Find authentication and session vulnerabilities. Use when user asks about auth bypass, session issues, login security, or token problems.
لغة النص الأصلي: الإنجليزية
القائمة
جمع SkillsMP عدد ١٧ من skills من instavm/security-skills. افتح أي skill لمراجعة مصدره وتفاصيله.
عرض ١٧ من أصل ١٧ skills مجمعة.
Find authentication and session vulnerabilities. Use when user asks about auth bypass, session issues, login security, or token problems.
لغة النص الأصلي: الإنجليزية
Find Business Logic vulnerabilities in captured traffic. Use when user asks about payment bypass, race conditions, workflow abuse, or application logic flaws.
لغة النص الأصلي: الإنجليزية
Find payment callback and webhook vulnerabilities. Use when user asks about payment security, callback tampering, hash validation, or transaction manipulation.
لغة النص الأصلي: الإنجليزية
Find checksum and signature vulnerabilities. Use when user asks about hash validation, signature bypass, checksum manipulation, or cryptographic weaknesses.
لغة النص الأصلي: الإنجليزية
Find enumerable endpoints that leak data through iteration. Use when user asks about data scraping, bulk data access, or iterating through records.
لغة النص الأصلي: الإنجليزية
Find IDOR (Insecure Direct Object Reference) vulnerabilities in captured traffic. Use when user asks about authorization issues, sequential IDs, or accessing other users' data.
لغة النص الأصلي: الإنجليزية
Find insecure configurations in HTTP traffic. Use when user asks about security headers, cookie security, CORS issues, or transport security.
لغة النص الأصلي: الإنجليزية
Find OTP implementation vulnerabilities. Use when user asks about OTP security, verification bypass, SMS security, or two-factor authentication issues.
لغة النص الأصلي: الإنجليزية
Find PII (Personally Identifiable Information) leakage in API responses. Use when user asks about data exposure, privacy issues, or sensitive data in traffic.
لغة النص الأصلي: الإنجليزية
Find Referer header leakage vulnerabilities. Use when user asks about URL leakage, third-party data exposure, or sensitive data in headers.
لغة النص الأصلي: الإنجليزية
Find leaked secrets, API keys, and credentials in traffic. Use when user asks about exposed keys, hardcoded secrets, or credential leakage.
لغة النص الأصلي: الإنجليزية
Find SQL Injection vulnerabilities in captured traffic. Use when user asks about database security, injection attacks, or data extraction.
لغة النص الأصلي: الإنجليزية
Find SSRF (Server-Side Request Forgery) vulnerabilities in captured traffic. Use when user asks about URL fetching, webhooks, integrations, or internal network access.
لغة النص الأصلي: الإنجليزية
List all APIs from mitmproxy traffic capture. Use when user asks to see APIs, endpoints, or wants an overview of captured HTTP traffic for a website or app.
لغة النص الأصلي: الإنجليزية
Generate a security vulnerability report. Use when user asks for a report, summary of findings, or formatted vulnerability documentation.
لغة النص الأصلي: الإنجليزية
Comprehensive security audit of mitmproxy traffic. Use when user wants to analyze captured HTTP traffic for vulnerabilities, or mentions pentesting, security testing, or vulnerability assessment.
لغة النص الأصلي: الإنجليزية
Enumerate subdomains from captured traffic. Use when user asks about subdomain discovery, attack surface mapping, or domain reconnaissance.
لغة النص الأصلي: الإنجليزية