security-arsenal

Centralize offensive security payloads and submission guidelines for bug bounty testing.

1|1|Updated Mar 24, 2026
One-click install
npx skills add https://github.com/guib1/red-team-docker --skill security-arsenal
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/guib1/red-team-docker/tree/main/pentest-lab/.agents/skills/bug-bounty/skills/security-arsenal
Command: npx skills add https://github.com/guib1/red-team-docker --skill security-arsenal

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security testers often hunt for multiple classes of vulnerabilities using disparate payloads and reference materials. This Skill collects and organizes payloads, bypass techniques, and submission rules into a single, auditable resource to accelerate testing and triage.

Core Features & Use Cases

  • Comprehensive payload library: XSS, SSRF, SQLi, XXE, NoSQLi, path traversal, HTTP smuggling, WebSocket, MFA bypass, and related attack patterns.
  • Submission rules and best practices: Guidance on what to submit and how to document findings to maximize triage efficiency.
  • Reference-driven testing: Access to curated lists and patterns to validate findings and avoid false positives in bug bounty programs.

Quick Start

Run the security-arsenal skill to load payloads and references for immediate testing.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
Where can I find a comprehensive payload library for XSS, SQLi, and XXE bug bounty testing?

A centralized payload library for XSS, SQLi, and XXE testing provides organized payloads and bypass patterns to accelerate vulnerability validation and avoid false positives in bug bounty programs.

How do I organize offensive security payloads and submission guidelines for bug bounty triage?

Organize offensive security payloads and submission guidelines by centralizing vulnerability workflows and documentation rules into an auditable resource to maximize triage efficiency.

Does this payload collection cover HTTP smuggling, WebSocket, and MFA bypass workflows?

Yes, the payload collection covers HTTP smuggling, WebSocket, and MFA bypass workflows alongside SSRF, NoSQLi, and path traversal attack patterns for comprehensive testing.

What is the best way to access bypass techniques for multiple vulnerability classes during testing?

The best way to access bypass techniques is using a reference-driven resource that curates lists and patterns for multiple vulnerability classes to validate findings accurately.

How do I document bug bounty findings to maximize triage efficiency?

Document bug bounty findings by following curated submission rules and best practices that specify what to submit and how to structure reports for triage teams.

Can I use these security payloads for NoSQLi and path traversal vulnerability validation?

Yes, you can use these security payloads for NoSQLi and path traversal testing to validate findings and avoid false positives across related vulnerability workflows.