Agent skill

Server Side

by transilienceai in transilienceai/communitytools

Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.

MITAuto-check passedSecurity

Install Server Side

skills CLI
$ npx skills add transilienceai/communitytools --skill server-side -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install transilienceai/communitytools server-side --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/transilienceai/communitytools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/server-side .claude/skills/server-side && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
server-side
GitHub stars
562
Token cost
~484 tokens
SKILL.md length
159 words
Files
54
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.

  • Works in 5 steps: Identify server-side processing points → Test for vulnerability class indicators → Bypass protections (WAF, allowlists,… → …
  • Tasks that involve Backend development
  • SKILL.md covers Techniques, Workflow and Reference
  • Runs Python scripts from its folder

What it does

Server Side is an agent skill from transilienceai/communitytools. Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.

Its SKILL.md is about 480 tokens, which your agent loads only when the skill is triggered. The skill folder holds 58 other files (for example `reference/INDEX.md`, `reference/file-upload-resources.md` and `reference/http-host-header-resources.md`).

It sits in Security, covering Backend development, Web application vulnerabilities and File uploads and storage. The repository describes itself as: Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research. The licence is MIT.

When your agent uses it

  • Tasks that involve Backend development
  • Tasks that involve Web application vulnerabilities
  • Tasks that involve File uploads and storage

Example prompts

  • “/server-side”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify server-side processing points
  2. Test for vulnerability class indicators
  3. Bypass protections (WAF, allowlists, encoding filters)
  4. Demonstrate impact (file read, RCE, internal access)
  5. Capture evidence with PoC

What it can do on your machine

Read from SKILL.md and the folder at commit 95fdc12. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Server Side loads about 484 tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 159 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~484

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from transilienceai/communitytools at commit 95fdc12, republished under its MIT licence (© transilienceai). 159 words, ~484 tokens.

Download SKILL.mdSave it as .claude/skills/server-side/SKILL.md (or your agent's skills folder). This skill also uses 53 other files; get the full folder from GitHub.
name
server-side
description
Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.

Server-Side

Test for server-side vulnerabilities that allow unauthorized access, RCE, or data exfiltration.

Techniques

TypeKey Vectors
SSRFInternal service access, cloud metadata, protocol smuggling
HTTP SmugglingCL.TE, TE.CL, TE.TE, CL.0, H2.CL, h2c, multi-layer proxy chains, connection pooling desync
Path TraversalDirectory traversal, null bytes, encoding bypass
File UploadExtension bypass, content-type manipulation, polyglot files
DeserializationJava, PHP, Python, .NET gadget chains
Host HeaderPassword reset poisoning, cache poisoning, routing-based SSRF
CUPS / cups-browsedCVE-2024-47076/47175/47176/47177 — UDP browse → IPP injection → PPD injection → foomatic-rip RCE (see skills/infrastructure/reference/scenarios/network-recon/cups-browsed-rce.md)

Workflow

  1. Identify server-side processing points
  2. Test for vulnerability class indicators
  3. Bypass protections (WAF, allowlists, encoding filters)
  4. Demonstrate impact (file read, RCE, internal access)
  5. Capture evidence with PoC

Reference

  • reference/scenarios/ssrf/*.md - SSRF techniques and labs
  • reference/http-request-smuggling*.md - Smuggling techniques
  • reference/scenarios/path-traversal/*.md - Path traversal bypass methods
  • reference/file-upload*.md - File upload exploitation
  • reference/insecure-deserialization*.md - Deserialization attacks
  • reference/http-host-header*.md - Host header injection
  • skills/infrastructure/reference/scenarios/network-recon/cups-browsed-rce.md - CUPS RCE chain (CVE-2024-47076/175/176/177); ipptool false positives vs libcups runtime parser; ippserver Python lib version-1.1 hardcode bug

© transilienceai, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 53 other files in skills/server-side of transilienceai/communitytools.

