ssti-jinja2
73Skill Claude CodeCodex
Guide Jinja2/Python server-side template injection exploitation during authorized penetration testing.
Offensive security toolkit for Claude Code
This repository also configures its own agents. See what red-run tells them →
Skill Claude CodeCodex
Guide Jinja2/Python server-side template injection exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide Twig/PHP server-side template injection exploitation during authorized penetration testing.
Skill Claude CodeCodex
Deploy WAR files via Apache Tomcat Manager for remote code execution. Use when Tomcat Manager is accessible with valid credentials (manager-script or manager-gui role). Covers WAR generation, deployment via text API and HTML interface, reverse shell delivery, and cleanup. Common initial access vector after credential…
Skill Claude CodeCodex
Discover web application injection points and route to the correct exploitation skill during authorized penetration testing.
Skill Claude CodeCodex
Guide DOM-based XSS exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide reflected XSS exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide stored (persistent) and blind XSS exploitation during authorized penetration testing.
Skill Claude CodeCodex
Guide XML External Entity (XXE) injection exploitation during authorized penetration testing.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: