.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/fsociety/waf-bypass
home/skills/ogrodev/fsociety/waf-bypass
ogrodev avatar

waf-bypass

byogrodev· 25 skills

Stars

20

Forks

2

Category

Security

View on GitHub

TL;DR

This skill should be used when the user mentions "WAF", "web application firewall", "WAF bypass", "WAF evasion", "WAF detection", "WAF fingerprint", "wafw00f", "firewall bypass", "firewall evasion", "request filtering", "request blocked", "payload blocked", "blocked by WAF", "403 forbidden", "406 not acceptable", "429 too many requests", "rate limit", "rate limiting", "IP ban", "IP block", "IP reputation", "IP blacklist", "CDN bypass", "origin IP", "origin discovery", "Cloudflare", "Cloudflare bypass", "CF bypass", "Cloudflare WAF", "AWS WAF", "AWS Shield", "AWS managed rules", "Akamai", "Akamai Kona", "Akamai WAF", "Imperva", "Incapsula", "Imperva WAF", "ModSecurity", "OWASP CRS", "Core Rule Set", "ModSec", "paranoia level", "Sucuri", "Sucuri WAF", "F5 BIG-IP", "F5 ASM", "Barracuda WAF", "Fortinet FortiWeb", "FortiWeb", "Citrix WAF", "Azure WAF", "Azure Front Door", "payload encoding", "double encoding", "URL encoding bypass", "Unicode normalization", "Unicode bypass", "null byte injection", "comment injection", "obfuscation", "mixed encoding", "hex encoding", "HTML entity encoding", "overlong UTF-8", "HTTP verb tampering", "method tampering", "HTTP/2 smuggling", "request smuggling", "chunked transfer", "chunked encoding", "content-type switching", "multipart abuse", "multipart boundary", "transfer-encoding", "HTTP parameter pollution", "HPP", "tamper script", "sqlmap tamper", "WAF rule bypass", "WAF rule evasion", "managed rules bypass", "custom rules bypass", "regex bypass", "regex evasion", "WAF fingerprinting", "WAF identification", "WAF detection technique", "nmap http-waf-detect", "nmap http-waf-fingerprint", "WAF error page", "WAF signature", "WAF response analysis", "security header analysis", "X-Forwarded-For bypass", "header injection bypass", "path normalization", "path confusion", "path traversal bypass", "directory traversal bypass".

How to install waf-bypass?

ogrodev/fsociety/waf-bypass
$npx -y skills add ogrodev/fsociety --skill waf-bypass

Installs into the current project.

›Prefer a prompt? Paste this to your agent

Use this skill

Run `npx skills use "https://github.com/ogrodev/fsociety" --skill "ogrodev/fsociety/waf-bypass"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.

Use the whole pack

Use the skills in "https://github.com/ogrodev/fsociety" that are relevant to the current task. Run `npx skills add "https://github.com/ogrodev/fsociety"` and select the relevant skills, then follow their instructions.

Preview

ogrodev/fsocietyogrodev/fsociety

$ npx -y skills add ogrodev/fsociety --skill waf-bypass

▸ installing to .claude/skills…

✓ waf-bypass ready

Repoogrodev/fsociety
TypeSkills
CategorySecurity
ForOpsArchitect
UpdatedMar 2026
License—
First seenJul 27, 2026

Tags

Skill

Related

6 picks
Type
  1. microsoft avatarentra-app-registrationGuides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.SkillsJul 2026484k1.3k
  2. microsoft avatarazure-complianceRun Azure compliance and security audits with azqr plus Key Vault expiration checks.SkillsJul 2026484k1.3k
  3. microsoft avatarentra-agent-idProvision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token…SkillsJul 2026207k1.3k
  4. firebase avatarfirebase-security-rules-auditorAudits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource…SkillsJul 202680k389
  5. samber avatargolang-securitySecurity best practices and vulnerability prevention for Golang.SkillsJul 202635k2.7k
  6. googleworkspace avatargws-modelarmorGoogle Model Armor: Filter user-generated content for safety.SkillsJul 202624k30k