Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

laravelversions

laravelversions 收录了来自 tighten 的 12 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
12
Stars
98
更新
2026-06-10
Forks
47
职业覆盖
1 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

frisk-agentic-audit
信息安全分析师

Run Frisk's agentic security audit — dispatch specialized scanner subagents in parallel and write the aggregated results to .frisk/agentic-findings.json so the Frisk CLI can ingest them.

2026-06-10
frisk-scan-auth-flow
信息安全分析师

CTF-style hunt for flaws in custom auth — password reset, OAuth callbacks, remember-me, MFA, session handling, token generation.

2026-06-10
frisk-scan-business-logic-injection
信息安全分析师

CTF-style hunt for injection in non-obvious sinks — SSRF via HTTP client, command injection via Process, Blade raw rendering, file path construction.

2026-06-10
frisk-scan-idor
信息安全分析师

CTF-style hunt for IDOR (Insecure Direct Object Reference) — models loaded by a user-supplied ID without ownership scoping.

2026-06-10
frisk-scan-mass-assignment
信息安全分析师

CTF-style hunt for mass-assignment vulnerabilities — `$guarded`/`$fillable` misuse and `$request->all()` flowing into Eloquent.

2026-06-10
frisk-scan-open-redirect
信息安全分析师

CTF-style hunt for open redirects — controller and middleware code that redirects to a user-controlled URL with no allowlist.

2026-06-10
frisk-scan-privilege-escalation
信息安全分析师

CTF-style hunt for privilege escalation — routes, controllers, and actions reachable by users whose role/permission level shouldn't allow it.

2026-06-10
frisk-scan-prompt-injection
信息安全分析师

CTF-style hunt for prompt injection — user input flowing into LLM message payloads without sandboxing, and trusted LLM responses driving permission decisions or interpolated into Slack/HTML/markdown channels.

2026-06-10
frisk-scan-race-conditions
信息安全分析师

CTF-style hunt for race conditions and atomicity bugs — read-then-write on money/credits/quotas without locking, non-idempotent webhook handlers, double-spend windows.

2026-06-10
frisk-scan-sensitive-data-exposure
信息安全分析师

CTF-style hunt for tokens, hashes, secrets, and PII leaking via API responses, logs, error pages, or cached views.

2026-06-10
frisk-scan-tenancy
信息安全分析师

CTF-style hunt for cross-tenant data leakage in multi-tenant apps — queries that skip tenant scoping, jobs that drop tenant context, cache keys missing tenant prefix, shared storage paths.

2026-06-10
frisk-scan-webhook-integrity
信息安全分析师

CTF-style hunt for unverified or weakly-verified inbound webhooks — missing HMAC checks, timing-unsafe comparisons, missing replay protection, hand-rolled signed-URL verification.

2026-06-10