auth-bypass
01Skill Claude CodeCodex
Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses.
An AI red-team agent for authorized labs and web app pentesting workflows. Turns Claude Code / OpenCode / Codex into a structured recon → test → exploit → report workflow, with containerized tools and resumable state.
Skill Claude CodeCodex
Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses.
Skill Claude CodeCodex
Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws.
Skill Claude CodeCodex
OS command injection detection, exploitation, and filter bypass.
Skill Claude CodeCodex
CORS misconfiguration testing for data theft and access control bypass.
Skill Claude CodeCodex
Cross-site request forgery testing for state-changing operations.
Skill Claude CodeCodex
Insecure deserialization detection and gadget chain exploitation.
Skill Claude CodeCodex
Discover hidden directories, files, and endpoints on a web server.
Skill Claude CodeCodex
Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution.
Skill Claude CodeCodex
File upload vulnerability testing — webshells, bypass, path traversal.
Skill Claude CodeCodex
GraphQL security testing — introspection, injection, auth bypass, DoS.
Skill Claude CodeCodex
Insecure direct object reference testing for broken access control.
Skill Claude CodeCodex
Information disclosure detection — error messages, files, headers, debug endpoints.
Skill Claude CodeCodex
JWT token attack techniques — alg bypass, key confusion, claim tampering.
Skill Claude CodeCodex
Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains.
Skill Claude CodeCodex
Open-source intelligence gathering — CVE lookup, breach search, DNS history, social profiling.
Skill Claude CodeCodex
Discover hidden parameters, test values, and identify input handling anomalies.
Skill Claude CodeCodex
Discover open ports, running services, and their versions on a target.
Skill Claude CodeCodex
Race condition and TOCTOU exploitation — parallel request attacks.
Skill Claude CodeCodex
Engagement report structure and formatting guidelines.
Skill Claude CodeCodex
HTTP request smuggling via CL.TE/TE.CL desync and cache poisoning.
Skill Claude CodeCodex
Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts.
Skill Claude CodeCodex
Frontend source code analysis for hidden routes, API endpoints, and secrets.
Skill Claude CodeCodex
Detect and exploit SQL injection vulnerabilities in web application parameters.
Skill Claude CodeCodex
Detect and exploit server-side request forgery to access internal resources and cloud metadata.