Agent Skills by Bingo
Showing 104 vetted skills indexed across 1 GitHub repositories.
sql-injection-advanced
Automates detection and extraction of SQL injection vulnerabilities in web applications.
api_security
Discover and test vulnerabilities in RESTful APIs, GraphQL APIs, and JWT tokens.
auth_attack
Detect authentication vulnerabilities in web applications using Python.
web_vuln
Automate detection and exploitation of XSS, SSRF, LFI, SSTI, RCE, and XXE vulnerabilities in web applications.
WAF BYPASS MASTERY
Automate WAF bypass and penetration testing with SQL injection, XSS, and SSRF techniques.
file-access-vuln
Automate testing of file access and upload vulnerabilities in web applications.
dependency-confusion
Identify and analyze package manager dependency confusion vulnerabilities across ecosystems.
injection-checking
Route injection testing workflows based on input context.
cmdi-command-injection
Provide command injection payloads, bypass techniques, and blind detection strategies for web applications.
prototype-pollution
Detect prototype pollution vulnerabilities in JavaScript applications with payloads and patterns.
unauthorized-access-common-services
Exploit unauthenticated management services like Redis, Rsync, and PHP-FPM.
saml-sso-assertion-attacks
Validate SAML assertion signatures, audiences, recipients, and XML parsing.
api-sec
Categorize API security testing into recon, authorization, token, and parameter issues.
ssti-server-side-template-injection
Identify and exploit Server-Side Template Injection vulnerabilities across templating engines.
macos-process-injection
Provides macOS code injection via DYLD hijacking, XPC exploits, Mach ports, MIG abuse, and Electron targeting.
format-string-exploitation
Exploit format string vulnerabilities for stack reads and arbitrary writes.
http-host-header-attacks
Detects and mitigates Host header vulnerabilities in web applications.
steganography-techniques
Detect hidden data in images, audio, files, and text.
csv-formula-injection
Detect CSV and spreadsheet formula injection vulnerabilities across Excel, LibreOffice Calc, and Google Sheets.
defi-attack-patterns
Analyze DeFi protocols for flash loan, oracle, and governance attack patterns.
websocket-security
Detect and mitigate WebSocket security flaws using wsrepl, ws-harness, and Burp Suite.
graphql-and-hidden-parameters
Discover and exploit GraphQL API vulnerabilities via introspection and hidden parameters.
browser-exploitation-v8
Exploit JavaScript engine vulnerabilities in Chrome/Chromium via V8 JIT type confusion.
xxe-xml-external-entity
Detect and exploit XML External Entity vulnerabilities in XML-based systems.