Skip to main content
Manusで任意のスキルを実行
ワンクリックで
GitHub リポジトリ

CodeAudit-Single_SKill

CodeAudit-Single_SKill には bazhahei123 から収集した 18 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。

収集済み skills
18
Stars
35
更新
2026-05-08
Forks
0
職業カバレッジ
1 件の職業カテゴリ · 100% 分類済み
リポジトリエクスプローラー

このリポジトリの skills

access-control-check
情報セキュリティアナリスト

Use this skill to audit application code for access control weaknesses, including authentication boundary issues, function-level authorization flaws, object-level authorization flaws, business-context authorization gaps, client-side-only enforcement, inconsistent permission checks across routes, methods, and layers, and framework-specific access-control sink candidates in Java, Android, C++, C#, Python, and PHP applications.

2026-05-08
business-logic-abuse-check
情報セキュリティアナリスト

Use this skill to audit application code for business logic abuse risks, including broken state transitions, workflow bypass, idempotency failures, replay issues, rate or quota abuse, accounting and value integrity flaws, beneficiary mismatches, and inconsistent business-rule enforcement across routes, jobs, and integrations.

2026-05-08
business-logic-abuse-candidate-sink-check
情報セキュリティアナリスト

Use this skill to audit business logic abuse risks with graph-database and taint-tracking friendly candidate sink inventories, including payment, authentication, rate/quota, workflow, promotion, resource-consumption, and third-party integration scenarios in Java, Android, C++, C#, Python, and PHP applications.

2026-05-08
unsafe-deserialization-check
情報セキュリティアナリスト

Use this skill to audit Java, Android, C#/.NET, C++, Python, and PHP application code for unsafe deserialization risks, including untrusted input reaching deserialization sinks, unsafe object restoration, dangerous magic or lifecycle method triggers, framework or library misuse, integrity boundary failures, and inconsistent deserialization controls across routes, jobs, IPC, RPC, mobile components, and data-processing layers.

2026-05-08
path-traversal-check
情報セキュリティアナリスト

Use this skill to audit Java, Android, C#/.NET, C++, Python, and PHP application code for path traversal, arbitrary file read/write/delete/overwrite, unsafe file path handling, archive extraction traversal, local resource inclusion, and inconsistent path validation across routes, jobs, IPC, RPC, mobile components, and file-processing layers.

2026-05-08
command-execution-check
情報セキュリティアナリスト

Use this skill to audit Java, Android, C#/.NET, C++, Python, and PHP application code for command injection, unsafe process execution, shell injection, argument or option injection, dangerous eval or expression execution, interpreter abuse, dynamic code loading, external-tool misuse, and inconsistent execution controls across routes, jobs, IPC, RPC, mobile components, and helper layers.

2026-05-08
sql-injection-check
情報セキュリティアナリスト

Use this skill to audit Java, Android, C#/.NET, C++, Python, and PHP application code for SQL injection risks, including unsafe query construction, raw SQL execution, ORM/query-builder misuse, stored procedure misuse, structural SQL control, second-order SQL injection, and inconsistent input handling across routes, jobs, IPC, RPC, mobile components, and data-access layers.

2026-05-08
ssrf-check
情報セキュリティアナリスト

Use this skill to audit Java, Android, C#/.NET, C++, Python, and PHP application code for server-side request forgery risks, including attacker-controlled request targets, unsafe URL construction, internal network reachability, metadata access, redirect or DNS-based bypasses, protocol misuse, cloud metadata access, and inconsistent outbound-request controls across routes, jobs, IPC, RPC, mobile components, and helper layers.

2026-05-08
xss-check
情報セキュリティアナリスト

Use this skill to audit Java, Android, C#/.NET, C++, Python, PHP, and JavaScript/TypeScript application code for cross-site scripting risks, including reflected XSS, stored XSS, unsafe template rendering, unescaped output, WebView XSS, native HTML rendering misuse, dangerous HTML and JavaScript sinks, client-side rendering misuse, and inconsistent output encoding or sanitization across routes, templates, components, mobile views, and rendering layers.

