Skip to main content
Exécutez n'importe quel Skill dans Manus
en un clic
Dépôt GitHub

opentaint

opentaint contient 15 skills collectées depuis seqra, avec une couverture métier par dépôt et des pages de détail sur le site.

skills collectés
15
Stars
113
mis à jour
2026-07-04
Forks
9
Couverture métier
3 catégories métier · 100% classifié
explorateur de dépôts

Skills dans ce dépôt

create-pass-through-approximation
Développeurs de logiciels

Model a library method's taint propagation as a passThrough approximation config. Use for a dropped external method whose propagation is simple copying

2026-07-04
create-rule
Développeurs de logiciels

Author and verify an OpenTaint detection rule for a vulnerability class on JVM code. Use whenever a rule needs to be created for an uncovered vulnerability, or an existing rule needs a false-positive or false-negative fix

2026-07-02
create-test-project
Développeurs de logiciels

Create an OpenTaint test project with annotated positive/negative samples for verifying a rule or approximation. Use when a rule or approximation needs a test project to check against

2026-07-02
debug-rule
Développeurs de logiciels

Debug a rule or approximation that behaves unexpectedly by tracing where taint is dropped. Use when its samples won't pass after repeated attempts, or it passes tests but is wrong on a real scan

2026-07-02
report-analyzer-issue
Développeurs de logiciels

Write an OpenTaint engine-issue report from a confirmed diagnosis, optionally opening a GitHub issue. Use when engine-side issue got confirmed and requires report

2026-07-02
triage-dependencies
Développeurs de logiciels

Mark which of a project's dependency libraries could introduce taint sources or sinks. Use to start attack-surface discovery

2026-07-02
appsec-agent
Analystes en sécurité de l'information

Run an end-to-end application-security analysis on a JVM project with OpenTaint — build, scan, model missing library methods, triage, and confirm vulnerabilities. Use when the user asks to find vulnerabilities, run SAST, or scan a Java/Kotlin app for security issues

2026-06-21
discover-attack-surface
Analystes en sécurité de l'information

Analyze project-used members of a dependency package for potential sources and sinks not covered by the built-in rules. Use for the depth pass of attack-surface discovery, one package at a time, after triage-dependencies flags it

2026-06-11
analyze-external-methods
Analystes en sécurité de l'information

Analyze and group an OpenTaint scan's dropped external methods and decide what to approximate or skip. Use when a dropped-external-methods.yaml needs turning into approximation targets

2026-06-10
analyze-findings
Analystes en assurance qualité des logiciels et testeurs

Triage OpenTaint findings — split a rule's results into distinct vulnerabilities and classify each true positive or false positive. Use when scan findings need a TP/FP verdict

2026-06-10
assemble-lib-rules
Développeurs de logiciels

Write the per-vuln-class security join rules that merge the created source/sink lib rules with the built-ins. Use after the per-package lib rules are created and tested, to wire them into project-level joins

2026-06-10
build-project
Développeurs de logiciels

Build a Java/Kotlin project for opentaint analysis and produce a project.yaml model. Use whenever an opentaint scan needs a project model and `opentaint compile` may need help

2026-06-10
create-dataflow-approximation
Développeurs de logiciels

Model a library method's taint propagation as code-based dataflow approximation and refine it against a test project until the sample passes. Use for a dropped external method whose propagation a passThrough copy cannot express

2026-06-10
generate-poc
Développeurs de logiciels

Reproduce a true-positive finding against the running application. Use when a finding needs dynamic confirmation

2026-06-10
run-scan
Développeurs de logiciels

Run an OpenTaint scan on project and produces the SARIF report. Use whenever the user asks to scan or re-scan a project

2026-06-10