security-arsenal

Provide security payloads and bypass techniques for web application vulnerabilities.

5|Updated May 27, 2026
One-click install
npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill security-arsenal-cybersecwoman
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/cybersecwoman/Kiro-BugHunter/tree/main/skills/security-arsenal
Command: npx skills add https://github.com/cybersecwoman/Kiro-BugHunter --skill security-arsenal-cybersecwoman

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill unit provides a vast library of security payloads, bypass techniques, and submission rules for various security vulnerabilities, helping users identify and exploit weaknesses in web applications.

Core Features & Use Cases

  • Security Payloads: Offers a wide range of payloads for XSS, SSRF, SQLi, XXE, NoSQLi, command injection, SSTI, IDOR, and path traversal.
  • Bypass Techniques: Includes methods to bypass common security defenses like CSP, WAF, and MFA.
  • Submission Rules: Provides guidelines on what findings are valid to submit and what to avoid to maintain report credibility.
  • Use Case: When testing a web application, this Skill unit can be used to craft specific payloads for different types of vulnerabilities, bypass security measures, and validate findings.

Quick Start

Use the security-arsenal skill to generate bypass techniques for a potential XSS vulnerability in the application.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate payloads for testing web application vulnerabilities like XSS and SQL injection?

To generate security payloads for testing vulnerabilities like XSS and SQL injection, this Skill provides a vast library of payloads and bypass techniques for various web application flaws including XSS, SSRF, SQLi, and XXE.

What techniques can I use to bypass WAF and CSP protections during security testing?

For bypassing WAF and CSP protections, this Skill includes specific bypass techniques designed to circumvent common web application security defenses like Content Security Policy and Web Application Firewalls.

Do I need prior security knowledge to use these web vulnerability payload libraries?

Yes, you need prior knowledge of security testing and an understanding of common web vulnerabilities to effectively use these payload libraries and bypass techniques for finding application weaknesses.

What are the submission rules for validating discovered web application vulnerabilities?

Submission rules for validating discovered vulnerabilities provide guidelines on what findings are valid to submit and what to avoid, ensuring your security reports maintain credibility during testing.

Can I find bypass methods for SSTI, IDOR, and path traversal vulnerabilities in one place?

Yes, you can find bypass methods and payloads for SSTI, IDOR, and path traversal in one place, as this Skill consolidates techniques for these specific web application vulnerabilities alongside others.