waf-bypass-hunter

Test payload variants against a Go WAF and Node.js backend to discover parser-differential bypasses.

112|13|Updated Dec 1, 2025
One-click install
npx skills add https://github.com/HacktronAI/skills --skill waf-bypass-hunter
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: waf-bypass-hunter
Source: https://github.com/HacktronAI/skills/tree/main/waf-bypass-hunter
Command: npx skills add https://github.com/HacktronAI/skills --skill waf-bypass-hunter

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps security researchers automatically discover bypass techniques against a WAF by analyzing parser differences between Go (WAF) and Node.js (backend), enabling faster discovery of bypass payloads and reducing manual trial-and-error.

Core Features & Use Cases

  • Parser-differential testing: Tests multiple payload variants to identify bypasses that bypass WAF filtering while still being parsed by the backend.
  • Payload cataloging: Maintains a library of bypass payload patterns and evaluation results.
  • Use Case: A pentester wants to enumerate WAF bypass techniques for a lab environment; the skill can generate and test payloads against a local WAF to gather bypass evidence and potential CVEs.

Quick Start

Run a basic bypass test against the local WAF at port 9091 using a minimal test payload, then review results and logs in the executor.