vulnerability-analysis
FeaturedUse when auditing source code for vulnerabilities — drive CodeQL/Semgrep/Joern to taint untrusted data source-to-sink across injection, memory safety, deserialization/prototype-pollution, secrets/crypto/authz/race, and supply-chain risks
Install
Quality Score: 95/100
Skill Content
Details
- Author
- hypnguyen1209
- Repository
- hypnguyen1209/offensive-claude
- Created
- 4 months ago
- Last Updated
- 5 days ago
- Language
- Python
- License
- MIT
Bundled in these plugins
Similar Skills
Semantically similar based on skill content — not just same category
vuln-audit
Audit application code for the OWASP Top 10 classes: injection (SQL/NoSQL/command), XSS, CSRF, SSRF, IDOR and broken access control, insecure deserialization, unsafe file upload, and misconfiguration. Use for any security review, "is this safe?", or code that handles untrusted input, queries, uploads, outbound URLs, or objects by ID. Produces a severity-ranked report with concrete fixes and proof. Defensive only.
vuln-scan
Systematic vulnerability scan across injection, auth, data exposure, and dependencies — traced by reading code, not grepping for keywords. Use when scanning for vulnerabilities, reviewing security, or validating threat models.