security-arsenal

Provide security payloads for XSS, SSRF, SQLi, and other web vulnerabilities.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill security-arsenal-kisilev13
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/Kisilev13/Hermes-Agent-Workspace/tree/main/skills/security-arsenal
Command: npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill security-arsenal-kisilev13

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill unit serves as a treasure trove for bug bounty hunters, providing a wide array of payloads for various web security vulnerabilities, aiding in the discovery and exploitation of bugs.

Core Features & Use Cases

  • Vulnerability Payloads: Offers a comprehensive set of payloads for XSS, SSRF, SQLi, XXE, IDOR, Path Traversal, Authentication Bypass, etc.
  • Use Case: For instance, if testing for SQL Injection vulnerabilities, you can quickly select a relevant payload from this Skill unit to attempt exploitation.

Quick Start

Use the 'security-arsenal' skill to test for SQL injection vulnerabilities in the web application.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find security payloads for testing XSS and SQL injection vulnerabilities?

To find security payloads for XSS and SQL injection vulnerabilities, you can use a comprehensive collection of exploitation inputs designed specifically for bug bounty hunting and penetration testing across various web vulnerabilities.

What types of web vulnerability payloads can I use for bug bounty hunting?

For bug bounty hunting, you can use payloads covering XSS, SSRF, SQLi, XXE, IDOR, Path Traversal, and Authentication Bypass. These payloads support both manual and automated exploitation attempts during security testing.

Can I use these security payloads for automated exploitation during penetration testing?

Yes, you can use these security payloads for automated exploitation during penetration testing. The collection is explicitly intended to support both manual and automated workflows for discovering and exploiting web application bugs.

Are there specific payloads for testing SSRF, XXE, and IDOR vulnerabilities?

Yes, there are specific payloads available for testing SSRF, XXE, and IDOR vulnerabilities. The collection provides a wide array of targeted inputs to aid in the discovery and exploitation of these particular web security flaws.

How do I test for path traversal and authentication bypass vulnerabilities in a web application?

To test for path traversal and authentication bypass vulnerabilities, you can select relevant payloads from this security collection to attempt exploitation. This aids in identifying access control weaknesses within the target web application.