Skill Claude CodeCodex
Exploit XMLRPC multicall, pingback for brute force and SSRF.
11 tagged rce, measured the same way as everything else here.
Skill Claude CodeCodex
Exploit XMLRPC multicall, pingback for brute force and SSRF.
Skill Claude CodeCodex
Detect insecure deserialization vulnerabilities in Java, Python (pickle), and PHP applications that allow remote code execution through crafted serialized objects. Covers gadget chain identification, ysoserial tool usage, and detection techniques in isolated lab environments. OWASP A08:2021.
Skill Claude CodeCodex
Deep white-box OSWE-style web application security audit. Invoke ONLY via the explicit /oswe:audit command. Detects stack and attack surface, traces source-to-sink vulnerabilities, chains them toward unauthenticated RCE under a proof contract, and writes a dated report to .oswe/reports/.