Skip to main content

getsentry/warden-skills

SkillsMP has collected 7 skills from getsentry/warden-skills. Open a skill to review its source and details.

Latest recorded source activity
SkillsMP catalog refreshed
skills collected
7
GitHub stars
57
GitHub forks
3

Skills in this repository

1 occupation categories · 86% classified

Showing 7 of 7 collected skills.

occupation
unclassified
description

Finds availability / denial-of-service bugs reachable from untrusted input — unbounded allocation, uncontrolled recursion, non-terminating loops, decompression bombs, panic/resource-leak, super-linear output amplification, algorithmic-complexity / ReDoS…

updated
occupation
Information Security Analysts
description

Detects broad web application security vulnerabilities using the Vercel DeepSec benchmark prompt. Use when benchmarking security review coverage or running an open-ended appsec scan for auth bypass, missing auth, XSS, RCE, SQL injection, SSRF, path traversal,…

updated
occupation
Information Security Analysts
description

Detects exploitable GitHub Actions workflow vulnerabilities, including pull_request_target pwn requests, unsafe PR checkout, expression injection in run steps and actions/github-script blocks, workflow_dispatch and workflow_call input command injection,…

updated
occupation
Information Security Analysts
description

Detects real personally identifiable information, customer identifiers, and customer-confidential business data in code changes. Use when asked to find PII, customer IPs, real email addresses, revenue data, billing data, personal data, privacy leaks, customer…

updated
occupation
Information Security Analysts
description

Detects authorization flaws: IDOR, missing ownership or tenant scoping, role checks that fail open, privilege escalation, unauthenticated admin actions, mass assignment, and token/session claims trusted for permission decisions. Use when asked to review route…

updated
occupation
Information Security Analysts
description

Detects bugs where untrusted input reaches a sink that produces code or command execution on the server. Covers command/shell injection, unsafe deserialization, server-side template injection, eval/Function/vm reached by user data, XXE-to-RCE gadgets, and…

updated
occupation
Information Security Analysts
description

Detects bugs where untrusted input reaches a sink that leaks data beyond its intended scope. Covers SSRF (including cloud metadata, internal services, image proxies), path traversal and archive zip-slip, SQL/NoSQL injection enabling bulk reads, XXE file read,…

updated
Showing 7 of 7 collected skills.