web-pentest
Installation
SKILL.md
Web Application Penetration Testing
When to Activate
- Web application security assessment (black/grey/white box)
- API security testing (REST, GraphQL, WebSocket)
- Authentication & session management testing (JWT, OAuth/OIDC, SAML)
- Business-logic and race-condition hunting
- WAF/CSP bypass, filter evasion, and CDN-layer attacks (desync, cache)
- Validating modern 2024-2026 vectors: HTTP/1.1 desync (0.CL/TE.0), SSRF->cloud metadata, prototype-pollution->RCE, SSTI sandbox escapes
Input-Signal Routing (what to test when you see X)
Fast test selection — map an observed parameter/behavior to the right deep-dive: