Search
Java · Penetration testing
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 892 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 2 | Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization. | PentesterFlow/ | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 3 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 2 days ago |
| 4 | 4.Ssti Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or… | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 5 | Insecure deserialization detection and gadget chain exploitation | NeoTheCapt/ | 142 | — | ~836 | Automated safety check: Pass | No licence | 2 mo ago |
| 6 | Server-side template injection detection, engine identification, and RCE | NeoTheCapt/ | 142 | — | ~748 | Automated safety check: Pass | No licence | 2 mo ago |