Skip to main content

Skills neste repositório

UnboundCompute/security-agent-skills - Página 4

O SkillsMP coletou 130 skills de UnboundCompute/security-agent-skills. Abra uma skill para revisar a origem e os detalhes.

UnboundCompute/security-agent-skills

Mostrando 10 de 130 skills coletadas.

ocupação
Analistas de garantia de qualidade de software e testadores
descrição

Test whether an AI agent obeys instructions hidden in the content it ingests, rather than only the user's. Enumerate every channel through which untrusted content reaches the model context (retrieved docs, fetched pages, uploaded files, emails, tool outputs,…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Decide whether a CVE in a dependency actually exposes your application before you scramble to patch: is the vulnerable function on a real call path from your code, do the trigger preconditions hold, and can an attacker control the input that reaches it. Use…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Turn a security patch or version diff into fresh findings: infer the fixed vulnerability from what the fix changed, reconstruct the pre-patch bug, then hunt the paths the fix did not cover and the same bug in code it never touched. Use when you have a fix…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Given one confirmed vulnerability, systematically find its siblings: the same defect shape repeated elsewhere in the codebase, and the parts of it the fix left uncovered. Use right after you confirm or read about a bug (your own finding, a CVE, a patch, a…

Idioma do texto original: inglês

atualizado
ocupação
Analistas de segurança da informação
descrição

Decide whether a whitebox lead is a real bug by tracing taint from an untrusted source to a dangerous sink and confirming every hop against live source. Use after a scanner, a candidate list, or your own reading surfaces a "this looks dangerous" sink (SQL…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Find the missing-check bug by comparing sibling functions that reach the same sink - one validates its input, its peer does not. Use on an authorized source target to surface broken access control, missing bounds checks, and skipped sanitization that linear…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Find memory-safety bugs in C/C++ and other unmanaged code - use-after-free, double-free, out-of-bounds read/write, uninitialized use, and NULL deref - by reasoning about object lifetime and buffer bounds along real code paths. Use on an authorized source…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Find concurrency and time-of-check/time-of-use bugs - TOCTOU, unsynchronized shared state, check-then-act, and atomicity violations - by reasoning about what state is shared, what can interleave, and where a window opens between a check and its use. Use on an…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Hunt security bugs across a whole codebase by reasoning over its structure (call graph and dataflow) instead of grepping for keywords. Use when you have source access to an authorized target (your own code, an OSS project, or an in-scope engagement) and want…

Idioma do texto original: inglês

atualizado
ocupação
Desenvolvedores de software
descrição

Map and prioritize the attack surface of an authorized black-box web target before testing it - enumerate hosts, endpoints, parameters, auth flows, and technologies, then order them by where bugs actually live. Use at the start of an in-scope engagement or…

Idioma do texto original: inglês

atualizado
Mostrando 10 de 130 skills coletadas.