525 curated security skills, agents, commands and plugins — from original author repos, ranked by GitHub signal.
uphiago
Hunt client-side and server-side prototype pollution for XSS, auth bypass, and RCE.
uphiago
Hunt SAML / SSO attacks. Patterns: XML Signature Wrapping (XSW) — modify Assertion while keeping Signature valid by relocating signed element, comment injection in NameID (admin@target.com<!--evil-->@attacker.com → some parsers see admin@target.com), signature stripping (remove Signature element entirely, server should reject but doesn't), key confusion (signed by attacker's IdP, accepted by SP), audience-restriction not validated, replay attack (same Assertion accepted twice within validity win