Generates Out-of-Band (OAST) interaction payloads with interactsh-client to detect and confirm Blind SSRF, Blind RCE, and Out-of-Band data leakage.
Skills in this repository
Zyrexnn/Cybermes - Page 3
SkillsMP has collected 90 skills from Zyrexnn/Cybermes. Open a skill to review its source and details.
Zyrexnn/CybermesShowing 10 of 90 collected skills.
Discovers hidden GET/POST/JSON parameters from web applications and categorizes them for IDOR, SSRF, SQLi, and redirect testing.
Pentest a web app, API, codebase, repository, URL, domain, or IP with Strix — autonomous AI penetration testing that exploits and proves vulnerabilities (OWASP Top 10 and beyond — injection, XSS, SSRF, auth/access-control flaws, IDOR, business logic) instead…
Orchestrates scoped subdomain enumeration, DNS resolution, and active web probing for bug bounty targets.
Performs whitebox static application security testing (SAST), code review, API route extraction, credential hunting, and vulnerability pattern detection in local repositories or GitHub codebases.
Analyzes scan results and code flaws, formulates security hypotheses, generates deterministic PoCs, and eliminates false positives following the "No PoC, No Finding" standard.
Applies URL encoding, header tampering, path normalization, and payload mutation to bypass Web Application Firewalls (WAF) when testing valid vulnerabilities.
Discovers web application endpoints, Javascript files, hidden paths, and technology fingerprints using httpx and katana.
Authorized bug-bounty / web-pentest methodology for New API (and One API fork) AI-gateway deployments, including their storefront (Midtrans) and LibreChat chat-GUI ecosystem. Covers endpoint mining, known patched decoys, access-control verification, and the…
Master orchestrator skill for end-to-end authorized web application penetration testing, mapping OWASP Top 10 vulnerabilities, coordinating specialized sub-skills, source code auditing, browser automation, and deterministic PoC reporting.