AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Attack Chain Web2

skill-sekolah76-syadagentic-attack-chain-web2 · by Sekolah76

Web2 attack chain plugin — apply Web2 trust boundaries and composition rules on top of attack-chaining-core for authorized testing of web apps, APIs, identity, cloud, and internal services.

— No reviews yet
0 installs
0 views
— view→install

Install

$ agentstack add skill-sekolah76-syadagentic-attack-chain-web2

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-sekolah76-syadagentic-attack-chain-web2)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
● 1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Attack Chain Web2? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Web2 Attack Chain Plugin

Purpose

Apply Web2-specific trust boundaries and composition rules on top of attack-chaining-core for authorized testing of web applications, APIs, identity systems, cloud deployments, and internal services.

Always run the core procedure first. This plugin supplies domain semantics; it does not waive evidence requirements.

Primary Web2 chain surfaces

  • authentication, registration, recovery, MFA, SSO, OAuth/OIDC, and session lifecycle;
  • object- and function-level authorization;
  • multi-tenant boundaries;
  • file upload, parsing, storage, and delivery;
  • SSRF and internal service reachability;
  • cloud metadata, IAM, secrets, queues, and storage;
  • web cache, proxy, host/routing, and request interpretation differences;
  • injection primitives and server-side execution;
  • client-side execution combined with account/session impact;
  • business-logic state machines and race conditions.

Web2 capability rules

Identity and session

Do not treat these as equivalent without proof:

  • knowing an email address;
  • knowing a user ID;
  • obtaining a reset token;
  • setting a session cookie;
  • obtaining an authenticated session;
  • bypassing MFA;
  • impersonating an administrator.

Check token purpose, audience, expiry, one-time use, binding, rotation, SameSite/domain/path, device/session binding, and revocation.

Authorization

For IDOR/BOLA chains prove that the identifier from one step can be used against the exact object/action in the next step. Check tenant scoping, indirect references, ownership revalidation, and backend service authorization.

SSRF and cloud pivots

Separate:

  • outbound request confirmed;
  • internal host reachable;
  • response readable;
  • headers/method controllable;
  • metadata protections bypassed;
  • credentials obtained;
  • credentials valid for a specific principal;
  • IAM permission allows a protected action.

A blind SSRF is not automatically cloud compromise.

File chains

Track file bytes, content type, extension, storage key, transformation, execution context, and delivery origin. Upload alone is not execution. Parsing bugs must establish attacker-controlled content reaching the vulnerable parser in a relevant profile.

Client-to-server chains

XSS or open redirect does not automatically imply account takeover. Establish victim requirements, cookie accessibility, CSRF protections, token exposure, privileged actions, and practical delivery.

Cache/proxy/request-smuggling chains

Prove front-end/back-end interpretation mismatch in the actual deployment and show how the poisoned or desynchronized request reaches a protected victim or route. Local parser disagreement alone is insufficient.

Common valid composition patterns

Use only as hypotheses:

  • information disclosure -> credential/token acquisition -> authenticated action;
  • account enumeration -> recovery weakness -> session acquisition;
  • low-privilege write -> stored client execution -> privileged action;
  • SSRF -> internal discovery -> secret acquisition -> IAM-authorized impact;
  • path/canonicalization mismatch -> authorization bypass -> protected object access;
  • upload primitive -> server-side parser/handler -> execution or data access;
  • cache poisoning -> victim request influence -> account/data impact;
  • race/business-logic flaw -> invariant bypass -> unauthorized value/state change.

Web2 chain blockers

Explicitly test:

  • token audience and nonce mismatch;
  • cookies inaccessible to script;
  • reauthentication/MFA before sensitive actions;
  • backend authorization independent of UI;
  • tenant ID derived from trusted identity;
  • egress filtering and metadata protections;
  • short-lived or non-exportable credentials;
  • upload re-encoding and isolated delivery domains;
  • CSP and browser behavior;
  • proxy normalization;
  • idempotency and transaction locking;
  • rate limits and fraud controls.

Required output additions

Include:

  • identity and tenant context per step;
  • session/token lifecycle table;
  • trust-boundary crossings;
  • victim interaction requirements;
  • cloud/IAM principal and exact permissions when applicable;
  • browser/proxy/backend assumptions;
  • safe reproduction plan using owned accounts and synthetic data.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.