Skip to main content
UnboundCompute
GitHub クリエイタープロフィール

UnboundCompute

1 件の GitHub リポジトリにある 130 件の収集済み skills をリポジトリ単位で表示します。

収集済み skills
130
リポジトリ
1
更新
2026年8月29日
リポジトリマップ

skills がある場所

収集済み skill 数が多いリポジトリを、このクリエイターカタログ内の比率と職業範囲とともに表示します。

リポジトリエクスプローラー

リポジトリと代表的な skills

auditing-account-recovery-and-reset-trust
未分類

Audit password reset and account recovery flows for the trust that lets an attacker take over an account: a reset token that is guessable, long-lived, reusable, or not bound to the account it was issued for, a recovery path that verifies a weaker factor than…

2026年8月29日
auditing-http2-and-grpc-multiplexing-trust
未分類

Audit HTTP/2 and gRPC edges for framing and multiplexing trust that breaks when a stream is translated or reused: an h2c or HTTP/2-to-HTTP/1.1 downgrade that reintroduces request smuggling, pseudo-header and header handling that lets a stream forge its path…

2026年8月29日
auditing-jwt-verification-and-key-trust
未分類

Audit how a service verifies JSON Web Tokens for the classic verification bypasses: an algorithm-confusion attack where a token switches the signing algorithm so a public key is used as a symmetric secret or the algorithm is set to none, a key selected from…

2026年8月29日
auditing-message-broker-topic-authorization
未分類

Audit message-broker topic and queue authorization for reach a client should not have: a wildcard subscription that receives another tenant's messages, a publish permission broad enough to inject into a control or command topic, a shared broker where topic…

2026年8月29日
auditing-oauth-token-audience-and-scope-trust
未分類

Audit how a resource server trusts OAuth access tokens for confusion it should reject: a token minted for one audience accepted by a different service, a scope treated as coarser or finer than it is so a token reaches an operation it was not granted, a…

2026年8月29日
auditing-payment-callback-and-amount-integrity
未分類

Audit payment provider callbacks and settlement notifications for the trust that lets an attacker forge or alter a payment result: a callback whose signature is not verified so a spoofed success is accepted, an amount or currency taken from the callback or…

2026年8月29日
auditing-payment-state-machine-and-idempotency
未分類

Audit payment and checkout state machines for transitions an attacker can drive out of order or replay for value: an order marked paid before the charge is confirmed, a step that can be skipped or repeated so goods ship without settlement, a non-idempotent…

2026年8月29日
auditing-saml-and-oidc-federation-trust
未分類

Audit federated single sign-on for assertions a relying party should not trust: a SAML response whose signature is not verified over the right element so a wrapped or altered assertion passes, an OIDC ID token whose issuer, audience, or nonce is unchecked, a…

2026年8月29日
収集済み skill 130 件中 8 件を表示しています。
1 件中 1 件のリポジトリを表示
すべてのリポジトリを表示しました