security-arsenal

Provide security payloads, bypass tables, and submission rules for bug bounty hunting.

1|Updated Jun 22, 2026
One-click install
npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill security-arsenal-0xhaaz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/0xhaaz/bug-bounty-toolkit/tree/main/skills/security-arsenal
Command: npx skills add https://github.com/0xhaaz/bug-bounty-toolkit --skill security-arsenal-0xhaaz

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the need for a one-stop security resource during bug bounty hunting, providing a wealth of payloads, bypass tables, and submission rules to aid in finding and validating vulnerabilities.

Core Features & Use Cases

  • Security Payloads: Offers a repository of payloads for various attack vectors like XSS, SSRF, SQLi, etc.
  • Bypass Techniques: Documents numerous bypass techniques to counteract security defenses.
  • Submission Rules: Provides guidelines for submitting findings effectively.

Quick Start

Use the security-arsenal skill to identify potential SQL injection vulnerabilities in your target.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
Where can I find a comprehensive list of payloads for vulnerability testing?

You can find security payloads for vulnerability testing in this repository, which covers attack vectors like XSS, SSRF, SQLi, XXE, NoSQLi, command injection, and SSTI to assist in identifying and validating findings.

How do I bypass security defenses during bug bounty hunting?

To bypass security defenses during bug bounty hunting, you can utilize documented bypass techniques and tables provided for countering filters in scenarios like XSS, SQLi, path traversal, HTTP smuggling, and MFA bypass.

What bypass techniques exist for HTTP smuggling and WebSocket vulnerabilities?

Bypass techniques for HTTP smuggling and WebSocket vulnerabilities are included as reference tables, assisting bug bounty hunters in validating findings and evading security defenses in these specific attack scenarios.

Do I need prior security knowledge to use these penetration testing payloads?

Yes, you need prior security knowledge to use these penetration testing payloads, as the repository requires familiarity with security concepts and vulnerability testing tools to effectively identify and validate findings.

How do I validate IDOR and path traversal findings?

You validate IDOR and path traversal findings by applying the specific security payloads and bypass tables provided, which assist in confirming vulnerabilities during your bug bounty hunting process.

What are the best ways to format bug bounty submission reports?

The best way to format bug bounty submission reports is to follow the provided submission rules, which offer guidelines for submitting vulnerability findings effectively after identifying and validating them.

Related Skills