com um clique
laravelversions
laravelversions contém 12 skills coletadas de tighten, com cobertura ocupacional por repositório e páginas de detalhe dentro do site.
Skills neste repositório
Run Frisk's agentic security audit — dispatch specialized scanner subagents in parallel and write the aggregated results to .frisk/agentic-findings.json so the Frisk CLI can ingest them.
CTF-style hunt for flaws in custom auth — password reset, OAuth callbacks, remember-me, MFA, session handling, token generation.
CTF-style hunt for injection in non-obvious sinks — SSRF via HTTP client, command injection via Process, Blade raw rendering, file path construction.
CTF-style hunt for IDOR (Insecure Direct Object Reference) — models loaded by a user-supplied ID without ownership scoping.
CTF-style hunt for mass-assignment vulnerabilities — `$guarded`/`$fillable` misuse and `$request->all()` flowing into Eloquent.
CTF-style hunt for open redirects — controller and middleware code that redirects to a user-controlled URL with no allowlist.
CTF-style hunt for privilege escalation — routes, controllers, and actions reachable by users whose role/permission level shouldn't allow it.
CTF-style hunt for prompt injection — user input flowing into LLM message payloads without sandboxing, and trusted LLM responses driving permission decisions or interpolated into Slack/HTML/markdown channels.
CTF-style hunt for race conditions and atomicity bugs — read-then-write on money/credits/quotas without locking, non-idempotent webhook handlers, double-spend windows.
CTF-style hunt for tokens, hashes, secrets, and PII leaking via API responses, logs, error pages, or cached views.
CTF-style hunt for cross-tenant data leakage in multi-tenant apps — queries that skip tenant scoping, jobs that drop tenant context, cache keys missing tenant prefix, shared storage paths.
CTF-style hunt for unverified or weakly-verified inbound webhooks — missing HMAC checks, timing-unsafe comparisons, missing replay protection, hand-rolled signed-URL verification.