offensive-waf-bypass
WAF bypass techniques checklist: encoding bypass (URL/HTML/Unicode/double encoding), case variation, comment injection, HTTP header manipulation, chunked encoding, IP rotation, timing attacks, and payload obfuscation per WAF vendor. Use when WAF is blocking payloads during web app tests.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-waf-bypass/SKILL.md
- skills/offensive-waf-bypass/LICENSE
- skills/offensive-waf-bypass/README.md
- skills/offensive-waf-bypass/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.