payload-library

Organize offensive security payloads and testing methodologies for web vulnerabilities.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/noname300989/Security-Claw --skill payload-library
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: payload-library
Source: https://github.com/noname300989/Security-Claw/tree/main/skills/payload-library
Command: npx skills add https://github.com/noname300989/Security-Claw --skill payload-library

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a comprehensive, organized library of offensive security payloads and methodologies, enabling security professionals to efficiently test for and exploit common web vulnerabilities.

Core Features & Use Cases

  • Vulnerability-Specific Payloads: Extensive lists of payloads for XSS, SQLi, SSRF, IDOR, Command Injection, XXE, and more, categorized by attack type and complexity (basic to WAF bypass).
  • Methodology Guides: Step-by-step instructions for testing each vulnerability class, including detection, exploitation, and validation.
  • Use Case: A penetration tester needs to exploit an SQL injection vulnerability on a target application. They can consult this Skill to find relevant SQLi payloads, understand the testing methodology, and even generate sqlmap commands tailored for WAF bypass.

Quick Start

Provide the payload-library skill with the vulnerability type 'XSS' and ask for WAF bypass techniques.

Frequently Asked Questions about payload-library

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is the best way to organize payloads for manual red teaming operations?

The best way to organize payloads for red teaming operations is using a comprehensive repository categorized by vulnerability class and complexity. This library structures offensive security payloads from basic to WAF bypass, streamlining manual testing workflows.

What payloads are available for SSRF and IDOR exploitation?

Payloads for SSRF and IDOR exploitation are available alongside methodologies for detecting and validating these flaws. The library supplies extensive lists of offensive security payloads categorized by attack type and complexity for manual penetration testing.

Can I generate sqlmap commands for SQL injection testing?

Yes, you can generate sqlmap commands tailored for WAF bypass during SQL injection testing. By consulting this library with the SQLi vulnerability type, you obtain relevant payloads, testing methodologies, and customized command generation for exploitation.

How do I test for JWT attacks and OAuth flaws during penetration testing?

To test for JWT attacks and OAuth flaws, this library provides step-by-step methodology guides covering detection, exploitation, and validation. It details offensive security payloads and testing methodologies specifically for these web vulnerability classes.

What is the best way to organize payloads for manual red teaming operations?

The best way to organize payloads for red teaming operations is using a comprehensive repository categorized by vulnerability class and complexity. This library structures offensive security payloads from basic to WAF bypass, streamlining manual testing workflows.