Pentest gRPC-Web services and endpoints. Use this skill whenever the user mentions gRPC-Web, gRPC over HTTP, protobuf services, Envoy proxies, or wants to test/audit gRPC-Web APIs. Trigger for any gRPC-Web reconnaissance, payload manipulation, CORS testing, or JavaScript bundle analysis tasks.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
The command stays on one line. Scroll horizontally to inspect it before copying.
Prefer a local copy? Download the files currently available to SkillsMP.
File Explorer
2 files
Showing SKILL.md
SKILL.md
Source instructions · Read-only preview
name
grpc-web-pentest
description
Pentest gRPC-Web services and endpoints. Use this skill whenever the user mentions gRPC-Web, gRPC over HTTP, protobuf services, Envoy proxies, or wants to test/audit gRPC-Web APIs. Trigger for any gRPC-Web reconnaissance, payload manipulation, CORS testing, or JavaScript bundle analysis tasks.
gRPC-Web Pentesting
A skill for security testing gRPC-Web services, including reconnaissance, payload manipulation, and vulnerability discovery.
When to use this skill
Use this skill when:
Testing gRPC-Web endpoints (application/grpc-web or application/grpc-web-text content types)
Analyzing JavaScript bundles for gRPC service definitions
Testing CORS configurations on gRPC-Web proxies
Manipulating gRPC-Web payloads for fuzzing or exploitation