web applications during authorized penetration testing.
Skill Claude CodeCodex
Guide HTTP request smuggling exploitation during authorized penetration testing.
Skill Claude CodeCodex
Deploy webshells to IIS, Apache, or Tomcat web roots via SMB share write access. Use when a domain user has write access to a file share that maps to a web server's document root — write a webshell via smbclient/net use, then trigger it via HTTP for RCE. Covers PHP, ASPX, and JSP webshells, .NET impersonation for…
Skill Claude CodeCodex
Security-focused source code review. Identifies hardcoded credentials, injection sinks, authentication weaknesses, and framework-specific vulnerabilities. Use when application source code is available for review.
Skill Claude CodeCodex
Guide blind SQL injection exploitation (boolean-based, time-based, and out-of-band) during authorized penetration testing.
Skill Claude CodeCodex
Guide error-based SQL injection exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide stacked query SQL injection and second-order injection exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide UNION-based SQL injection exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide server-side request forgery (SSRF) exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide Freemarker/Java server-side template injection exploitation during authorized penetration testing.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: