SQLi HunterSQL and NoSQL injection across ORM raw fragments, GraphQL resolvers, OIDC-proxy backends, and SOQL. Built...
claude "/hunt-sqli https://target.com"
→ trigger: auto-loaded
XSS HunterCross-site scripting across DOM, reflected, stored, and mutation-based patterns. Built from 174 public bu...
claude "/hunt-xss https://target.com"
→ trigger: auto-loaded
SSRF HunterServer-side request forgery including cloud metadata endpoint exfiltration, internal network pivoting, an...
claude "/hunt-ssrf https://target.com"
→ trigger: auto-loaded
RCE HunterRemote code execution via deserialization, template injection, command injection, and unsafe eval pattern...
claude "/hunt-rce https://target.com"
→ trigger: auto-loaded
IDOR HunterInsecure direct object references including BOLA in REST/GraphQL, ID enumeration, and horizontal privileg...
claude "/hunt-idor https://target.com"
→ trigger: auto-loaded
CSRF HunterCross-site request forgery including SameSite bypass, token fixation, and JSON-based CSRF in single-page ...
claude "/hunt-csrf https://target.com"
→ trigger: auto-loaded
SSTI HunterServer-side template injection across Jinja2, Twig, Freemarker, Velocity, and Pebble with RCE escalation ...
claude "/hunt-ssti https://target.com"
→ trigger: auto-loaded
XXE HunterXML external entity injection including blind OOB exfiltration, file read via error messages, and XXE-to-...
claude "/hunt-xxe https://target.com"
→ trigger: auto-loaded
/hunt-file-upload
Web HuntingFile Upload HunterUnrestricted file upload bypasses — MIME type spoofing, extension trickery, polyglots, path traversal via...
claude "/hunt-file-upload https://target.com"
→ trigger: auto-loaded
/hunt-cache-poison
Web HuntingCache Poison HunterWeb cache poisoning via unkeyed headers, parameter cloaking, fat GET exploitation, and cache-key normaliz...
claude "/hunt-cache-poison https://target.com"
→ trigger: auto-loaded
/hunt-http-smuggling
Web HuntingHTTP Smuggling HunterHTTP request smuggling — CL.TE, TE.CL, TE.TE variants with bypass and response queue poisoning escalation...
claude "/hunt-http-smuggling https://target.com"
→ trigger: auto-loaded
/hunt-race-condition
Web HuntingRace Condition HunterRace condition exploitation on payment flows, coupon redemption, rate-limit bypass, and parallel request ...
claude "/hunt-race-condition https://target.com"
→ trigger: auto-loaded
/hunt-business-logic
Web HuntingBusiness Logic HunterBusiness logic flaws — price manipulation, workflow bypass, state machine abuse, and trust boundary viola...
claude "/hunt-business-logic https://target.com"
→ trigger: auto-loaded
GraphQL HunterGraphQL introspection abuse, batching attacks, IDOR through aliases, nested query DoS, and authorization ...
claude "/hunt-graphql https://target.com"
→ trigger: auto-loaded
LLM/AI HunterLLM-integrated application vulnerabilities — prompt injection, insecure tool use, training data extractio...
claude "/hunt-llm-ai https://target.com"
→ trigger: auto-loaded
/hunt-dispatch
Web HuntingDispatch HunterSmart target triage and hunting path dispatch — routes to the right skill based on reconnaissance signals...
claude "/hunt-dispatch https://target.com"
→ trigger: auto-loaded
Misc Vuln HunterCatch-all for open redirect, CRLF injection, clickjacking, host header injection, and other frequently di...
claude "/hunt-misc https://target.com"
→ trigger: auto-loaded
ASP.NET HunterASP.NET-specific attack surface — ViewState deserialization, __EVENTTARGET manipulation, IIS short filena...
claude "/hunt-aspnet https://target.com"
→ trigger: auto-loaded
Bug Bounty PlannerStructured methodology for scoping, prioritizing, and executing a bug bounty engagement from program sele...
claude "/bug-bounty https://target.com"
→ trigger: auto-loaded
/bb-methodology
Web HuntingBB MethodologyEnd-to-end bug bounty methodology — recon, attack surface mapping, vulnerability testing order, and triag...
claude "/bb-methodology https://target.com"
→ trigger: auto-loaded
/bb-local-toolkit
Web HuntingLocal ToolkitLocal toolchain setup for bug bounty — ffuf, nuclei, sqlmap, burp configurations, and wordlist management...
claude "/bb-local-toolkit https://target.com"
→ trigger: auto-loaded
/security-arsenal
Web HuntingSecurity ArsenalCurated command arsenal for web security testing — one-liner reference for recon, fuzzing, exploitation, ...
claude "/security-arsenal https://target.com"
→ trigger: auto-loaded