Use when pentesting a web application or API — injection, XSS/CSP, SSRF/cloud-metadata, HTTP desync & cache poisoning, SSTI/prototype-pollution/deserialization, JWT/OAuth/GraphQL/IDOR, business logic & single-packet race
$npx -y skills add hypnguyen1209/offensive-claude --skill web-pentestInstalls into the current project.
Run `npx skills use "https://github.com/hypnguyen1209/offensive-claude" --skill "hypnguyen1209/offensive-claude/web-pentest"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/hypnguyen1209/offensive-claude" that are relevant to the current task. Run `npx skills add "https://github.com/hypnguyen1209/offensive-claude"` and select the relevant skills, then follow their instructions.