Skip to content
OpenSmartRoute

Marketplace

Everything your AI needs, in one place.

Ready-made agents, skills, personas, prompts, templates and tools. Each one is checked before it goes live, works with any model, and installs in a click. Rate what you use so the best rises to the top.

143.8K
listings
1
installs
0
reviews
38.7K
publishers
51 results
Skill

exploiting-http-request-smuggling

Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length disa

by mukul975skills.sh
(0)
0Free
Skill

exploiting-idor-vulnerabilities

Identifies and exploits Insecure Direct Object Reference (IDOR) vulnerabilities by manipulating object identifiers (numeric IDs, UUIDs, slugs) in API requests and URLs, using Burp Suite proxy history,

by mukul975skills.sh
(0)
0Free
Skill

exploiting-insecure-deserialization

Identifying and exploiting insecure deserialization vulnerabilities in Java, PHP, Python, and .NET applications to achieve remote code execution during authorized penetration tests.

by mukul975skills.sh
(0)
0Free
Skill

exploiting-nosql-injection-vulnerabilities

Detects and exploits NoSQL injection vulnerabilities in MongoDB, CouchDB, and similar databases to demonstrate authentication bypass, data extraction, and unauthorized access via crafted query operato

by mukul975skills.sh
(0)
0Free
Skill

exploiting-oauth-misconfiguration

Identifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect URI manipulation, token leakage, and authorization code theft during security assessments.

by mukul975skills.sh
(0)
0Free
Skill

exploiting-server-side-request-forgery

Identifying and exploiting SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.

by mukul975skills.sh
(0)
0Free
Skill

exploiting-sql-injection-with-sqlmap

Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests.

by mukul975skills.sh
(0)
0Free
Skill

exploiting-template-injection-vulnerabilities

Detects and exploits Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution. Use when pentesting a web appli

by mukul975skills.sh
(0)
0Free
Skill

exploiting-type-juggling-vulnerabilities

Exploits PHP type juggling vulnerabilities caused by loose (==) comparison operators to bypass authentication, defeat hash verification via magic hashes, and manipulate application logic through type

by mukul975skills.sh
(0)
0Free
Skill

exploiting-websocket-vulnerabilities

Testing WebSocket implementations for authentication bypass, cross-site hijacking, injection attacks, and insecure message handling during authorized security assessments.

by mukul975skills.sh
(0)
0Free
Skill

implementing-web-application-logging-with-modsecurity

Configure ModSecurity WAF with the OWASP Core Rule Set (CRS) for web application audit logging, tuning SecRuleEngine, SecAuditEngine, and CRS paranoia levels to reduce false positives, and writing cus

by mukul975skills.sh
(0)
0Free
Skill

performing-clickjacking-attack-test

Testing web applications for clickjacking vulnerabilities by assessing frame embedding controls and crafting proof-of-concept overlay attacks during authorized security assessments.

by mukul975skills.sh
(0)
0Free
Skill

performing-csrf-attack-simulation

Testing web applications for Cross-Site Request Forgery vulnerabilities by crafting forged requests that exploit authenticated user sessions during authorized security assessments.

by mukul975skills.sh
(0)
0Free
Skill

performing-directory-traversal-testing

Test web applications for path traversal and Local/Remote File Inclusion vulnerabilities by manipulating file path parameters, applying encoding and filter-bypass techniques, automating discovery with

by mukul975skills.sh
(0)
0Free
Skill

performing-graphql-security-assessment

Assessing GraphQL API endpoints for introspection leaks, injection attacks, authorization flaws, and denial-of-service vulnerabilities during authorized security tests.

by mukul975skills.sh
(0)
0Free
Skill

performing-http-parameter-pollution-attack

Executes HTTP Parameter Pollution attacks that inject duplicate request parameters to bypass input validation, WAF rules, and other security controls when front-end and back-end systems parse duplicat

by mukul975skills.sh
(0)
0Free
Skill

performing-jwt-none-algorithm-attack

Execute and test the JWT none algorithm attack, crafting tokens with the alg header set to none using PyJWT and an intercepting proxy (Burp Suite/mitmproxy) to bypass signature verification and forge

by mukul975skills.sh
(0)
0Free
Skill

performing-second-order-sql-injection

Detect and exploit second-order SQL injection vulnerabilities where malicious input is stored in a database and later executed in an unsafe SQL query during a different application operation.

by mukul975skills.sh
(0)
0Free
Skill

performing-security-headers-audit

Auditing HTTP security headers including CSP, HSTS, X-Frame-Options, and cookie attributes to identify missing or misconfigured browser-level protections.

by mukul975skills.sh
(0)
0Free
Skill

performing-web-application-firewall-bypass

Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads pa

by mukul975skills.sh
(0)
0Free
Skill

performing-web-cache-poisoning-attack

Exploiting web cache mechanisms to serve malicious content to other users by poisoning cached responses through unkeyed headers and parameters during authorized security tests.

by mukul975skills.sh
(0)
0Free
Skill

testing-cors-misconfiguration

Identifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthorized cross-domain data access and credential theft during security assessments.

by mukul975skills.sh
(0)
0Free
Skill

testing-for-broken-access-control

Systematically tests web applications and APIs for broken access control (OWASP A01:2021), including privilege escalation, missing function-level checks, insecure direct object references, and multi-t

by mukul975skills.sh
(0)
0Free
Skill

testing-for-business-logic-vulnerabilities

Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going beyon

by mukul975skills.sh
(0)
0Free
1

Find

Search or browse by kind. Every card shows who made it, how many people installed it and what they think.

2

Install

One click. You get a manifest the router understands, plus copy-paste snippets for the CLI, Python and YAML.

3

Rate and publish

Leave a star rating after you have used it. Made something useful? Publish it - free listings go live immediately.

Prefer the terminal? osr stack apply registry://starter installs the starter template.