DevOps & Security skills

Browse reusable Agent Skills, each with a clear purpose and practical guidance.

attack-cache-poison

Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-cors

CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-graphql

GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-host-header

Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-idor-automation

IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-jwt

JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-open-redirect

Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-prototype-pollution

JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-request-smuggling

HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass

1.21k repo starsObserved in 1 repos
DevOps & Security

attack-ssrf

Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques

1.21k repo starsObserved in 1 repos
DevOps & Security