★ ★ ★LIVE51 SPECIALIZED SKILLS ACROSS 8 ATTACK DOMAINS · BUGGY AI·VIEW SKILLS →★ ★ ★
BUGGY
buggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leakedbuggy.hunt("https://target.com")→ [sqli] signal detectedclaude.triage(finding="blind-sqli")→ [7-gate] passed (7/7)recon.subdomains("target.com")→ [142] active assetsauth.audit_jwt(token="ey...")→ [none-alg] bypass foundbuggy.generate_report(cvss=9.8)→ [hackerone] markdown readyapi.probe_graphql("api.target.com/v1")→ [introspection] enabledm365.enum_users("target.com")→ [pw-spray] safe modemobile.decompile_apk("app.apk")→ [hardcoded-key] leaked
SKILLS/WEB-HUNTING
> 22 SKILLS ACTIVE

Web Hunting SECURITY DOMAIN

Deep-dive skills for SQL injection, XSS, SSRF, RCE, business logic, and 15+ other web vulnerability classes — each built from real bug bounty reports.

22 SKILLS IN DOMAIN
🌐 CATEGORY
← All 8 Domains
/hunt-sqli
Web Hunting
SQLi HunterSQL and NoSQL injection across ORM raw fragments, GraphQL resolvers, OIDC-proxy backends, and SOQL. Built...
claude "/hunt-sqli https://target.com" → trigger: auto-loaded
Both ✓12 reports
/hunt-xss
Web Hunting
XSS HunterCross-site scripting across DOM, reflected, stored, and mutation-based patterns. Built from 174 public bu...
claude "/hunt-xss https://target.com" → trigger: auto-loaded
Both ✓174 reports
/hunt-ssrf
Web Hunting
SSRF HunterServer-side request forgery including cloud metadata endpoint exfiltration, internal network pivoting, an...
claude "/hunt-ssrf https://target.com" → trigger: auto-loaded
/hunt-rce
Web Hunting
RCE HunterRemote code execution via deserialization, template injection, command injection, and unsafe eval pattern...
claude "/hunt-rce https://target.com" → trigger: auto-loaded
/hunt-idor
Web Hunting
IDOR HunterInsecure direct object references including BOLA in REST/GraphQL, ID enumeration, and horizontal privileg...
claude "/hunt-idor https://target.com" → trigger: auto-loaded
Both ✓26 reports
/hunt-csrf
Web Hunting
CSRF HunterCross-site request forgery including SameSite bypass, token fixation, and JSON-based CSRF in single-page ...
claude "/hunt-csrf https://target.com" → trigger: auto-loaded
/hunt-ssti
Web Hunting
SSTI HunterServer-side template injection across Jinja2, Twig, Freemarker, Velocity, and Pebble with RCE escalation ...
claude "/hunt-ssti https://target.com" → trigger: auto-loaded
/hunt-xxe
Web Hunting
XXE HunterXML external entity injection including blind OOB exfiltration, file read via error messages, and XXE-to-...
claude "/hunt-xxe https://target.com" → trigger: auto-loaded
/hunt-file-upload
Web Hunting
File Upload HunterUnrestricted file upload bypasses — MIME type spoofing, extension trickery, polyglots, path traversal via...
claude "/hunt-file-upload https://target.com" → trigger: auto-loaded
/hunt-cache-poison
Web Hunting
Cache Poison HunterWeb cache poisoning via unkeyed headers, parameter cloaking, fat GET exploitation, and cache-key normaliz...
claude "/hunt-cache-poison https://target.com" → trigger: auto-loaded
/hunt-http-smuggling
Web Hunting
HTTP Smuggling HunterHTTP request smuggling — CL.TE, TE.CL, TE.TE variants with bypass and response queue poisoning escalation...
claude "/hunt-http-smuggling https://target.com" → trigger: auto-loaded
/hunt-race-condition
Web Hunting
Race Condition HunterRace condition exploitation on payment flows, coupon redemption, rate-limit bypass, and parallel request ...
claude "/hunt-race-condition https://target.com" → trigger: auto-loaded
/hunt-business-logic
Web Hunting
Business Logic HunterBusiness logic flaws — price manipulation, workflow bypass, state machine abuse, and trust boundary viola...
claude "/hunt-business-logic https://target.com" → trigger: auto-loaded
/hunt-graphql
Web Hunting
GraphQL HunterGraphQL introspection abuse, batching attacks, IDOR through aliases, nested query DoS, and authorization ...
claude "/hunt-graphql https://target.com" → trigger: auto-loaded
/hunt-llm-ai
Web Hunting
LLM/AI HunterLLM-integrated application vulnerabilities — prompt injection, insecure tool use, training data extractio...
claude "/hunt-llm-ai https://target.com" → trigger: auto-loaded
/hunt-dispatch
Web Hunting
Dispatch HunterSmart target triage and hunting path dispatch — routes to the right skill based on reconnaissance signals...
claude "/hunt-dispatch https://target.com" → trigger: auto-loaded
/hunt-misc
Web Hunting
Misc Vuln HunterCatch-all for open redirect, CRLF injection, clickjacking, host header injection, and other frequently di...
claude "/hunt-misc https://target.com" → trigger: auto-loaded
/hunt-aspnet
Web Hunting
ASP.NET HunterASP.NET-specific attack surface — ViewState deserialization, __EVENTTARGET manipulation, IIS short filena...
claude "/hunt-aspnet https://target.com" → trigger: auto-loaded
/bug-bounty
Web Hunting
Bug Bounty PlannerStructured methodology for scoping, prioritizing, and executing a bug bounty engagement from program sele...
claude "/bug-bounty https://target.com" → trigger: auto-loaded
/bb-methodology
Web Hunting
BB MethodologyEnd-to-end bug bounty methodology — recon, attack surface mapping, vulnerability testing order, and triag...
claude "/bb-methodology https://target.com" → trigger: auto-loaded
/bb-local-toolkit
Web Hunting
Local ToolkitLocal toolchain setup for bug bounty — ffuf, nuclei, sqlmap, burp configurations, and wordlist management...
claude "/bb-local-toolkit https://target.com" → trigger: auto-loaded
/security-arsenal
Web Hunting
Security ArsenalCurated command arsenal for web security testing — one-liner reference for recon, fuzzing, exploitation, ...
claude "/security-arsenal https://target.com" → trigger: auto-loaded