Search
By NeoTheCapt
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses | NeoTheCapt/ | 142 | — | ~1.3k | Automated safety check: Pass | No licence | 2 mo ago |
| 2 | Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws | NeoTheCapt/ | 142 | — | ~2.8k | Automated safety check: Pass | No licence | 2 mo ago |
| 3 | CORS misconfiguration testing for data theft and access control bypass | NeoTheCapt/ | 142 | — | ~904 | Automated safety check: Pass | No licence | 2 mo ago |
| 4 | Cross-site request forgery testing for state-changing operations | NeoTheCapt/ | 142 | — | ~791 | Automated safety check: Pass | No licence | 2 mo ago |
| 5 | Insecure deserialization detection and gadget chain exploitation | NeoTheCapt/ | 142 | — | ~836 | Automated safety check: Pass | No licence | 2 mo ago |
| 6 | Discover hidden directories, files, and endpoints on a web server | NeoTheCapt/ | 142 | — | ~737 | Automated safety check: Notes | No licence | 2 mo ago |
| 7 | Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains | NeoTheCapt/ | 142 | — | ~608 | Automated safety check: Pass | No licence | 2 mo ago |
| 8 | Discover hidden parameters, test values, and identify input handling anomalies | NeoTheCapt/ | 142 | — | ~944 | Automated safety check: Pass | No licence | 2 mo ago |
| 9 | Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution | NeoTheCapt/ | 142 | — | ~988 | Automated safety check: Warn | No licence | 2 mo ago |
| 10 | Discover open ports, running services, and their versions on a target | NeoTheCapt/ | 142 | — | ~634 | Automated safety check: Pass | No licence | 2 mo ago |
| 11 | HTTP request smuggling via CL.TE/TE.CL desync and cache poisoning | NeoTheCapt/ | 142 | — | ~982 | Automated safety check: Pass | No licence | 2 mo ago |
| 12 | Frontend source code analysis for hidden routes, API endpoints, and secrets | NeoTheCapt/ | 142 | — | ~3k | Automated safety check: Pass | No licence | 2 mo ago |
| 13 | 13.Sqli Testing Detect and exploit SQL injection vulnerabilities in web application parameters | NeoTheCapt/ | 142 | — | ~1.2k | Automated safety check: Pass | No licence | 2 mo ago |
| 14 | 14.Ssrf Testing Detect and exploit server-side request forgery to access internal resources and cloud metadata | NeoTheCapt/ | 142 | — | ~768 | Automated safety check: Pass | No licence | 2 mo ago |
| 15 | Subdomain discovery via subfinder, DNS brute-force, and passive sources | NeoTheCapt/ | 142 | — | ~1.7k | Automated safety check: Notes | No licence | 2 mo ago |
| 16 | Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference | NeoTheCapt/ | 142 | — | ~2.9k | Automated safety check: Pass | No licence | 2 mo ago |
| 17 | 17.Web Recon Enumerate web technologies, headers, endpoints, and metadata from a target | NeoTheCapt/ | 142 | — | ~770 | Automated safety check: Pass | No licence | 2 mo ago |
| 18 | 18.Xss Testing Detect and exploit cross-site scripting vulnerabilities in web applications | NeoTheCapt/ | 142 | — | ~1.4k | Automated safety check: Pass | No licence | 2 mo ago |
| 19 | 19.Xxe Testing XML external entity injection for file read, SSRF, and DoS. An agent skill from NeoTheCapt/RedteamAgent. | NeoTheCapt/ | 142 | — | ~1k | Automated safety check: Pass | No licence | 2 mo ago |
| 20 | Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts | NeoTheCapt/ | 142 | — | ~5.1k | Automated safety check: Notes | No licence | 2 mo ago |
| 21 | OS command injection detection, exploitation, and filter bypass | NeoTheCapt/ | 142 | — | ~754 | Automated safety check: Pass | No licence | 2 mo ago |
| 22 | File upload vulnerability testing — webshells, bypass, path traversal | NeoTheCapt/ | 142 | — | ~1.6k | Automated safety check: Pass | No licence | 2 mo ago |
| 23 | 23.Idor Testing Insecure direct object reference testing for broken access control | NeoTheCapt/ | 142 | — | ~793 | Automated safety check: Pass | No licence | 2 mo ago |
| 24 | Information disclosure detection — error messages, files, headers, debug endpoints | NeoTheCapt/ | 142 | — | ~1.1k | Automated safety check: Notes | No licence | 2 mo ago |
| 25 | 25.Ssti Testing Server-side template injection detection, engine identification, and RCE | NeoTheCapt/ | 142 | — | ~748 | Automated safety check: Pass | No licence | 2 mo ago |