Skip to main content

这个仓库中的 skills

igbuend/grimbard - 第 3 页

SkillsMP 已收集 igbuend/grimbard 中的 89 个 Skill。打开任一 Skill 可查看来源和详情。

igbuend/grimbard

已展示 9 / 89 个已收集 Skill。

职业分类
信息安全分析师
描述

Security anti-pattern for verbose error messages (CWE-209). Use when generating or reviewing code that handles errors, exceptions, or generates user-facing error responses. Detects stack trace exposure and detailed error information leakage to users.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security anti-pattern for weak encryption (CWE-326, CWE-327). Use when generating or reviewing code that encrypts data, handles encryption keys, or uses cryptographic modes. Detects DES, ECB mode, static IVs, and custom crypto implementations.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security anti-pattern for weak password hashing (CWE-327, CWE-759). Use when generating or reviewing code that stores or verifies user passwords. Detects use of MD5, SHA1, SHA256 without salt, or missing password hashing entirely. Recommends bcrypt, Argon2,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security anti-pattern for XPath injection vulnerabilities (CWE-643). Use when generating or reviewing code that queries XML documents, constructs XPath expressions, or handles user input in XML operations. Detects unescaped quotes and special characters in…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security anti-pattern for Cross-Site Scripting vulnerabilities (CWE-79). Use when generating or reviewing code that renders HTML, handles user input in web pages, uses innerHTML/document.write, or builds dynamic web content. Covers Reflected, Stored, and…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Reconnaissance skill for XSS attack surface — analyzes headers, frameworks, JS libraries, and DOM patterns at a URL to map what makes XSS possible or harder. For ethical hackers preparing for XSS testing.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Generate security-focused DISCOVERY.md for code review and threat modeling. Use when assessing unfamiliar codebases.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Legal and ethical guidelines for bug bounties, pentesting, and security research. Use when conducting authorized security testing.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze SARIF files and generate security reports with CVSS scoring, exploitation scenarios, and remediation guidance. Use when reviewing static analysis results.

原文语言:英语

更新
已展示 9 / 89 个已收集 Skill。