Security fuzzing
bb-huge 🤗 , Personal bug bounty findings hub and bug bounty orchestration for multiple agents
npx -y skills add ShulkwiSEC/bb-huge --skill security-fuzzingAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 18 stars18 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
SKILL.md
2.5 KB, as published. Nobody here has run it
SecLists Fuzzing (Curated)
Description
Essential fuzzing payloads: SQL injection, command injection, special characters. Curated essentials for vulnerability testing.
Source: SecLists/Fuzzing Repository: https://github.com/danielmiessler/SecLists License: MIT
When to Use This Skill
Use this skill when you need:
- SQL injection testing
- Command injection testing
- Input validation testing
- LDAP injection
- NoSQL injection
⚠️ IMPORTANT: Only use for authorized security testing, bug bounty programs, CTF competitions, or educational purposes.
Key Files in This Skill
quick-SQLi.txt - Quick SQL injection testsGeneric-SQLi.txt - Generic SQL injectionsqli.auth.bypass.txt - Authentication bypassMySQL.fuzzdb.txt - MySQL-specific payloadsNoSQL.txt - NoSQL injection payloadscommand-injection-commix.txt - Command injection
Usage Example
# Access files from this skill
import os
# Example: Load patterns/payloads
skill_path = "references/Fuzzing"
# List all available files
for root, dirs, files in os.walk(skill_path):
for file in files:
if file.endswith('.txt'):
filepath = os.path.join(root, file)
print(f"Found: {filepath}")
# Read file content
with open(filepath, 'r', errors='ignore') as f:
content = f.read().splitlines()
print(f" Lines: {len(content)}")
Security & Ethics
Authorized Use Cases ✅
- Authorized penetration testing with written permission
- Bug bounty programs (within scope)
- CTF competitions
- Security research in controlled environments
- Testing your own systems
- Educational demonstrations
Prohibited Use Cases ❌
- Unauthorized access attempts
- Testing without permission
- Malicious activities
- Privacy violations
- Any illegal activities
Complete SecLists Collection
This is a curated subset of SecLists. For the complete collection:
- Full repository: https://github.com/danielmiessler/SecLists
- Size: 4.5 GB with 6,000+ files
- All categories: Passwords, Usernames, Discovery, Fuzzing, Payloads, Web-Shells, Pattern-Matching, AI, Miscellaneous
Generated by Skill Seeker | SecLists Fuzzing Collection License: MIT - Use responsibly with proper authorization