Skip to main content

ersinkoc/security-check

SkillsMP 已收集 ersinkoc/security-check 中的 49 个 Skill。打开任一 Skill 可查看来源和详情。

最近记录的来源活动
SkillsMP 收录数据更新
已收集 skills
49
GitHub 星标
56
GitHub Forks
5

这个仓库中的 skills

2 个职业分类 · 已分类 100%

已展示 40 / 49 个已收集 Skill。

职业分类
信息安全分析师
描述

Comprehensive AI-powered security scanning suite with 48 skills covering OWASP Top 10, 7 language-specific deep scanners (Go, TypeScript, Python, PHP, Rust, Java, C#), supply chain analysis, infrastructure-as-code scanning, and 3000+ checklist items. Use when…

原文语言:英语

更新
职业分类
信息安全分析师
描述

C#/.NET-specific security deep scan

原文语言:英语

更新
职业分类
信息安全分析师
描述

Go-specific security deep scan

原文语言:英语

更新
职业分类
信息安全分析师
描述

Java/Kotlin-specific security deep scan

原文语言:英语

更新
职业分类
信息安全分析师
描述

PHP-specific security deep scan

原文语言:英语

更新
职业分类
信息安全分析师
描述

Python-specific security deep scan

原文语言:英语

更新
职业分类
信息安全分析师
描述

Rust-specific security deep scan

原文语言:英语

更新
职业分类
信息安全分析师
描述

TypeScript/JavaScript-specific security deep scan

原文语言:英语

更新
职业分类
信息安全分析师
描述

REST, GraphQL, and gRPC API security audit — authentication, authorization, data exposure, and configuration

原文语言:英语

更新
职业分类
信息安全分析师
描述

Authentication flaw detection — weak passwords, broken auth, credential stuffing, and bypass vectors

原文语言:英语

更新
职业分类
信息安全分析师
描述

Authorization flaw detection — IDOR, broken access control, horizontal and vertical privilege issues

原文语言:英语

更新
职业分类
信息安全分析师
描述

Business logic flaw detection — price manipulation, workflow bypass, race conditions, and abuse vectors

原文语言:英语

更新
职业分类
信息安全分析师
描述

CI/CD pipeline security — GitHub Actions injection, secret exposure, untrusted actions, and artifact poisoning

原文语言:英语

更新
职业分类
信息安全分析师
描述

Clickjacking and UI redressing detection — missing frame protection headers and CSP frame-ancestors

原文语言:英语

更新
职业分类
信息安全分析师
描述

OS Command Injection detection in shell execution, subprocess calls, and process spawning

原文语言:英语

更新
职业分类
信息安全分析师
描述

CORS misconfiguration detection — wildcard origin, reflected origin, null origin, and credential leaks

原文语言:英语

更新
职业分类
信息安全分析师
描述

Cryptography misuse detection — weak algorithms, ECB mode, static IVs, weak PRNG, and key management flaws

原文语言:英语

更新
职业分类
信息安全分析师
描述

Cross-Site Request Forgery detection — missing tokens, SameSite misconfiguration, and CORS-CSRF interaction

原文语言:英语

更新
职业分类
信息安全分析师
描述

Sensitive data exposure detection — PII leaks, verbose errors, debug mode, and information disclosure

原文语言:英语

更新
职业分类
信息安全分析师
描述

Supply chain and dependency security analysis across all package ecosystems

原文语言:英语

更新
职业分类
信息安全分析师
描述

Insecure deserialization detection across all serialization formats and languages

原文语言:英语

更新
职业分类
信息安全分析师
描述

Incremental security scan for changed files only — optimized for PR and commit-level reviews

原文语言:英语

更新
职业分类
信息安全分析师
描述

Docker-specific security checks — image hardening, secrets in layers, compose security, and runtime configuration

原文语言:英语

更新
职业分类
信息安全分析师
描述

Insecure file upload detection — unrestricted types, MIME mismatch, polyglot files, and webshell upload

原文语言:英语

更新
职业分类
信息安全分析师
描述

GraphQL injection, introspection abuse, query complexity attacks, and authorization bypass detection

原文语言:英语

更新
职业分类
信息安全分析师
描述

HTTP Header Injection and Response Splitting detection via CRLF injection in headers

原文语言:英语

更新
职业分类
信息安全分析师
描述

Infrastructure-as-Code security scanning — Dockerfile, Kubernetes, Terraform, and GitHub Actions misconfigurations

原文语言:英语

更新
职业分类
信息安全分析师
描述

JWT implementation flaw detection — algorithm confusion, weak secrets, missing validation, and storage issues

原文语言:英语

更新
职业分类
信息安全分析师
描述

LDAP Injection detection in search filters, DN construction, and bind operations

原文语言:英语

更新
职业分类
信息安全分析师
描述

Mass assignment and over-posting detection — unfiltered request body binding to data models

原文语言:英语

更新
职业分类
信息安全分析师
描述

NoSQL Injection detection for MongoDB, Redis, CouchDB, and Elasticsearch

原文语言:英语

更新
职业分类
信息安全分析师
描述

Open redirect detection — unvalidated redirect URLs, protocol-relative bypasses, and URI scheme abuse

原文语言:英语

更新
职业分类
软件开发工程师
描述

Master orchestration skill that coordinates the entire 4-phase security scanning pipeline

原文语言:英语

更新
职业分类
软件开发工程师
描述

Path traversal and directory traversal detection — LFI, RFI, zip slip, and symlink attacks

原文语言:英语

更新
职业分类
软件开发工程师
描述

Privilege escalation vector detection — role manipulation, admin bypass, and RBAC circumvention

原文语言:英语

更新
职业分类
软件开发工程师
描述

Race condition and TOCTOU detection — database races, file system races, double-spend, and atomicity failures

原文语言:英语

更新
职业分类
软件开发工程师
描述

Missing rate limiting and application-level DoS vector detection — ReDoS, query complexity, resource exhaustion

原文语言:英语

更新
职业分类
软件开发工程师
描述

Remote Code Execution detection via eval, exec, dynamic code loading, and code injection vectors

原文语言:英语

更新
职业分类
软件开发工程师
描述

Codebase discovery and architecture mapping for security analysis

原文语言:英语

更新
职业分类
软件开发工程师
描述

Final consolidated security assessment report generator with CVSS severity and remediation roadmap

原文语言:英语

更新
已展示 40 / 49 个已收集 Skill。