security-arsenal

Organize security payloads and bypass patterns for common web vulnerabilities.

Updated Jun 5, 2026
One-click install
npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill security-arsenal-sseshachala
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-arsenal
Source: https://github.com/sseshachala/Claude-BugHunter-archive/tree/main/skills/security-arsenal
Command: npx skills add https://github.com/sseshachala/Claude-BugHunter-archive --skill security-arsenal-sseshachala

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security testing and vulnerability validation often require a centralized collection of payloads, bypass patterns, wordlists, and submission rules to ensure consistent, auditable findings.

Core Features & Use Cases

  • Provides a comprehensive payload library for XSS, SSRF, SQLi, XXE, NoSQLi injections, SSTI, IDOR, path traversal, HTTP smuggling, WebSocket messaging, and MFA bypass.
  • Includes bypass tables, gf pattern names, and an always-rejected list to guide when not to submit and how to triage findings.
  • Useful for red team operators, bug bounty researchers, and security engineers evaluating payload effectiveness and reporting criteria.

Quick Start

Browse the payload library and select the appropriate payloads for your target vulnerability and policy scope.

Frequently Asked Questions about security-arsenal

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find security payloads for XSS, SSRF, and SQLi testing?

Security payload libraries for XSS, SSRF, and SQLi testing organize injection patterns and bypass rules by vulnerability type to ensure consistent and auditable validation. They provide structured examples for targeted web vulnerability assessment.

What is the best way to organize bypass patterns and submission rules for bug bounty findings?

Organizing bypass patterns for bug bounty findings requires structured tables and an always-rejected list to triage results. This approach standardizes reporting criteria and guides researchers on when not to submit invalid vulnerability reports.

Can I use a single payload library for SSTI, IDOR, path traversal, and HTTP smuggling?

Yes, a comprehensive payload library can cover SSTI, IDOR, path traversal, and HTTP smuggling. It centralizes diverse injection examples and testing guidelines so security engineers can evaluate multiple web vulnerabilities consistently.

Does this payload collection include MFA bypass and WebSocket testing examples?

MFA bypass and WebSocket testing examples are included alongside NoSQLi and XXE payloads. These structured patterns enable red team operators to validate authentication flaws and messaging vulnerabilities across different web protocols.

When should I not submit security testing findings during vulnerability validation?

You should not submit security testing findings when they match criteria on an always-rejected list or fall outside defined scope boundaries. Clear submission rules and bypass tables help triage findings and prevent unsafe testing practices.