Agent Skill
2/7/2026

a05-security-misconfiguration

Skills for exploiting security misconfigurations including XXE, file upload, subdomain takeover, and cache issues per OWASP A05:2021.

O
omkar
0GitHub Stars
1Views
npx skills add omkar-ukirde/RedStrike.AI

SKILL.md

Namea05-security-misconfiguration
DescriptionSkills for exploiting security misconfigurations including XXE, file upload, subdomain takeover, and cache issues per OWASP A05:2021.

name: a05-security-misconfiguration description: Skills for exploiting security misconfigurations including XXE, file upload, subdomain takeover, and cache issues per OWASP A05:2021. compatibility: Requires xxeinjector, nuclei allowed-tools: xxeinjector nuclei burpsuite curl metadata: owasp: A05:2021 category: web

Security Misconfiguration (OWASP A05)

Missing or improperly configured security controls at any level of the application stack.

Skills

Quick Reference

AttackTargetImpact
XXEXML parsersFile read, SSRF, RCE
File UploadUpload endpointsWebshell, RCE
Subdomain TakeoverDangling DNSPhishing, cookies
Cache DeceptionCDN/proxyData theft
Skills Info
Original Name:a05-security-misconfigurationAuthor:omkar