strix icon indicating copy to clipboard operation
strix copied to clipboard

Add Open Redirect, Subdomain Takeover, and Information Disclosure vulnerability guides

Open Trusthoodies opened this issue 1 month ago • 0 comments

Problem

Currently missing three critical vulnerability types in the prompts collection:

  • Open Redirect (phishing, OAuth token theft, SSRF chaining)
  • Subdomain Takeover (full subdomain control, cookie theft)
  • Information Disclosure (credentials, source code exposure)

Proposed Solution

Add comprehensive vulnerability guides following the existing template structure:

  • /strix/prompts/vulnerabilities/open_redirect.jinja
  • /strix/prompts/vulnerabilities/subdomain_takeover.jinja
  • /strix/prompts/vulnerabilities/information_disclosure.jinja

Benefits

  • Complete coverage of OWASP Top 10 related vulnerabilities
  • Enhanced AI detection capabilities for redirect-based attacks
  • Better enumeration of exposed information leaks
  • Subdomain security assessment capabilities

Trusthoodies avatar Nov 23 '25 17:11 Trusthoodies