بنقرة واحدة
laravelversions
يحتوي laravelversions على 12 من skills المجمعة من tighten، مع تغطية مهنية على مستوى المستودع وصفحات skill داخل الموقع.
Skills في هذا المستودع
Run Frisk's agentic security audit — dispatch specialized scanner subagents in parallel and write the aggregated results to .frisk/agentic-findings.json so the Frisk CLI can ingest them.
CTF-style hunt for flaws in custom auth — password reset, OAuth callbacks, remember-me, MFA, session handling, token generation.
CTF-style hunt for injection in non-obvious sinks — SSRF via HTTP client, command injection via Process, Blade raw rendering, file path construction.
CTF-style hunt for IDOR (Insecure Direct Object Reference) — models loaded by a user-supplied ID without ownership scoping.
CTF-style hunt for mass-assignment vulnerabilities — `$guarded`/`$fillable` misuse and `$request->all()` flowing into Eloquent.
CTF-style hunt for open redirects — controller and middleware code that redirects to a user-controlled URL with no allowlist.
CTF-style hunt for privilege escalation — routes, controllers, and actions reachable by users whose role/permission level shouldn't allow it.
CTF-style hunt for prompt injection — user input flowing into LLM message payloads without sandboxing, and trusted LLM responses driving permission decisions or interpolated into Slack/HTML/markdown channels.
CTF-style hunt for race conditions and atomicity bugs — read-then-write on money/credits/quotas without locking, non-idempotent webhook handlers, double-spend windows.
CTF-style hunt for tokens, hashes, secrets, and PII leaking via API responses, logs, error pages, or cached views.
CTF-style hunt for cross-tenant data leakage in multi-tenant apps — queries that skip tenant scoping, jobs that drop tenant context, cache keys missing tenant prefix, shared storage paths.
CTF-style hunt for unverified or weakly-verified inbound webhooks — missing HMAC checks, timing-unsafe comparisons, missing replay protection, hand-rolled signed-URL verification.