  • SKILL.md
  • reference/INDEX.md
  • reference/file-upload-resources.md
  • reference/http-host-header-resources.md
  • reference/http-request-smuggling-resources.md
  • reference/insecure-deserialization-resources.md
  • reference/protocol-coercion.md
  • reference/scenarios/deserialization/dotnet-deserialization.md
  • reference/scenarios/deserialization/java-deserialization.md
  • reference/scenarios/deserialization/nodejs-deserialization.md
  • reference/scenarios/deserialization/php-deserialization.md
  • reference/scenarios/deserialization/python-and-ruby.md
  • reference/scenarios/deserialization/react-server-components-flight.md
  • reference/scenarios/deserialization/tools/aspnet_viewstate_build.py
  • reference/scenarios/file-upload/content-type-and-magic-bytes.md
  • reference/scenarios/file-upload/defense-evasion-and-yara.md
  • … and 38 more

Open the folder on GitHubat commit 95fdc12

Compare with similar skills

Server Side next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Server Side compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Server Side this skilltransilienceai/communitytools562—~484Automated safety check: PassMIT
Laravel Securityaffaan-m/ECC275k3 repos~2kAutomated safety check: PassMIT
Psalm Security Analysiscachethq/core230—~4.7kAutomated safety check: PassCustom licence
Security DjangoIgorWarzocha/Opencode-Workflows122—~1.6kAutomated safety check: NotesNone
Security Reviewtrycompai/comp2k—~853Automated safety check: PassAGPL-3.0
Laravel Security Auditaiskillstore/marketplace4304 repos~1.1kAutomated safety check: NotesNone

Similar skills

  • Laravel Security

    affaan-m/ECC

    Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.

    275k GitHub starsUsed in 3 repos~2k tokens
    Backend & APIsAuto-check passed
  • Runs and interprets Psalm security (taint) analysis on a Laravel project.

    230 GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Security Django

    IgorWarzocha/Opencode-Workflows

    Review Django security audit patterns for settings and middleware.

    122 GitHub stars~1.6k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Security Review

    trycompai/comp

    Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it…

    2k GitHub stars~853 tokensUpdated today
    SecurityAuto-check passed
  • Laravel Security Audit

    aiskillstore/marketplace

    Security auditor for Laravel applications. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 4 repos~1.1k tokens
    SecurityAuto-check: notes
  • Php Security

    HoangNguyen0403/agent-skills-standard

    PHP-only security standards for database access, password handling, and input validation.

    571 GitHub stars~604 tokensUpdated yesterday
    SecurityAuto-check passed

More from transilienceai/communitytools

All 35 skills in this repo
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    562 GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Workflow

    transilienceai/communitytools

    GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review.

    562 GitHub stars~812 tokensUpdated 2 mo ago
    Auto-check: notes
  • Pci Secure Software

    transilienceai/communitytools

    Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.

    562 GitHub stars~1.8k tokensUpdated 2 mo ago
    Auto-check passed
  • Protect With Password

    transilienceai/communitytools

    Generate ONE strong password and apply it to each referenced file (PDF, Word, Excel, PowerPoint, or any type).

    562 GitHub stars~583 tokensUpdated 2 mo ago
    Auto-check passed
  • Skill Update

    transilienceai/communitytools

    Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits.

    562 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Source Code Scanning

    transilienceai/communitytools

    Security-focused source code review and SAST. An agent skill from transilienceai/communitytools.

    562 GitHub stars~1.2k tokensUpdated 2 mo ago
    Auto-check: notes

Questions about Server Side

What does Server Side do?

Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection. Server Side is an agent skill from transilienceai/communitytools. Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.

When should I use Server Side?

Server Side fits situations like: tasks that involve Backend development; tasks that involve Web application vulnerabilities; tasks that involve File uploads and storage.

How do I install Server Side in Claude Code?

Run `npx skills add transilienceai/communitytools --skill server-side -a claude-code`. Or copy the skill folder (skills/server-side in transilienceai/communitytools) into .claude/skills/server-side in your project. Claude Code loads it when a task matches its description.

How do I install Server Side in Codex?

Run `npx skills add transilienceai/communitytools --skill server-side -a codex`. Or copy the skill folder (skills/server-side in transilienceai/communitytools) into .agents/skills/server-side in your project. Codex loads it when a task matches its description.

Can I use Server Side in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add transilienceai/communitytools --skill server-side -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/server-side, .gemini/skills/server-side, .github/skills/server-side and .opencode/skills/server-side in your project.

What does Server Side need to run?

Going by SKILL.md and its folder, Server Side needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Server Side access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Server Side safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Server Side use?

Server Side is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Server Side use?

About 484 tokens (SKILL.md is roughly 1.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Server Side?

Skills that share tags, products or a category with Server Side: Laravel Security (affaan-m/ECC, 275k stars), Psalm Security Analysis (cachethq/core, 230 stars), Security Django (IgorWarzocha/Opencode-Workflows, 122 stars) and Security Review (trycompai/comp, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Server Side?

transilienceai (a GitHub organization) maintains it in transilienceai/communitytools, which has 562 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on July 29, 2026.

Source: transilienceai/communitytools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.