web2-vuln-classes

Document detection patterns and examples for 24 web application vulnerabilities.

Updated Jul 1, 2026
One-click install
npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill web2-vuln-classes-bpnrockstar
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web2-vuln-classes
Source: https://github.com/bpnrockstar/UnifiedBugHunter/tree/main/skills/web2-vuln-classes
Command: npx skills add https://github.com/bpnrockstar/UnifiedBugHunter --skill web2-vuln-classes-bpnrockstar

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a comprehensive guide to 24 common web application vulnerabilities, helping users understand the root causes, detection patterns, and real-world examples.

Core Features & Use Cases

  • Complete Reference: Covers IDOR, auth bypass, XSS, SSRF, SQLi, business logic, race conditions, OAuth/OIDC, file upload, GraphQL, LLM/AI, API misconfig, ATO, SSTI, subdomain takeover, cloud/infra misconfigs, HTTP smuggling, cache poisoning, MFA bypass, SAML attacks, LFI->RCE, deserialization, CSS injection, and error disclosure.
  • Detection Patterns: Provides detailed detection patterns for each vulnerability type.
  • Real-World Examples: Includes real-world examples to illustrate how each vulnerability can be exploited.

Quick Start

Use the skill to learn about and test for IDOR vulnerabilities in your web applications.

Frequently Asked Questions about web2-vuln-classes

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I test for IDOR and other web application vulnerabilities?

You can use this skill to learn about and detect IDOR vulnerabilities by following its detailed detection patterns and testing methods specifically designed for web applications.

What are the root causes of common web security bug classes?

This skill provides comprehensive root cause analysis and real-world examples across 24 common web application vulnerabilities, including SSRF, SQLi, XSS, and OAuth/OIDC flaws.

Do I need prior security testing knowledge to use these vulnerability detection patterns?

Yes, this skill requires existing knowledge of web application security and common attack vectors to effectively apply its detection patterns and mitigate the 24 covered bug classes.

How do I detect GraphQL and LLM/AI vulnerabilities in my web application?

This skill provides specific detection patterns and real-world examples for GraphQL and LLM/AI vulnerabilities, alongside 22 other web application bug classes like API misconfigurations and business logic flaws.

What is the best way to find detection patterns for HTTP smuggling and cache poisoning?

This skill serves as a comprehensive reference offering detailed detection patterns and real-world examples for HTTP smuggling, cache poisoning, and 22 other web2 vulnerability classes.