TacoSkill LAB

The marketplace for AI agent skills

Product

  • SkillHub
  • Playground
  • Create
  • SkillKit

Resources

  • Privacy
  • Terms
  • About

Platforms

  • Claude Code
  • Cursor
  • Codex CLI
  • Gemini CLI
  • OpenCode

© 2026 TacoSkill LAB. All rights reserved.

TacoSkill LAB
TacoSkill LAB
HomeSkillHubCreatePlaygroundSkillKit
  1. Home
  2. /
  3. SkillHub
  4. /
  5. Scenario:
Improve

Scenario:

3.1

by majiayu000

117Favorites
144Upvotes
0Downvotes

Performing a web app pentest for sof comanpym and task y iwth testing the lastest of their social network web app. Try to escalate your privileges and exploit different vulnerabilities to read the flag at '/flag.php'.

pentest

3.1

Rating

0

Installs

Security

Category

Quick Review

This skill documents a web application penetration testing scenario with specific vulnerabilities (IDOR, XXE). While it provides concrete exploitation steps including XXE payload for reading /flag.php, the description is poorly written with typos and unclear phrasing ('sof comanpym and task y iwth'), making it difficult for a CLI agent to understand the objective. The write-up shows a logical exploitation chain (enumeration → IDOR → password reset → XXE), but lacks sufficient detail for automation (missing specific API endpoints, payload delivery methods, and clear step-by-step instructions). The structure is minimal with referenced images that provide context. Novelty is moderate - while pentesting requires specialized knowledge, the specific vulnerabilities shown (IDOR, XXE) are common patterns that a capable CLI agent with security tools could potentially discover independently, though this skill does reduce token cost by documenting the specific path. The skill would benefit significantly from clearer description, more detailed technical steps, and better formatting for programmatic consumption.

LLM Signals

Description coverage2
Task knowledge5
Structure3
Novelty3

GitHub Signals

49
7
1
1
Last commit 0 days ago

Publisher

majiayu000

majiayu000

Skill Author

Related Skills

secure-code-guardiansecurity-reviewerrepomix-safe-mixer

Loading SKILL.md…

Try onlineView on GitHub

Publisher

majiayu000 avatar
majiayu000

Skill Author

Related Skills

secure-code-guardian

Jeffallan

6.4

security-reviewer

Jeffallan

6.4

repomix-safe-mixer

daymade

7.4

iotnet

BrownFineSecurity

6.3
Try online