Skip to main content

ersinkoc/security-check

SkillsMP has collected 49 skills from ersinkoc/security-check. Open a skill to review its source and details.

Latest recorded source activity
SkillsMP catalog refreshed
skills collected
49
GitHub stars
56
GitHub forks
5

Skills in this repository

2 occupation categories · 100% classified

Showing 40 of 49 collected skills.

occupation
Information Security Analysts
description

Comprehensive AI-powered security scanning suite with 48 skills covering OWASP Top 10, 7 language-specific deep scanners (Go, TypeScript, Python, PHP, Rust, Java, C#), supply chain analysis, infrastructure-as-code scanning, and 3000+ checklist items. Use when…

updated
occupation
Information Security Analysts
description

C#/.NET-specific security deep scan

updated
occupation
Information Security Analysts
description

Go-specific security deep scan

updated
occupation
Information Security Analysts
description

Java/Kotlin-specific security deep scan

updated
occupation
Information Security Analysts
description

PHP-specific security deep scan

updated
occupation
Information Security Analysts
description

Python-specific security deep scan

updated
occupation
Information Security Analysts
description

Rust-specific security deep scan

updated
occupation
Information Security Analysts
description

TypeScript/JavaScript-specific security deep scan

updated
occupation
Information Security Analysts
description

REST, GraphQL, and gRPC API security audit — authentication, authorization, data exposure, and configuration

updated
occupation
Information Security Analysts
description

Authentication flaw detection — weak passwords, broken auth, credential stuffing, and bypass vectors

updated
occupation
Information Security Analysts
description

Authorization flaw detection — IDOR, broken access control, horizontal and vertical privilege issues

updated
occupation
Information Security Analysts
description

Business logic flaw detection — price manipulation, workflow bypass, race conditions, and abuse vectors

updated
occupation
Information Security Analysts
description

CI/CD pipeline security — GitHub Actions injection, secret exposure, untrusted actions, and artifact poisoning

updated
occupation
Information Security Analysts
description

Clickjacking and UI redressing detection — missing frame protection headers and CSP frame-ancestors

updated
occupation
Information Security Analysts
description

OS Command Injection detection in shell execution, subprocess calls, and process spawning

updated
occupation
Information Security Analysts
description

CORS misconfiguration detection — wildcard origin, reflected origin, null origin, and credential leaks

updated
occupation
Information Security Analysts
description

Cryptography misuse detection — weak algorithms, ECB mode, static IVs, weak PRNG, and key management flaws

updated
occupation
Information Security Analysts
description

Cross-Site Request Forgery detection — missing tokens, SameSite misconfiguration, and CORS-CSRF interaction

updated
occupation
Information Security Analysts
description

Sensitive data exposure detection — PII leaks, verbose errors, debug mode, and information disclosure

updated
occupation
Information Security Analysts
description

Supply chain and dependency security analysis across all package ecosystems

updated
occupation
Information Security Analysts
description

Insecure deserialization detection across all serialization formats and languages

updated
occupation
Information Security Analysts
description

Incremental security scan for changed files only — optimized for PR and commit-level reviews

updated
occupation
Information Security Analysts
description

Docker-specific security checks — image hardening, secrets in layers, compose security, and runtime configuration

updated
occupation
Information Security Analysts
description

Insecure file upload detection — unrestricted types, MIME mismatch, polyglot files, and webshell upload

updated
occupation
Information Security Analysts
description

GraphQL injection, introspection abuse, query complexity attacks, and authorization bypass detection

updated
occupation
Information Security Analysts
description

HTTP Header Injection and Response Splitting detection via CRLF injection in headers

updated
occupation
Information Security Analysts
description

Infrastructure-as-Code security scanning — Dockerfile, Kubernetes, Terraform, and GitHub Actions misconfigurations

updated
occupation
Information Security Analysts
description

JWT implementation flaw detection — algorithm confusion, weak secrets, missing validation, and storage issues

updated
occupation
Information Security Analysts
description

LDAP Injection detection in search filters, DN construction, and bind operations

updated
occupation
Information Security Analysts
description

Mass assignment and over-posting detection — unfiltered request body binding to data models

updated
occupation
Information Security Analysts
description

NoSQL Injection detection for MongoDB, Redis, CouchDB, and Elasticsearch

updated
occupation
Information Security Analysts
description

Open redirect detection — unvalidated redirect URLs, protocol-relative bypasses, and URI scheme abuse

updated
occupation
Software Developers
description

Master orchestration skill that coordinates the entire 4-phase security scanning pipeline

updated
occupation
Software Developers
description

Path traversal and directory traversal detection — LFI, RFI, zip slip, and symlink attacks

updated
occupation
Software Developers
description

Privilege escalation vector detection — role manipulation, admin bypass, and RBAC circumvention

updated
occupation
Software Developers
description

Race condition and TOCTOU detection — database races, file system races, double-spend, and atomicity failures

updated
occupation
Software Developers
description

Missing rate limiting and application-level DoS vector detection — ReDoS, query complexity, resource exhaustion

updated
occupation
Software Developers
description

Remote Code Execution detection via eval, exec, dynamic code loading, and code injection vectors

updated
occupation
Software Developers
description

Codebase discovery and architecture mapping for security analysis

updated
occupation
Software Developers
description

Final consolidated security assessment report generator with CVSS severity and remediation roadmap

updated
Showing 40 of 49 collected skills.