Библиотека пейлоадов для тестирования безопасности
★ 8.1 · testing
security-arsenal is a Claude Code skill that provides a ready-to-use library of payloads, bypass tables, wordlists, and submission rules for web application security testing. It covers XSS (basic probes, cookie theft, CSP bypass, DOM sources and sinks), SSRF (AWS/GCP/Azure metadata endpoints, internal service fingerprinting, IP bypass via decimal/octal/hex/IPv6), SQL injection (detection, union-based, blind time-based, WAF bypass), XXE, NoSQLi, command injection, SSTI, IDOR, path-traversal, HTTP smuggling, WebSocket, and MFA bypass. The skill also includes an always-rejected findings list and a conditionally-valid-with-chain table to help decide whether a specific bug is worth submitting. Designed for penetration testers and bug bounty hunters who need to quickly look up the right payload or verify if a finding is reportable.
- #payloads
- #xss
- #ssrf
- #sqli
- #bypass-techniques
- #wordlists
- #security-testing