Skip to main content

anshumanbh/securevibes

SkillsMP は anshumanbh/securevibes から 9 件の skill を収集しています。skill を開くとソースと詳細を確認できます。

記録された最新のソース活動
SkillsMP カタログ更新
収集済み skills
9
GitHub スター
283
GitHub フォーク
62

このリポジトリの skills

1 件の職業カテゴリ · 100% 分類済み

収集済み skill 9 件中 9 件を表示しています。

職業分類
情報セキュリティアナリスト
説明

Validate Server-Side Request Forgery (SSRF) vulnerabilities by testing if user-controlled URLs can reach internal services, cloud metadata endpoints, or alternative protocols. Use when testing CWE-918 (SSRF), CWE-441 (Unintended Proxy), CWE-611 (XXE leading…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Validate OS Command Injection vulnerabilities including direct command injection, blind command injection via time delays, and out-of-band command execution. Test by injecting shell metacharacters and commands into user-controlled inputs. Use when testing…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Validate NoSQL injection vulnerabilities across MongoDB, Cassandra, CouchDB, Redis, and other NoSQL databases. Test operator injection, JavaScript injection, and query manipulation patterns. Use when testing CWE-943 (Improper Neutralization of Special…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Validate SQL injection vulnerabilities (including blind SQLi) across time-based, error-based, boolean-based, UNION-based, stacked-query, and out-of-band patterns. Use when testing CWE-89 (SQL Injection), CWE-564 (Hibernate SQL Injection), and related SQL…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Validate Cross-Site Scripting (XSS) vulnerabilities including Reflected, Stored, and DOM-based XSS. Test by injecting script payloads into user-controlled inputs and observing if they execute in browser context. Use when testing CWE-79 (XSS), CWE-80 (Basic…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Validate XML External Entity (XXE) injection vulnerabilities including file disclosure, SSRF, denial of service, and blind XXE via out-of-band channels. Test by injecting malicious XML with external entity references into endpoints that parse XML. Use when…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Validate authorization failures including IDOR, privilege escalation, and missing access controls. Test by attempting unauthorized access with lower-privileged credentials. Use when testing CWE-639 (IDOR), CWE-269 (Improper Privilege Management), CWE-862…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Validate miscellaneous injection vulnerabilities NOT covered by dedicated skills. Covers SSTI, LDAP, XPath, XQuery, CRLF/HTTP Header, Email Header, GraphQL, Expression Language (EL/OGNL), JSON/JavaScript eval injection, ORM/HQL, CSV/Formula, Regex (ReDoS),…

原文の言語: 英語

更新
職業分類
情報セキュリティアナリスト
説明

Identify agentic AI security threats based on OWASP Top 10 for Agentic Applications 2026. Use when analyzing AI agents, LLM-powered applications, chatbots, auto-reply systems, tool-using AI, browser automation, sandbox execution, or any application that uses…

原文の言語: 英語

更新
収集済み skill 9 件中 9 件を表示しています。