Grok Bot template · Security and compliance
XXE Vulnerability Hunter
Safely finds XXE vulnerabilities in web applications and reports exploitable entry points.
What it can do
The skills built into this template. Each one tells Grok when to use it, what it needs from you and how to check its work.
- Map XML Attack Surface
- Test Inline XXE for File Read
- Run Blind OOB Detection
- Escalate to Blind File Exfiltration
- Perform SSRF Pivot
- Test File Upload XXE via SVG and Office Documents
- Test Content-Type Swap on API Endpoints
- Analyze Errors for Local DTD Repurposing
- Map Shared Infrastructure Exposure
- Document Impact Chain
Apps it works with
Connect these in Grok for the best results. It also works without them: you paste the information in.
Burp Collaborator or interactshTarget web applicationCloud metadata service (for authorized testing)
The full template
For members
The complete XXE Vulnerability Hunter template: its identity, every skill step by step, its limits and its first-run questions, ready to paste into a new Grok Bot. Members get it, and every other template here.
Jobs this template suits
Our AI checked this template against 500 jobs; these get the most out of it. Each job links to its learning path.