Библиотека пейлоадов для тестирования безопасности

★ 8.1 · testing

security-arsenal is a Claude Code skill that provides a ready-to-use library of payloads, bypass tables, wordlists, and submission rules for web application security testing. It covers XSS (basic probes, cookie theft, CSP bypass, DOM sources and sinks), SSRF (AWS/GCP/Azure metadata endpoints, internal service fingerprinting, IP bypass via decimal/octal/hex/IPv6), SQL injection (detection, union-based, blind time-based, WAF bypass), XXE, NoSQLi, command injection, SSTI, IDOR, path-traversal, HTTP smuggling, WebSocket, and MFA bypass. The skill also includes an always-rejected findings list and a conditionally-valid-with-chain table to help decide whether a specific bug is worth submitting. Designed for penetration testers and bug bounty hunters who need to quickly look up the right payload or verify if a finding is reportable.