npx claudepluginhub transilienceai/communitytoolsThis skill uses the workspace's default tool permissions.
Test for server-side vulnerabilities that allow unauthorized access, RCE, or data exfiltration.
reference/file-upload-cheat-sheet.mdreference/file-upload-quickstart.mdreference/file-upload-resources.mdreference/http-host-header-cheat-sheet.mdreference/http-host-header-quickstart.mdreference/http-host-header-resources.mdreference/http-request-smuggling-advanced.mdreference/http-request-smuggling-cheat-sheet.mdreference/http-request-smuggling-quickstart.mdreference/http-request-smuggling-resources.mdreference/http-request-smuggling.mdreference/insecure-deserialization-cheat-sheet.mdreference/insecure-deserialization-quickstart.mdreference/insecure-deserialization-resources.mdreference/path-traversal-cheat-sheet.mdreference/path-traversal-quickstart.mdreference/smuggling-authenticated.mdreference/ssrf-cheat-sheet.mdreference/ssrf-quickstart.mdGuides SSRF penetration testing in web apps: identifies URL input risks, exploits internal/cloud metadata access, blind SSRF via OOB, bypasses like IP tricks/DNS rebinding, checklists, and impact evaluation.
Identifies common web vulnerability patterns like SQL injection, command injection, XSS, and OWASP Top 10 during whitebox pentesting and code reviews.
References 100 critical web vulnerabilities by category with definitions, root causes, impacts, and mitigations. Useful for web security audits, testing, and remediation planning.
Share bugs, ideas, or general feedback.
Test for server-side vulnerabilities that allow unauthorized access, RCE, or data exfiltration.
| Type | Key Vectors |
|---|---|
| SSRF | Internal service access, cloud metadata, protocol smuggling |
| HTTP Smuggling | CL.TE, TE.CL, TE.TE, CL.0, H2.CL, h2c, multi-layer proxy chains, connection pooling desync |
| Path Traversal | Directory traversal, null bytes, encoding bypass |
| File Upload | Extension bypass, content-type manipulation, polyglot files |
| Deserialization | Java, PHP, Python, .NET gadget chains |
| Host Header | Password reset poisoning, cache poisoning, routing-based SSRF |
reference/ssrf*.md - SSRF techniques and labsreference/http-request-smuggling*.md - Smuggling techniquesreference/path-traversal*.md - Path traversal bypass methodsreference/file-upload*.md - File upload exploitationreference/insecure-deserialization*.md - Deserialization attacksreference/http-host-header*.md - Host header injection