Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft. Use when working with testing for open redirect vulnerabilities.
Skills in this repository
oyi77/1ai-skills - Page 25
SkillsMP has collected 1,311 skills from oyi77/1ai-skills. Open a skill to review its source and details.
oyi77/1ai-skillsShowing 40 of 1,311 collected skills.
Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments. Use when working with testing for sensitive data exposure.
Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks. Use when testing web applications for xml injection vulnerabilities including xxe,…
Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies…
Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments. Use when working with testing for xss vulnerabilities with burpsuite.
Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests. Use when working with testing for xxe injection vulnerabilities.
Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements. Use when working with testing jwt token security.
Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against…
Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server,…
Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks. Use when testing…
Use when tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation,…
Investigate token and NFT scams including rug pulls, honeypot tokens, pump-and-dump schemes, wash trading, and NFT floor manipulation to identify fraudulent patterns and trace perpetrator wallets. Use when analyzing suspicious token launches, investigating…
Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a. Use when working with tracking threat actor…
Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts…
Performs initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate…
Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures. Use when working with triaging security incident with ir playbook.
Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities. Use when working with triaging vulnerabilities with ssvc framework.
AI-powered vulnerability scanning with intelligent payload generation. Use when scanning web applications for specific vulnerability types, generating exploit payloads, or running automated security tests.
Profile and cluster blockchain wallet addresses to identify entity associations, assess risk levels, and build address reputation intelligence across multiple chains. Use when analyzing wallet behavior, clustering related addresses, assessing counterparty…
Smart contract and DeFi security auditing for maximum bounty payouts. Use when auditing Solidity/Vyper contracts, testing DeFi protocols, hunting web3 vulnerabilities, or preparing Immunefi submissions.
Monetize bug bounty findings through writeups, tools, and consulting. Use when turning security research into income streams, writing paid writeups, or building a security brand.
Apache Airflow workflow orchestration — DAGs, operators, sensors, XComs, pools, scheduling. Use when working with airflow pipelines.
Dagster data orchestration — software-defined assets, ops, jobs, schedules, sensors, IO managers. Use when working with dagster pipelines.
dbt data transformation — models, tests, macros, sources, snapshots, documentation, packages. Use when working with dbt transform.
Prefect workflow orchestration — flows, tasks, deployments, work pools, schedules, retries. Use when working with prefect flows.
Apache Spark distributed processing — DataFrames, SQL, streaming, MLlib, cluster management. Use when working with spark processing.
Temporal durable workflows — workflow/activity definitions, retries, signals, queries, versioning. Use when working with temporal workflows.
Skill: agent-arena-skill. See SKILL.md body for details. Use when this domain is relevant.
AI-powered quality engineering with flaky test detection, mutation testing, chaos engineering, risk-based test prioritization, and cross-project pattern learning. Use when building quality.
Takes a problem statement and produces a deployable micro-SaaS product — landing page, auth, payments, database, API, and billing. Use when building micro-SaaS products solo.
Meta-skill for integrating external GitHub skill repos into 1ai-skills. Covers discovery, deduplication, format conversion, category mapping, validation, and quality gates. Use when integrating external skill repos, bulk skill imports, skill format conversion.
Android Jetpack Compose — declarative UI, state management, Material Design, and Play Store deployment. Use when working with android jetpack.
REST API design — resource modeling, versioning, pagination, error handling, OpenAPI/Swagger documentation. Use when working with api design.
API gateway design — rate limiting, authentication, routing, caching, request transformation. Kong, Traefik, custom gateways. Use when working with api gateway.
REST and GraphQL API testing — contract testing, schema validation, and integration test automation. Use when working with api testing.
App Store and Play Store optimization — keywords, screenshots, reviews, and conversion rate optimization. Use when working with app store optimization.
Appwrite backend-as-a-service — auth, database, storage, functions, realtime for web/mobile/desktop. Use when working with appwrite patterns.
Generate test suites, analyze coverage, and scaffold E2E tests automatically. Use when creating tests for existing code, improving test coverage, scaffolding integration tests, or setting.
Effective brainstorming skill for features and projects. Clarify intent, explore options, and guide design decisions to align with user goals. Use when working with brainstorming.
Apache Cassandra patterns — data modeling, CQL, partition keys, clustering, replication, performance tuning. Use when working with cassandra patterns.