skills/web-hunting
22 skills

Web Hunting

Deep-dive skills for SQL injection, XSS, SSRF, RCE, business logic, and 15+ other web vulnerability classes — each built from real bug bounty reports.

/hunt-sqliBoth ✓
SQLi Hunter
SQL and NoSQL injection across ORM raw fragments, GraphQL resolvers, OIDC-proxy backends, and SOQL. Built from 12 disclosed reports including CVE-2021-22911 and CVE-2024-53900.
12 reports
/hunt-xssBoth ✓
XSS Hunter
Cross-site scripting across DOM, reflected, stored, and mutation-based patterns. Built from 174 public bug bounty reports.
174 reportsdemo
/hunt-ssrfBoth ✓
SSRF Hunter
Server-side request forgery including cloud metadata endpoint exfiltration, internal network pivoting, and webhook abuse patterns.
/hunt-rceBoth ✓
RCE Hunter
Remote code execution via deserialization, template injection, command injection, and unsafe eval patterns derived from real disclosures.
/hunt-idorBoth ✓
IDOR Hunter
Insecure direct object references including BOLA in REST/GraphQL, ID enumeration, and horizontal privilege escalation. Built from 26 reports.
26 reports
/hunt-csrfBoth ✓
CSRF Hunter
Cross-site request forgery including SameSite bypass, token fixation, and JSON-based CSRF in single-page apps.
demo
/hunt-sstiBoth ✓
SSTI Hunter
Server-side template injection across Jinja2, Twig, Freemarker, Velocity, and Pebble with RCE escalation paths.
/hunt-xxeBoth ✓
XXE Hunter
XML external entity injection including blind OOB exfiltration, file read via error messages, and XXE-to-SSRF chains.
/hunt-file-uploadBoth ✓
File Upload Hunter
Unrestricted file upload bypasses — MIME type spoofing, extension trickery, polyglots, path traversal via filename.
/hunt-cache-poisonBoth ✓
Cache Poison Hunter
Web cache poisoning via unkeyed headers, parameter cloaking, fat GET exploitation, and cache-key normalization bugs.
/hunt-http-smugglingLimited ⚠
HTTP Smuggling Hunter
HTTP request smuggling — CL.TE, TE.CL, TE.TE variants with bypass and response queue poisoning escalation.
/hunt-race-conditionLimited ⚠
Race Condition Hunter
Race condition exploitation on payment flows, coupon redemption, rate-limit bypass, and parallel request amplification.
/hunt-business-logicBoth ✓
Business Logic Hunter
Business logic flaws — price manipulation, workflow bypass, state machine abuse, and trust boundary violations.
/hunt-graphqlBoth ✓
GraphQL Hunter
GraphQL introspection abuse, batching attacks, IDOR through aliases, nested query DoS, and authorization bypass.
/hunt-llm-aiBoth ✓
LLM/AI Hunter
LLM-integrated application vulnerabilities — prompt injection, insecure tool use, training data extraction, and model denial of service.
/hunt-dispatchLimited ⚠
Dispatch Hunter
Smart target triage and hunting path dispatch — routes to the right skill based on reconnaissance signals.
/hunt-miscBoth ✓
Misc Vuln Hunter
Catch-all for open redirect, CRLF injection, clickjacking, host header injection, and other frequently disclosed low-to-medium classes.
/hunt-aspnetBoth ✓
ASP.NET Hunter
ASP.NET-specific attack surface — ViewState deserialization, __EVENTTARGET manipulation, IIS short filename disclosure, and Razor injection.
/bug-bountyBoth ✓
Bug Bounty Planner
Structured methodology for scoping, prioritizing, and executing a bug bounty engagement from program selection to final submission.
/bb-methodologyBoth ✓
BB Methodology
End-to-end bug bounty methodology — recon, attack surface mapping, vulnerability testing order, and triage workflow.
/bb-local-toolkitLimited ⚠
Local Toolkit
Local toolchain setup for bug bounty — ffuf, nuclei, sqlmap, burp configurations, and wordlist management.
/security-arsenalBoth ✓
Security Arsenal
Curated command arsenal for web security testing — one-liner reference for recon, fuzzing, exploitation, and post-exploitation.

Ready to install your first skill? Start in minutes.

Browse all 8 attack domains — 51 specialized skills, MIT licensed.

Browse all 8 domainsRead the install guide

Works with Claude Free, Pro, Teams, and Enterprise · MIT License