security-arsenal

Provide offensive security payloads, bypass techniques, and vulnerability submission criteria.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill security-arsenal-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/pdparchitect/rook/tree/main/skills/security-arsenal
Command: npx skills add https://github.com/pdparchitect/rook --skill security-arsenal-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a centralized, high-fidelity repository of security payloads, bypass techniques, and submission criteria, eliminating the need to hunt for fragmented snippets during active security research.

Core Features & Use Cases

  • Payload Library: Access verified payloads for XSS, SSRF, SQLi, XXE, IDOR, and more, including WAF and filter bypass techniques.
  • Submission Rules: Consult the "Always Rejected" and "Conditionally Valid" tables to ensure findings meet professional reporting standards.
  • Use Case: When auditing an API for SQL injection, use this Skill to quickly retrieve engine-specific blind SQLi payloads and WAF-bypass syntax to confirm the vulnerability.

Quick Start

Use the security-arsenal skill to provide a list of SSRF payloads for cloud metadata services and internal service fingerprinting.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find WAF bypass payloads for SQL injection testing?

To find WAF bypass payloads for SQL injection testing, access a centralized library of verified payloads and bypass techniques. This repository provides engine-specific blind SQLi syntax and filter evasion methods to confirm vulnerabilities during audits.

What is the best way to retrieve SSRF payloads for cloud metadata services?

The best way to retrieve SSRF payloads for cloud metadata services is using a comprehensive security payload library. It provides specialized payloads for internal service fingerprinting and cloud metadata extraction during reconnaissance.

Can I use these security payloads for source-code auditing and API testing?

Yes, these security payloads support source-code auditing and API testing across web, cloud, and infrastructure attack surfaces. They aid in reconnaissance, vulnerability verification, and reporting phases by providing standardized testing primitives.

What security testing primitives are available for XSS and XXE vulnerabilities?

Available security testing primitives include verified payloads for XSS, XXE, IDOR, SSRF, and SQLi. The library offers high-fidelity snippets and bypass techniques, eliminating the need to hunt for fragmented code during active research.