web-exploit-technique
Installation
SKILL.md
Web-exploit technique
Goal: turn a confirmed web vulnerability into maximum impact — data extraction, authentication bypass, RCE, or persistent access — using the precise exploitation path for each vulnerability class.
When this technique applies
vuln-search-techniqueproduced confirmed web vulnerability findings.- Vulnerability class is known (SQLi, SSRF, XSS, SSTI, file upload, etc.).
- Need to prove exploitability and assess actual business impact.
- Engagement scope includes web application exploitation.
Boundary
- Input: confirmed vulnerability + surface + class from
vuln-search-technique. - Infrastructure exploitation (CVE-based, service-level): use
vuln-exploit-technique. - Post-exploitation lateral movement: separate engagement after initial access established.
- Deep custom exploit development:
offensive-coding/skills for BOF, shellcode, ROP. - LLM-backed features / prompt injection into web apps (chat widgets, AI summarizers, RAG endpoints, agentic tools reachable over HTTP): route to
llm-technique— same HTTP surface, but exploitation model, evidence, and impact chain differ from classic web bugs.