pentest-fuzz-skill
Help with authorized Web pentest, Web fuzzing, and CTF-style vulnerability analysis. Use this skill whenever the user wants payload ideas, fuzz dictionaries, quick probe strings, test methodology, response-difference heuristics, or per-vulnerability checklists for common Web bugs such as SQL injection, XSS, SSTI, SSRF, XXE, file inclusion, IDOR, JWT weaknesses, deserialization, auth bypass, or command injection. Make sure to use it when the user asks how to test a Web bug, what characters or tokens to fuzz, how to organize notes by vulnerability type, or which vulnerability family a behavior most likely belongs to, even if they do not explicitly mention a skill.
Source facts
- Repository
- m-sec-org/BreachWeave
- Last source activity
- May 6, 2026 at 08:59
- Detected SKILL.md language
- English
- Stars
- 517
- Forks
- 64
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.