| name | web-security |
| description | Exploits web application vulnerabilities. Use when working with SQL injection, XSS, SSRF, SSTI, command injection, path traversal, authentication bypass, deserialization, or any web-based CTF challenge. |
| allowed-tools | Bash, Read, Write, Grep, Glob |
Web Security Skill
Quick Workflow
Progress:
- [ ] Identify technology stack
- [ ] Check common files (robots.txt, .git)
- [ ] Test injection points (SQLi, XSS, SSTI)
- [ ] Check authentication/session flaws
- [ ] Develop exploit
- [ ] Extract flag
Quick Recon
gobuster dir -u http://target -w /usr/share/wordlists/dirb/common.txt
ffuf -u http://target/FUZZ -w wordlist.txt
whatweb http://target
curl -I http://target
curl http://target/robots.txt
curl http://target/.git/HEAD
Vulnerability Reference
Tools Quick Reference
| Tool | Purpose | Command |
|---|
| sqlmap | SQLi automation | sqlmap -u URL --dbs |
| commix | Command injection | commix -u URL |
| tplmap | SSTI automation | tplmap -u URL |
| ffuf | Fuzzing | ffuf -u URL/FUZZ -w wordlist |
| Burp Suite | Proxy/intercept | GUI |
| jwt_tool | JWT attacks | jwt_tool TOKEN |