attack-cache-poison
Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage
GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass
Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host
IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure
JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping
Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains
JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation
HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass
Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques