Skip to main content

mitm-find-insecure

Find insecure configurations in HTTP traffic. Use when user asks about security headers, cookie security, CORS issues, or transport security.

소스 정보

저장소
instavm/security-skills
최근 소스 활동
2026년 3월 23일 05:24
감지된 SKILL.md 언어
영어
스타
86
포크
11

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
mitm-find-insecure
description
Find insecure configurations in HTTP traffic. Use when user asks about security headers, cookie security, CORS issues, or transport security.
# Find Insecure Configurations Analyze the mitmproxy dump (log.txt) for insecure configs for: $ARGUMENTS > **Requires**: `log.txt` in the current directory. If it's missing, capture traffic first: > ```bash > mitmdump --set flow_detail=3 2>&1 | tee log.txt > ``` ## Security Checks ### 1. HTTP Instead of HTTPS - Sensitive data over plain HTTP - Login/payment pages on HTTP - Mixed content issues ### 2. Missing Security Headers - `Strict-Transport-Security` (HSTS) - `X-Content-Type-Options` - `X-Frame-Options` - `Content-Security-Policy` - `X-XSS-Protection` - `Referrer-Policy` ### 3. Insecure Cookies - Missing `Secure` flag - Missing `HttpOnly` flag - Missing `SameSite` attribute - Session cookies without protection ### 4. CORS Issues - `Access-Control-Allow-Origin: *` - Credentials allowed with wildcard - Overly permissive origins ### 5. SSL/TLS Issues - SHA1 certificates (deprecated) - Weak cipher suites - Outdated TLS versions ### 6. Information Disclosure - Sensitive data in GET params - Debug/verbose errors exposed - Stack traces in responses - Internal file paths revealed ## Output Format For each finding: - **Endpoint/Resource**: Where issue exists - **Issue**: What's misconfigured - **Current Value**: What was observed - **Recommended**: Secure configuration - **Risk**: Potential attack vector - **Severity**: Critical/High/Medium/Low/Info
GitHub에서 보기