What problem does it solve?
It solves the challenge of quickly understanding which Web2 vulnerability class matches an observed behavior and how to validate it for reporting and payout readiness.
Core Features & Use Cases
- Bug class reference for real hunting: Covers 20 Web2 vulnerability domains including IDOR, broken auth/access control, XSS, SSRF (with 11 IP bypass techniques), SQLi, business logic flaws, race conditions, OAuth/OIDC, file upload (10 bypass techniques), GraphQL, LLM/AI agentic risks (OWASP ASI 2026 ASI01–ASI10), API misconfiguration, ATO taxonomy, SSTI, subdomain takeover, cloud/infra misconfigs, HTTP request smuggling, cache poisoning/deception, MFA bypass (7 patterns), and SAML/SSO attacks (XSW, comment injection, signature stripping).
- Root-cause + detection patterns + bypass tables: Provides testing checklists, common variants, and chaining opportunities to help you move from suspicion to evidence.
- Exploit/validation playbooks: Includes targeted payload ideas, impact escalation logic, and “triage rules” to determine when findings are informational vs bounty-worthy.
Quick Start
Use the web2-vuln-classes skill when you suspect an IDOR, upload bypass, SSRF, or ATO path and need a structured plan to test, escalate, and document it for a professional bug report.