security-arsenal

Provide security payloads and bypass techniques for web application penetration testing.

3|Updated Nov 12, 2025
One-click install
npx skills add https://github.com/cmndcntrlcyber/rtpi --skill security-arsenal-cmndcntrlcyber
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/cmndcntrlcyber/rtpi/tree/main/knowledge_seed/bug_hunter_skills/security-arsenal
Command: npx skills add https://github.com/cmndcntrlcyber/rtpi --skill security-arsenal-cmndcntrlcyber

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a vast collection of security payloads, bypass tables, and wordlists to aid in penetration testing and vulnerability assessments, helping you identify and exploit security flaws in web applications.

Core Features & Use Cases

  • Payload Library: Offers a wide range of payloads for XSS, SSRF, SQLi, XXE, NoSQLi, command injection, SSTI, IDOR, and path traversal.
  • Bypass Techniques: Includes methods to bypass common security measures like CSP, WAF, and authentication.
  • Wordlists: Provides extensive lists for parameter fuzzing and password cracking.
  • Use Case: When performing a security audit, use this Skill to test for vulnerabilities like XSS or SSRF and gather evidence for a report.

Quick Start

Run the 'security-arsenal' skill to access the payload library and choose the appropriate payloads for your assessment.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find payloads for web application penetration testing?

This library provides payloads for web application penetration testing, offering specialized inputs for XSS, SSRF, SQLi, XXE, NoSQLi, command injection, SSTI, IDOR, and path traversal contexts.

What techniques can I use to bypass WAF and CSP during a vulnerability assessment?

This Skill provides bypass techniques for vulnerability assessments, offering dedicated tables and methods to circumvent common security measures like Web Application Firewalls and Content Security Policies.

How do I test for SSTI and IDOR vulnerabilities manually?

Manual SSTI and IDOR vulnerability testing requires selecting and applying specific payloads from this library to your target application contexts to identify and exploit security flaws.

Does this security arsenal include wordlists for parameter fuzzing?

This security arsenal includes extensive wordlists for parameter fuzzing, providing broad input lists to help identify exposed parameters and password cracking during audits.

Can I automate payload injection across multiple web applications?

You cannot automate payload injection across multiple web applications directly, as this library requires manual selection and application of specific payloads to individual application contexts.