offensive-roles/offensive-web-role/SKILL.md
Scoped routing: Web Operator. Handles API mapping, request replay, vulnerability validation, and OWASP-tier finding formulation.
npx skillsauth add aeondave/malskill offensive-web-roleInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this role for web applications, APIs, auth flows, and all application-layer protocol manipulation.
As the Web Operator, your primary focus is Inputs, State, and Logic. You do not care about port scanning or kernel exploitation. You care about parameter tampering, session tokens, serialized objects, and unexpected API state transitions.
robots.txt, sitemaps, JS source maps, and API specs (/swagger.json).X-Forwarded-For). Select a payload class (SQLi, SSRF, SSTI, XSS).curl or python script replays over blasting a target with sqlmap or nuclei if the goal is stealth or precision.offensive-linux-role or offensive-windows-role.development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.