cybersec

Solid

Security audit toolkit for the ccboard project (Rust/Leptos/Axum stack). Use when auditing authentication flows, API endpoints, WASM security, or reviewing Rust code for unsafe usage and memory safety issues.

API & Backend 96 stars 8 forks Updated 3 weeks ago MIT

Install

View on GitHub

Quality Score: 84/100

Stars 20%
66
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
40
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Cybersec Skills — ccboard Security audit toolkit for the ccboard Rust/Leptos stack. ## Reference files in this directory These files are reference documentation for security test patterns. Update them to reflect ccboard's actual Axum routes, auth flows, and data model. ## Key security areas for ccboard - **Authentication**: session tokens, CSRF protection in Leptos forms - **Authorization**: route-level guards in Axum middleware - **WASM**: client-side code exposure, sensitive data in WASM binary - **SQL**: raw query usage, input sanitization - **Dependency audit**: `cargo audit` for known CVEs in dependencies ## Usage ```bash cargo audit # CVE scan grep -r "unsafe" src/ # unsafe block audit grep -r "unwrap()" src/ | wc -l # panic surface audit ```

Details

Author
FlorianBruniaux
Repository
FlorianBruniaux/ccboard
Created
7 months ago
Last Updated
3 weeks ago
Language
Rust
License
MIT

Integrates with

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

Data & Documents Listed

security-audit

Audits codebases for security vulnerabilities, secrets exposure, auth risks, dependency health, and misconfigurations.

0 Updated 2 weeks ago
alimansoor2003
Code & Development Listed

golang-security

Security best practices and vulnerability prevention for Golang — injection (SQL, command, XSS), cryptography, path traversal, SSRF and HTTP security headers, cookies, secrets management, memory safety, PII in logs, STRIDE/DREAD threat modeling, plus `gosec` SAST, race detection, and fuzz testing. Apply when writing, reviewing, or auditing Go code for security, or when touching crypto, file or network I/O, secrets, user input, or authentication. Not for non-exploitable defensive bugs such as nil panics or slice aliasing (→ See `samber/cc-skills-golang@golang-safety` skill), dependency vulnerability scanning with govulncheck (→ See `samber/cc-skills-golang@golang-dependency-management` skill), or wiring security scanners into CI pipelines (→ See `samber/cc-skills-golang@golang-continuous-integration` skill).

0 Updated 1 weeks ago
rzisso
AI & Automation Listed

mkcso

Chief Security Officer mode. Infrastructure-first security audit: secrets archaeology, dependency supply chain, CI/CD pipeline security, LLM/AI security, skill supply chain scanning, plus OWASP Top 10, STRIDE threat modeling, and active verification. Two modes: daily (zero-noise, 8/10 confidence gate) and comprehensive (monthly deep scan, 2/10 bar). Trend tracking across audit runs. Use when: "security audit", "threat model", "pentest review", "OWASP", "CSO review".

14 Updated 2 months ago
ngocsangyem