Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick
GitHub-Repository

ai-ide-skills

ai-ide-skills enthält 8 gesammelte Skills von Mindgard, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.

gesammelte Skills
8
Stars
61
aktualisiert
2026-03-09
Forks
8
Berufsabdeckung
1 Berufskategorien · 100% klassifiziert
Repository-Explorer

Skills in diesem Repository

ai-ide-attack-chains
Informationssicherheitsanalysten

Plans and constructs multi-stage attack chains against AI IDEs. Use when combining vulnerability primitives into end-to-end exploits, assessing overall IDE security posture, or mapping how individual vulnerabilities chain together through the file-write pivot point. Each chain is classified by interaction tier to prioritize reportable findings.

2026-03-09
ai-ide-code-exec
Informationssicherheitsanalysten

Tests AI IDEs for code execution vulnerabilities beyond MCP and terminal filters. Use when assessing hooks abuse, binary planting, IDE settings exploitation, tools definition auto-loading, or environment variable prefixing attack vectors. Patterns are ordered by interaction tier: Tier 1 (zero-interaction) through Tier 4 (trusted workspace + specific action).

2026-03-09
ai-ide-data-exfil
Informationssicherheitsanalysten

Tests AI IDEs for data exfiltration vulnerabilities. Use when assessing markdown image rendering, Mermaid diagram abuse, pre-configured URL fetching, model provider redirect, webview rendering, or other outbound data channels in AI coding assistants.

2026-03-09
mcp-config-poisoning
Informationssicherheitsanalysten

Tests AI IDEs for MCP configuration poisoning vulnerabilities. Use when auditing MCP integration security, testing whether an IDE auto-loads untrusted MCP server definitions from workspace config files, or assessing MCP tool approval and invocation controls. Assessment is structured around four interaction tiers, tested in priority order from zero-click auto-load to TOCTOU on trusted workspaces.

2026-03-09
ai-ide-recon
Informationssicherheitsanalysten

Maps attack surface of AI-assisted IDEs before vulnerability testing. Use when starting a security assessment of an AI IDE, analyzing IDE documentation for security blind spots, or enumerating config files and auto-load paths. Works for both open-source and closed-source targets. Annotates every discovered feature with an interaction tier so testing prioritizes zero-click and agent-mediated vectors first.

2026-03-03
ai-ide-source-audit
Informationssicherheitsanalysten

Guides source code auditing of open-source AI IDEs for security vulnerabilities. Use when reviewing AI IDE source code, analyzing command filtering implementations, auditing MCP integration code, or assessing file-write permission models in open-source AI coding tools.

2026-03-03
prompt-injection-chains
Informationssicherheitsanalysten

Tests AI IDEs for prompt injection vulnerabilities that enable config modification and privilege escalation. Use when assessing adversarial directory attacks, prompt template auto-loading, rules override, or file-write-to-config-modification attack chains. Patterns are organized by interaction tier from highest to lowest severity.

2026-03-03
terminal-filter-bypass
Informationssicherheitsanalysten

Tests terminal command filtering and allowlist implementations in AI IDEs for bypass vulnerabilities. Use when assessing command execution controls, testing shell injection vectors, or evaluating allowlist/blocklist implementations in AI coding agents.

2026-03-03