ssti-testing
25Skill Claude CodeCodex
Server-side template injection detection, engine identification, and RCE.
An AI red-team agent for authorized labs and web app pentesting workflows. Turns Claude Code / OpenCode / Codex into a structured recon → test → exploit → report workflow, with containerized tools and resumable state.
This repository also configures its own agents. See what RedteamAgent tells them →
Skill Claude CodeCodex
Server-side template injection detection, engine identification, and RCE.
Skill Claude CodeCodex
Subdomain discovery via subfinder, DNS brute-force, and passive sources.
Skill Claude CodeCodex
Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference.
Skill Claude CodeCodex
Enumerate web technologies, headers, endpoints, and metadata from a target.
Skill Claude CodeCodex
WebSocket security testing — injection, auth bypass, hijacking.
Skill Claude CodeCodex
Detect and exploit cross-site scripting vulnerabilities in web applications.
Skill Claude CodeCodex
XML external entity injection for file read, SSRF, and DoS.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: