security-arsenal

Provide offensive security payloads and bypass techniques for manual penetration testing.

3|1|Updated Jul 2, 2026
One-click install
npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill security-arsenal-entrovyx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/EntroVyx/hermes-agent-offsec/tree/main/skills/offsec/redteam/security-arsenal
Command: npx skills add https://github.com/EntroVyx/hermes-agent-offsec --skill security-arsenal-entrovyx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides a centralized, vetted repository of security payloads, bypass techniques, and submission rules, preventing the use of stale or ineffective methods during offensive security engagements.

Core Features & Use Cases

  • Payload Library: Access verified payloads for XSS, SSRF, SQLi, XXE, and more, including specific bypass techniques for modern WAFs and filters.
  • Submission Guidance: Utilize the Always Rejected and Conditionally Valid tables to ensure findings meet high-impact criteria before reporting.
  • Use Case: When testing a potential SSRF vulnerability, use this skill to quickly retrieve cloud metadata probes or DNS rebinding payloads to confirm impact and bypass internal filters.

Quick Start

Use the security-arsenal skill to provide the latest bypass payloads for a blind SQL injection vulnerability on a MySQL target.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find effective bypass payloads for modern WAFs during a pentest?

To find effective WAF bypass payloads during a pentest, utilize a centralized security payload library that provides vetted injection techniques and filter evasion methods across diverse technology stacks.

What is the best way to confirm blind vulnerability impact for bug bounty submissions?

The best way to confirm blind vulnerability impact for bug bounty submissions is using established out-of-band (OOB) confirmation methods and cloud metadata probes to verify the finding before reporting.

How does an impact-driven hunting approach improve security vulnerability submissions?

Impact-driven hunting improves security vulnerability submissions by enforcing high-impact criteria through specific submission guidance tables, ensuring findings are conditionally valid and preventing rejected reports.

Can I use a centralized payload library for testing business logic flaws and authentication bypass?

Yes, you can use a centralized payload library for testing business logic flaws and authentication bypass, as it supports diverse attack vectors including web injection across various platforms.

Why are my penetration testing findings being rejected by bug bounty platforms?

Penetration testing findings are often rejected because they fail to meet high-impact criteria. Using Always Rejected and Conditionally Valid submission tables ensures your reports meet impact-driven hunting principles.

When do I need specific cloud metadata probes or DNS rebinding payloads for SSRF testing?

You need specific cloud metadata probes or DNS rebinding payloads for SSRF testing when attempting to confirm impact and bypass internal filters on a potential server-side request forgery vulnerability.