# ByamB4

> Open-source publisher. Listings imported from github.com/ByamB4 — credited to the original author with their license.

- **Listings:** 21
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/byamb4
- **Website:** https://github.com/ByamB4

## Published listings

- [Xxe](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-xxe) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-xxe`
  Detect XML External Entity injection where XML parsers process untrusted input with external entity loading enabled, allowing file read or SSRF.
- [Recursion Dos](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-recursion-dos) — Skill · Free — `agentstack add skill-byamb4-find-cve-agent-recursion-dos`
  Detect stack overflow and infinite recursion DoS in recursive parsers, tree walkers, and serializers that lack depth limits.
- [Prototype Pollution](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-prototype-pollution) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-prototype-pollution`
  Detect prototype pollution via object merge/clone/assign operations where __proto__ or constructor.prototype keys can modify Object.prototype.
- [Target Recon](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-target-recon) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-target-recon`
  Target discovery methodology for finding high-quality npm/PyPI/GitHub packages to audit for vulnerabilities, with evaluation criteria and search strategies.
- [Ssrf](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-ssrf) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-ssrf`
  Detect Server-Side Request Forgery where user-controlled URLs can reach internal services, cloud metadata endpoints, or bypass network boundaries.
- [Fp Check](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-fp-check) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-fp-check`
  Systematic false positive elimination for security findings. 6-gate verification, 13-item checklist, devil's advocate questioning. MANDATORY before any CVE submission.
- [Entity Expansion](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-entity-expansion) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-entity-expansion`
  Detect XML/SVG/YAML entity expansion (Billion Laughs) vulnerabilities in parsers that allow unbounded entity definitions.
- [Sandbox Escape](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-sandbox-escape) — Skill · Free — `agentstack add skill-byamb4-find-cve-agent-sandbox-escape`
  Detect VM/sandbox escape vulnerabilities in packages using node:vm, simpleeval, or custom sandboxes that can be bypassed to achieve code execution.
- [Decompression Bomb](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-decompression-bomb) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-decompression-bomb`
  Detect decompression bomb vulnerabilities where compressed input can expand to exhaust memory, targeting buffer-based decompression without size limits.
- [Path Traversal](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-path-traversal) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-path-traversal`
  Detect path traversal and Zip Slip vulnerabilities where user-controlled path components can escape intended directories.
- [Jwt Attacks](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-jwt-attacks) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-jwt-attacks`
  Detect JWT implementation vulnerabilities including algorithm confusion, none algorithm acceptance, weak secrets, and JWK injection attacks.
- [Redos](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-redos) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-redos`
  Detect Regular Expression Denial of Service (ReDoS) where crafted input causes catastrophic backtracking in regex patterns applied to user-controlled strings.
- [Code Injection Codegen](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-code-injection-codegen) — Skill · Free — `agentstack add skill-byamb4-find-cve-agent-code-injection-codegen`
  Detect code injection vulnerabilities in packages that dynamically generate or evaluate code via new Function(), eval(), vm.run*, or template literal interpolation.
- [Ssti](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-ssti) — Skill · Free — `agentstack add skill-byamb4-find-cve-agent-ssti`
  Detect Server-Side Template Injection where user input is passed as the template string itself rather than as template variables, enabling code execution.
- [Method Clobbering](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-method-clobbering) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-method-clobbering`
  Detect method clobbering via user-controlled object keys that overwrite built-in methods like toString, valueOf, or hasOwnProperty, causing crashes or logic bypass.
- [Advisory Mining](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-advisory-mining) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-advisory-mining`
  Mine GitHub Security Advisories and CVE databases for incomplete fixes, finding variant vulnerabilities in patched code or similar patterns in related packages.
- [Auth Bypass](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-auth-bypass) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-auth-bypass`
  Detect authentication and authorization bypass vulnerabilities including missing auth middleware, JWT algorithm confusion, IDOR, and session fixation.
- [Report Writing](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-report-writing) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-report-writing`
  Generate polished, human-sounding vulnerability disclosure reports for GHSA, HackerOne, and email. Auto-selects channel, calculates CVSS, and adapts tone.
- [Command Injection](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-command-injection) — Skill · Free — `agentstack add skill-byamb4-find-cve-agent-command-injection`
  Detect OS command injection via shell execution sinks where user-controlled input reaches system commands without proper sanitization.
- [Sqli](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-sqli) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-sqli`
  Detect SQL injection where user input reaches SQL query construction through string concatenation, template literals, or ORM raw query methods.
- [Cross Pollination](https://agentstack.voostack.com/l/skill-byamb4-find-cve-agent-cross-pollination) — Skill · Free · security-reviewed — `agentstack add skill-byamb4-find-cve-agent-cross-pollination`
  Cross-pollination multiplier technique: find a vulnerability in one package, then search for the same pattern across all similar packages to multiply findings.

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
