server-side
Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.
How do I install this agent skill?
npx skills add https://github.com/transilienceai/communitytools --skill server-sideIs this agent skill safe to install?
- Gen Agent Trust Hubfail
This skill is a security testing toolkit that provides detailed instructions and functional payloads for exploiting server-side vulnerabilities, including SSRF, Path Traversal, and Remote Code Execution (RCE). It includes functional web shells for multiple languages and a Python script for generating malicious ASP.NET ViewState tokens. Automated scans identified several files as containing malicious patterns.
- Socketfail
33 alerts: gptSecurity, gptAnomaly, gptMalware
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Server-Side
Test for server-side vulnerabilities that allow unauthorized access, RCE, or data exfiltration.
Techniques
| Type | Key Vectors |
|---|---|
| SSRF | Internal service access, cloud metadata, protocol smuggling |
| HTTP Smuggling | CL.TE, TE.CL, TE.TE, CL.0, H2.CL, h2c, multi-layer proxy chains, connection pooling desync |
| Path Traversal | Directory traversal, null bytes, encoding bypass |
| File Upload | Extension bypass, content-type manipulation, polyglot files |
| Deserialization | Java, PHP, Python, .NET gadget chains |
| Host Header | Password reset poisoning, cache poisoning, routing-based SSRF |
| CUPS / cups-browsed | CVE-2024-47076/47175/47176/47177 — UDP browse → IPP injection → PPD injection → foomatic-rip RCE (see skills/infrastructure/reference/scenarios/network-recon/cups-browsed-rce.md) |
Workflow
- Identify server-side processing points
- Test for vulnerability class indicators
- Bypass protections (WAF, allowlists, encoding filters)
- Demonstrate impact (file read, RCE, internal access)
- Capture evidence with PoC
Reference
reference/scenarios/ssrf/*.md- SSRF techniques and labsreference/http-request-smuggling*.md- Smuggling techniquesreference/scenarios/path-traversal/*.md- Path traversal bypass methodsreference/file-upload*.md- File upload exploitationreference/insecure-deserialization*.md- Deserialization attacksreference/http-host-header*.md- Host header injectionskills/infrastructure/reference/scenarios/network-recon/cups-browsed-rce.md- CUPS RCE chain (CVE-2024-47076/175/176/177); ipptool false positives vs libcups runtime parser; ippserver Python lib version-1.1 hardcode bug
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/transilienceai/communitytools/server-side">View server-side on skillZs</a>