XXE/XML technique list -- classic, blind OOB, error-based, parameter entities, billion laughs, XInclude, XSLT, and XXE in SVG/DOCX/XLSX/PPTX/RSS/SOAP formats -- plus the SSRF/file-read/port-scan escalations XXE enables. Converted from master-pentest-prompt.md…
Skills in this repository
ankitsingh015/HuntMCP - Page 2
SkillsMP has collected 47 skills from ankitsingh015/HuntMCP. Open a skill to review its source and details.
ankitsingh015/HuntMCPShowing 7 of 47 collected skills.
Conventions for writing HuntMCP's own Claude Code Skills, especially the ongoing conversion of knowledge/master-pentest-prompt.md's [PHASE N] sections into .claude/skills/<topic>/SKILL.md files. Use this before creating or editing any file under…
Path traversal encodings, the file-upload bypass matrix (extension/MIME/magic-byte checks), and file-format-specific attacks (SVG/DOCX/XLSX XXE, PDF launch actions, polyglot images). Converted from master-pentest-prompt.md Phase 6. Use on any file-upload…
How to load prior knowledge before testing a target -- public bug-bounty report learning, offensive skill-file references, the Lessons Registry feedback loop, and tech-stack-based keyword lookup into it. Converted from master-pentest-prompt.md Phases…
Full-spectrum recon technique list (subdomains, JS mining, history, dorks, cloud storage, internet-exposure scanners, DNS) and the 8-category JavaScript intelligence-mining checklist. Converted from master-pentest-prompt.md Phases 1/1.5. Use during…
HTTP request smuggling and desync technique list, including the 2025-26 "HTTP/1.1 must die" desync-endgame classes (0.CL, CL.0, H2.TE, TE.TE chunk extensions, response queue poisoning, dangling-byte, browser-powered desyncs). Converted from…
Tool-separation doctrine (what's allowed to touch the live target vs. research-only) and a curl flag cheat sheet for manual PoC/verification work. Converted from master-pentest-prompt.md Phase 0.7. Use whenever an agent needs to hand-craft a curl request…