with one click
RedteamAgent
RedteamAgent contains 31 collected skills from NeoTheCapt, with repository-level occupation coverage and site-owned skill detail pages.
Skills in this repository
Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws
Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts
Detect and exploit SQL injection vulnerabilities in web application parameters
Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses
Detect and exploit cross-site scripting vulnerabilities in web applications
Discover hidden parameters, test values, and identify input handling anomalies
File upload vulnerability testing — webshells, bypass, path traversal
XML external entity injection for file read, SSRF, and DoS
Frontend source code analysis for hidden routes, API endpoints, and secrets
Discover hidden directories, files, and endpoints on a web server
Discover open ports, running services, and their versions on a target
Subdomain discovery via subfinder, DNS brute-force, and passive sources
Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference
Enumerate web technologies, headers, endpoints, and metadata from a target
OS command injection detection, exploitation, and filter bypass
CORS misconfiguration testing for data theft and access control bypass
Cross-site request forgery testing for state-changing operations
GraphQL security testing — introspection, injection, auth bypass, DoS
HTTP request smuggling via CL.TE/TE.CL desync and cache poisoning
Information disclosure detection — error messages, files, headers, debug endpoints
Race condition and TOCTOU exploitation — parallel request attacks
Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution
Insecure direct object reference testing for broken access control
Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains
Server-side template injection detection, engine identification, and RCE
Open-source intelligence gathering — CVE lookup, breach search, DNS history, social profiling
Insecure deserialization detection and gadget chain exploitation
JWT token attack techniques — alg bypass, key confusion, claim tampering
Engagement report structure and formatting guidelines
Detect and exploit server-side request forgery to access internal resources and cloud metadata
WebSocket security testing — injection, auth bypass, hijacking