strix
strix copied to clipboard
Add Open Redirect, Subdomain Takeover, and Information Disclosure vulnerability guides
Problem
Currently missing three critical vulnerability types in the prompts collection:
- Open Redirect (phishing, OAuth token theft, SSRF chaining)
- Subdomain Takeover (full subdomain control, cookie theft)
- Information Disclosure (credentials, source code exposure)
Proposed Solution
Add comprehensive vulnerability guides following the existing template structure:
/strix/prompts/vulnerabilities/open_redirect.jinja/strix/prompts/vulnerabilities/subdomain_takeover.jinja/strix/prompts/vulnerabilities/information_disclosure.jinja
Benefits
- Complete coverage of OWASP Top 10 related vulnerabilities
- Enhanced AI detection capabilities for redirect-based attacks
- Better enumeration of exposed information leaks
- Subdomain security assessment capabilities