ffuf-web-fuzzing

ffuf web fuzzing for authorized pentests. Common modes, payloads, and gotchas.

Score 0(?)CommunityCodeby jthackSource
Verified for:

Install

$ npx skills add jthack/ffuf_claude_skill

Best for

Authorized pentest engagements where ffuf is part of the stack.

Not ideal for

Anything not explicitly authorized — fuzzing third-party hosts is hostile.

About this skill

Web fuzzing with ffuf for authorized penetration testing.

ffufPentestFuzzing

Score breakdown

Score breakdown

rubric 1.0
Install count
0/20
Provenance
8.3/15
GitHub stars
0/15
Recency
8.5/10
Compatibility
2/10
Documentation depth
8/10
Install ergonomics
4/10
License
5/5
Verification freshness
4.3/5

Composite 0–100 score derived from 9 verifiable signals. See the rubric →

Security audits run by a real security firm. CodeQL + Semgrep + audit workflows.

CodeQLSemgrepAudit
Code

Kubernetes hardening by the book. NetworkPolicies, RBAC, OPA, service mesh.

KubernetesRBACOPA
Code

Real exploits, no false positives. 96.15% exploit success across 50+ vuln types.

PentestExploitationAction-taking
Code