/security-payloads
Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing.
$ npx -y skills add Eyadkelleh/awesome-skills-security --skill security-payloads --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/security-payloads
Context preview
The summary Claude sees to decide when to auto-load this skill.
Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing.
SKILL.md
security-payloads.SKILL.mdname: security-payloads
description: "Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing."
SecLists Payloads (Curated)
Description
Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing.
**Source:** [SecLists/Payloads](https://github.com/danielmiessler/SecLists/tree/master/Payloads) **Repository:** https://github.com/danielmiessler/SecLists **License:** MIT
When to Use This Skill
Use this skill when you need:
- Anti-virus testing
- File upload testing
- Path traversal testing
- Security control validation
**⚠️ IMPORTANT:** Only use for authorized security testing, bug bounty programs, CTF competitions, or educational purposes.
Key Files in This Skill
- `EICAR test file`
- `Null byte file names`
- `Command execution file names`
Usage Example
# Access files from this skill
import os
# Example: Load patterns/payloads
skill_path = "references/Payloads"
# List all available files
for root, dirs, files in os.walk(skill_path):
for file in files:
if file.endswith('.txt'):
filepath = os.path.join(root, file)
print(f"Found: {filepath}")
# Read file content
with open(filepath, 'r', errors='ignore') as f:
content = f.read().splitlines()
print(f" Lines: {len(content)}")Security & Ethics
Authorized Use Cases ✅
- Authorized penetration testing with written permission
- Bug bounty programs (within scope)
- CTF competitions
- Security research in controlled environments
- Testing your own systems
- Educational demonstrations
Prohibited Use Cases ❌
- Unauthorized access attempts
- Testing without permission
- Malicious activities
- Privacy violations
- Any illegal activities
Complete SecLists Collection
This is a curated subset of SecLists. For the complete collection:
- **Full repository:** https://github.com/danielmiessler/SecLists
- **Size:** 4.5 GB with 6,000+ files
- **All categories:** Passwords, Usernames, Discovery, Fuzzing, Payloads, Web-Shells, Pattern-Matching, AI, Miscellaneous
---
**Generated by Skill Seeker** | SecLists Payloads Collection **License:** MIT - Use responsibly with proper authorization
Read more
name: security-payloads description: "Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing."
SecLists Payloads (Curated)
Description
Essential exploitation payloads: anti-virus test files, file name exploits, malicious files. Curated for testing.
**Source:** [SecLists/Payloads](https://github.com/danielmiessler/SecLists/tree/master/Payloads) **Repository:** https://github.com/danielmiessler/SecLists **License:** MIT
When to Use This Skill
Use this skill when you need:
- Anti-virus testing
- File upload testing
- Path traversal testing
- Security control validation
**⚠️ IMPORTANT:** Only use for authorized security testing, bug bounty programs, CTF competitions, or educational purposes.
Key Files in This Skill
- `EICAR test file`
- `Null byte file names`
- `Command execution file names`
Usage Example
# Access files from this skill
import os
# Example: Load patterns/payloads
skill_path = "references/Payloads"
# List all available files
for root, dirs, files in os.walk(skill_path):
for file in files:
if file.endswith('.txt'):
filepath = os.path.join(root, file)
print(f"Found: {filepath}")
# Read file content
with open(filepath, 'r', errors='ignore') as f:
content = f.read().splitlines()
print(f" Lines: {len(content)}")Security & Ethics
Authorized Use Cases ✅
- Authorized penetration testing with written permission
- Bug bounty programs (within scope)
- CTF competitions
- Security research in controlled environments
- Testing your own systems
- Educational demonstrations
Prohibited Use Cases ❌
- Unauthorized access attempts
- Testing without permission
- Malicious activities
- Privacy violations
- Any illegal activities
Complete SecLists Collection
This is a curated subset of SecLists. For the complete collection:
- **Full repository:** https://github.com/danielmiessler/SecLists
- **Size:** 4.5 GB with 6,000+ files
- **All categories:** Passwords, Usernames, Discovery, Fuzzing, Payloads, Web-Shells, Pattern-Matching, AI, Miscellaneous
---
**Generated by Skill Seeker** | SecLists Payloads Collection **License:** MIT - Use responsibly with proper authorization
A curated collection of security testing resources packaged as agent skills, available on skills.sh Repository: Eyadkelleh/awesome-skills-security · skills.sh: Eyadkelleh/awesome-skills-security
Repo: Eyadkelleh/awesome-skills-security
Other skills on awesome-skills-security.
- /llm-testing
Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.
Open skill - /security-fuzzing
Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
Open skill - /security-passwords
Top password lists for authorized security testing: common passwords, darkweb leaks, worst passwords. Curated essentials (<10MB).
Open skill - /security-patterns
Sensitive data patterns for security testing: API keys, credit cards, emails, SSNs, phone numbers, IPs, and more. Use for data discovery and validation.
Open skill - /security-usernames
Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing.
Open skill - /security-webshells
Web shell samples for detection and analysis: PHP, ASP, ASPX, JSP, Python, Perl shells. Use for security research and detection system testing.
Open skill