2026-05-08
access-control-source-check
情報セキュリティアナリスト

Use this skill to identify source points for access control audits, including backend routes, mobile/deep-link entries, identity sources, role and permission inputs, object identifiers, tenant or organization scope inputs, business action and state inputs, client-controlled parameters, alternate entry points, and framework-specific source locations in Java, Android, C#/.NET, C++, Python, and PHP applications.

2026-05-08
business-logic-abuse-candidate-source-check
情報セキュリティアナリスト

Use this skill to identify business logic source points with graph-database and taint-tracking friendly candidate inventories, including payment, authentication, rate/quota, workflow, promotion, resource-consumption, and third-party integration scenarios in Java, Android, C++, C#, Python, and PHP applications.

2026-05-08
unsafe-deserialization-source-check
情報セキュリティアナリスト

Use this skill to identify source points for unsafe deserialization audits, including serialized payloads, encoded blobs, uploaded files, cookies, sessions, cache values, queue messages, stored metadata, polymorphic type fields, object restoration inputs, mobile/IPC/RPC payloads, and framework-specific deserialization source locations in Java, Android, C#/.NET, C++, Python, and PHP applications.

2026-05-08
file-path-handling-source-check
情報セキュリティアナリスト

Use this skill to identify source points for path traversal and unsafe file path handling audits, including path parameters, filenames, uploaded file metadata, archive entry names, stored paths, resource selectors, template names, export destinations, cleanup targets, queue payloads, mobile/IPC/RPC file inputs, and framework-specific path source locations in Java, Android, C#/.NET, C++, Python, and PHP applications.

2026-05-08
command-execution-source-check
情報セキュリティアナリスト

Use this skill to identify source points for command execution and code execution audits, including command names, shell strings, argv values, flags, options, file paths, environment values, working directories, script content, eval expressions, external tool inputs, queued task payloads, stored command templates, mobile/IPC/RPC execution inputs, and framework-specific execution source locations in Java, Android, C#/.NET, C++, Python, and PHP applications.

2026-05-08
sql-injection-source-check
情報セキュリティアナリスト

Use this skill to identify source points for SQL injection audits, including request parameters, search filters, sort and pagination controls, raw SQL fragments, ORM raw-helper inputs, dynamic table and column selectors, report templates, saved filters, imported rows, stored query metadata, Android local SQL inputs, IPC/RPC/job/query payloads, and framework-specific SQL source locations in Java, Android, C#/.NET, C++, Python, and PHP applications.

2026-05-08
ssrf-source-check
情報セキュリティアナリスト

Use this skill to identify source points for server-side request forgery audits, including URL parameters, host and path selectors, callback and webhook targets, remote fetch inputs, import and preview URLs, redirect-controlled values, DNS-sensitive hostnames, protocol selectors, proxy settings, stored callback URLs, queued fetch jobs, Android mobile/IPC/WebView request sources, native/RPC request sources, and framework-specific outbound request source locations in Java, Android, C#/.NET, C++, Python, and PHP applications.

2026-05-08
xss-source-check
情報セキュリティアナリスト

Use this skill to identify source points for cross-site scripting audits, including reflected input, stored user content, template model values, rich text and markdown payloads, sanitized or trusted HTML variables, browser-side sources, API-delivered content, framework component props, DOM data sources, Android WebView/native HTML sources, .NET Razor/Blazor rendering sources, C++ native HTML/WebView sources, and rendering source locations in Java, Android, C#/.NET, C++, JavaScript/TypeScript, Python, and PHP applications.

2026-05-08
business-logic-source-check
情報セキュリティアナリスト

Use this skill to identify source points for business logic abuse audits, including workflow state inputs, transition actions, sequence markers, idempotency keys, replay identifiers, rate and quota dimensions, value and accounting inputs, actor-target-beneficiary bindings, retryable events, callbacks, jobs, and integration-driven business events.

2026-04-27