Skip to main content
UnboundCompute
GitHub 创作者资料

UnboundCompute

按仓库查看 1 个 GitHub 仓库中的 130 个已收集 skills。

已收集 skills
130
仓库
1
更新
2026年8月29日
仓库分布

Skills 分布在哪些仓库

按已收集 skill 数展示主要仓库,并显示它们在该创作者目录中的占比和职业覆盖。

仓库浏览

仓库与代表性 skills

auditing-account-recovery-and-reset-trust
未分类

Audit password reset and account recovery flows for the trust that lets an attacker take over an account: a reset token that is guessable, long-lived, reusable, or not bound to the account it was issued for, a recovery path that verifies a weaker factor than…

2026年8月29日
auditing-http2-and-grpc-multiplexing-trust
未分类

Audit HTTP/2 and gRPC edges for framing and multiplexing trust that breaks when a stream is translated or reused: an h2c or HTTP/2-to-HTTP/1.1 downgrade that reintroduces request smuggling, pseudo-header and header handling that lets a stream forge its path…

2026年8月29日
auditing-jwt-verification-and-key-trust
未分类

Audit how a service verifies JSON Web Tokens for the classic verification bypasses: an algorithm-confusion attack where a token switches the signing algorithm so a public key is used as a symmetric secret or the algorithm is set to none, a key selected from…

2026年8月29日
auditing-message-broker-topic-authorization
未分类

Audit message-broker topic and queue authorization for reach a client should not have: a wildcard subscription that receives another tenant's messages, a publish permission broad enough to inject into a control or command topic, a shared broker where topic…

2026年8月29日
auditing-oauth-token-audience-and-scope-trust
未分类

Audit how a resource server trusts OAuth access tokens for confusion it should reject: a token minted for one audience accepted by a different service, a scope treated as coarser or finer than it is so a token reaches an operation it was not granted, a…

2026年8月29日
auditing-payment-callback-and-amount-integrity
未分类

Audit payment provider callbacks and settlement notifications for the trust that lets an attacker forge or alter a payment result: a callback whose signature is not verified so a spoofed success is accepted, an amount or currency taken from the callback or…

2026年8月29日
auditing-payment-state-machine-and-idempotency
未分类

Audit payment and checkout state machines for transitions an attacker can drive out of order or replay for value: an order marked paid before the charge is confirmed, a step that can be skipped or repeated so goods ship without settlement, a non-idempotent…

2026年8月29日
auditing-saml-and-oidc-federation-trust
未分类

Audit federated single sign-on for assertions a relying party should not trust: a SAML response whose signature is not verified over the right element so a wrapped or altered assertion passes, an OIDC ID token whose issuer, audience, or nonce is unchecked, a…

2026年8月29日
已展示 8 / 130 个已收集 Skill。
已展示 1 / 1 个仓库
已展示全部仓库