web security skills

95 tagged web security, measured the same way as everything else here.

Browse within: penetration-testing 69bugbounty 61reverse-engineering 61fuzzing 60reconnaissance 60skill-md 15owasp 10

cwe

01

0dayInc/pwn

Skill Claude CodeCodex

Exhaustively test a target against every applicable CWE.

76 3d ago A 14 tokens original MIT

osint

02

0dayInc/pwn

Skill Claude CodeCodex

Drive extroosint with the right kind, feeds, pivots, and keys.

76 3d ago A 21 tokens original MIT

penetration-testing

03

0dayInc/pwn

Skill Claude CodeCodex

Run a scoped pentest with NmapIt, Burp, Metasploit, and a written report.

76 3d ago A 26 tokens original MIT

vigolium-scanner

04

vigolium/skills

Skill Claude CodeCodex

Use when operating the vigolium CLI for web vulnerability scanning, security testing, or traffic analysis. Covers scanning a URL/spec/raw request, running AI agent scans (autopilot, swarm, audit, query), triaging findings, confirming them with replay/fuzz, handing off to Burp, browsing stored traffic, writing…

9 18d ago A 85 tokens

galact-byte/galact-Skills

Skill Claude CodeCodex

A security-testing guide for finding command injection, where user input is treated as part of an operating-system command or an external program's arguments. It covers web applications, APIs, and continuous-integration systems in authorized tests.

5 19d ago A 208 tokens

galact-byte/galact-Skills

Skill Claude CodeCodex

A security-testing skill for checking whether Node.js's built-in permission controls can be bypassed. It covers the current permission model and older policy files.

5 19d ago A 209 tokens

galact-byte/galact-Skills

Skill Claude CodeCodex

A security-testing triage guide for identifying a target’s attack surface—the features and components that could be exposed to attack—and choosing suitable tests.

5 19d ago A 162 tokens

withcrux/agentHack-skills

Skill Claude CodeCodex

Analyze JSON Web Tokens (JWTs) for common security vulnerabilities including algorithm confusion attacks (RS256 to HS256), none algorithm bypass, weak secret brute-forcing, and claim manipulation. Practice in isolated lab environments to understand authentication bypass and privilege escalation via token forgery.

5 4mo ago A 62 tokens

withcrux/agentHack-skills

Skill Claude CodeCodex

Detect reflected, stored, and DOM-based Cross-Site Scripting (XSS) vulnerabilities in web applications using manual payloads and browser-based analysis inside isolated lab environments. Covers OWASP A03 injection and sanitization bypass.

5 4mo ago A 57 tokens