Skip to main content

Skills en este repositorio

UnboundCompute/security-agent-skills - Página 4

SkillsMP ha recopilado 130 skills de UnboundCompute/security-agent-skills. Abre una skill para revisar su origen y sus detalles.

UnboundCompute/security-agent-skills

Mostrando 10 de 130 skills recopiladas.

ocupación
Analistas de garantía de calidad de software y probadores
descripción

Test whether an AI agent obeys instructions hidden in the content it ingests, rather than only the user's. Enumerate every channel through which untrusted content reaches the model context (retrieved docs, fetched pages, uploaded files, emails, tool outputs,…

Idioma del texto original: inglés

actualizado
ocupación
Analistas de seguridad de la información
descripción

Decide whether a CVE in a dependency actually exposes your application before you scramble to patch: is the vulnerable function on a real call path from your code, do the trigger preconditions hold, and can an attacker control the input that reaches it. Use…

Idioma del texto original: inglés

actualizado
ocupación
Analistas de seguridad de la información
descripción

Turn a security patch or version diff into fresh findings: infer the fixed vulnerability from what the fix changed, reconstruct the pre-patch bug, then hunt the paths the fix did not cover and the same bug in code it never touched. Use when you have a fix…

Idioma del texto original: inglés

actualizado
ocupación
Analistas de seguridad de la información
descripción

Given one confirmed vulnerability, systematically find its siblings: the same defect shape repeated elsewhere in the codebase, and the parts of it the fix left uncovered. Use right after you confirm or read about a bug (your own finding, a CVE, a patch, a…

Idioma del texto original: inglés

actualizado
ocupación
Analistas de seguridad de la información
descripción

Decide whether a whitebox lead is a real bug by tracing taint from an untrusted source to a dangerous sink and confirming every hop against live source. Use after a scanner, a candidate list, or your own reading surfaces a "this looks dangerous" sink (SQL…

Idioma del texto original: inglés

actualizado
ocupación
Desarrolladores de software
descripción

Find the missing-check bug by comparing sibling functions that reach the same sink - one validates its input, its peer does not. Use on an authorized source target to surface broken access control, missing bounds checks, and skipped sanitization that linear…

Idioma del texto original: inglés

actualizado
ocupación
Desarrolladores de software
descripción

Find memory-safety bugs in C/C++ and other unmanaged code - use-after-free, double-free, out-of-bounds read/write, uninitialized use, and NULL deref - by reasoning about object lifetime and buffer bounds along real code paths. Use on an authorized source…

Idioma del texto original: inglés

actualizado
ocupación
Desarrolladores de software
descripción

Find concurrency and time-of-check/time-of-use bugs - TOCTOU, unsynchronized shared state, check-then-act, and atomicity violations - by reasoning about what state is shared, what can interleave, and where a window opens between a check and its use. Use on an…

Idioma del texto original: inglés

actualizado
ocupación
Desarrolladores de software
descripción

Hunt security bugs across a whole codebase by reasoning over its structure (call graph and dataflow) instead of grepping for keywords. Use when you have source access to an authorized target (your own code, an OSS project, or an in-scope engagement) and want…

Idioma del texto original: inglés

actualizado
ocupación
Desarrolladores de software
descripción

Map and prioritize the attack surface of an authorized black-box web target before testing it - enumerate hosts, endpoints, parameters, auth flows, and technologies, then order them by where bugs actually live. Use at the start of an in-scope engagement or…

Idioma del texto original: inglés

actualizado
Mostrando 10 de 130 skills recopiladas.