All authors
dmdhrumilmistry avatar

Claude Skills by dmdhrumilmistry

github.com/dmdhrumilmistry
36 skillsA× 32B× 40 installs0 views
Sh Kb Access ControlA

Knowledge base for finding broken access control - IDOR/BOLA, missing function-level authorization, privilege escalation, and multi-tenant isolation failures. Use when hunting authorization issues or reviewing whether users can access resources/actions they shouldn't. CWE-284/285/639/862/863, OWASP A01:2021-Broken Access Control.

securityrustsql
0
14
Sh Kb AuthA

Knowledge base for finding authentication and session-management failures - weak login, broken JWT/session handling, password/reset flaws, MFA bypass, credential storage issues. Use when hunting authentication (not authorization - see sh-kb-access-control). CWE-287/384/613/620/640, OWASP A07:2021-Identification and Authentication Failures.

securityrustgo
0
14
Sh Kb CryptoA

Knowledge base for finding cryptographic failures - weak hashing/encryption, insecure randomness, hardcoded/static keys and IVs, ECB mode, missing integrity, and predictable tokens. Use when hunting crypto misuse. CWE-327/328/330/326/916, OWASP A02:2021-Cryptographic Failures.

securitypythonrust
0
14
Sh Kb CsrfA

Knowledge base for finding Cross-Site Request Forgery - state-changing requests that rely only on ambient credentials (cookies) with no anti-CSRF token or SameSite protection. Use when hunting CSRF. CWE-352, OWASP A01:2021-Broken Access Control.

ai-agentsrustexpress
0
14
Sh Kb DeserializationA

Knowledge base for finding insecure deserialization - untrusted data fed to object-deserialization APIs that can trigger RCE or object injection via gadget chains. Use when hunting deserialization issues. CWE-502, OWASP A08:2021-Software and Data Integrity Failures.

developmentjavascriptpython
0
14
Sh Kb File UploadA

Knowledge base for finding unrestricted/insecure file upload - uploads that allow dangerous file types, execution in the upload dir, path control over the stored name, or missing content validation, leading to RCE, XSS, or overwrite. Use when hunting file-upload issues. CWE-434/436/616, OWASP A04/A05:2021.

ai-agentsrustphp
0
14
Sh Kb InjectionA

Knowledge base for finding command/OS injection, template injection (SSTI), code injection (eval), and LDAP/NoSQL/expression injection. Use when hunting injection into shells, template engines, interpreters, or directory queries. CWE-77/78/94/917, OWASP A03:2021-Injection.

ai-agentspythonrust
0
14
Sh Kb Open RedirectA

Knowledge base for finding open/unvalidated redirects - user-controlled redirect targets that send victims to attacker sites, enabling phishing, token leakage, and OAuth/SSO abuse. Use when hunting open redirects. CWE-601, OWASP A01:2021-Broken Access Control.

developmentjavascriptpython
0
14
Sh Kb Path TraversalB

Knowledge base for finding path/directory traversal and local/remote file inclusion - user-controlled paths reaching filesystem or include operations, enabling arbitrary file read/write or code inclusion. Use when hunting traversal/LFI/RFI. CWE-22/23/98, OWASP A01:2021-Broken Access Control.

ai-agentsrustphp
0
14
Sh Kb Race ConditionsA

Knowledge base for finding race conditions and TOCTOU flaws - concurrent requests exploiting non-atomic check-then-act logic (double-spend, limit bypass, balance manipulation, file TOCTOU). Use when hunting concurrency/business-logic race bugs. CWE-362/367/366, OWASP A04:2021-Insecure Design.

ai-agentsawsbackend
0
14
Sh Kb SecretsA

Knowledge base for finding hardcoded secrets and sensitive-data exposure - API keys, passwords, tokens, private keys, and connection strings embedded in source/config, or secrets leaked to logs/errors/URLs. Use when hunting secret exposure. CWE-798/259/312/532, OWASP A05/A02:2021.

ai-agentsgosql
0
14
Sh Kb SqliA

Knowledge base for finding SQL injection (and query-language injection). Use when hunting SQLi, or when a hunter/reviewer needs sources, sinks, detection queries, payloads, false-positive filters, and remediation for injection into SQL/ORM raw queries. CWE-89, OWASP A03:2021-Injection.

ai-agentspythonrust
0
14
Sh Kb SsrfA

Knowledge base for finding Server-Side Request Forgery - when the server makes outbound requests to attacker-controlled destinations. Use when hunting SSRF or reviewing URL/host inputs that reach HTTP/network clients. CWE-918, OWASP A10:2021-SSRF.

toolspythonrust
0
14
Sh Kb XssA

Knowledge base for finding Cross-Site Scripting - reflected, stored, and DOM-based XSS. Use when hunting XSS or reviewing untrusted data rendered into HTML/JS/attributes without context-correct encoding. CWE-79, OWASP A03:2021-Injection.

developmentjavascriptrust
0
14
Sh Kb XxeB

Knowledge base for finding XML External Entity injection - XML parsers configured to resolve external/general entities on untrusted input, enabling file read, SSRF, and DoS. Use when hunting XXE. CWE-611/776/827, OWASP A05:2021-Security Misconfiguration.

ai-agentspythonrust
0
14
Sh Pr ReviewA

Security-review a GitHub pull request, post the result as inline review comments on the PR, and set a pass/fail commit status that branch protection can enforce. Fails the PR for vulnerabilities it introduces or makes worse; passes with a warning for pre-existing ones. Triages the diff first and scales depth to risk, dedupes across re-pushes, and never posts without an explicit yes. Use when reviewing a pull request rather than a whole codebase.

ai-agentspythonrust
0
14
Sh RouterA

Entry point / dispatcher for the security-harness. Use when the user asks for any application-security work - 'security review', 'audit this codebase', 'pentest', 'find vulnerabilities', 'check for SQLi/XSS/IDOR/SSRF', 'generate a security report/SARIF'. Interprets the request and routes it to the full sh-security-review pipeline, a single stage, or a single vulnerability-class knowledge base.

securitysqlgit
0
14
Sh Security ReviewA

Run the full multi-agent security review pipeline on a codebase - recon/mapping (Graft + SBOM/CVE), parallel vulnerability hunting backed by ~15 per-class knowledge bases, escalation chaining, impact verification, and reporting to README/JSON/SARIF/doc/PDF. Use when the user asks to security-review, audit, pentest, or find vulnerabilities in a codebase. Usually invoked via the sh-router skill.

ai-agentssqlnode
0
14
Sh Kb Access ControlA

Knowledge base for finding broken access control - IDOR/BOLA, missing function-level authorization, privilege escalation, and multi-tenant isolation failures. Use when hunting authorization issues or reviewing whether users can access resources/actions they shouldn't. CWE-284/285/639/862/863, OWASP A01:2021-Broken Access Control.

securityrustsql
0
14
Sh Kb AuthA

Knowledge base for finding authentication and session-management failures - weak login, broken JWT/session handling, password/reset flaws, MFA bypass, credential storage issues. Use when hunting authentication (not authorization - see sh-kb-access-control). CWE-287/384/613/620/640, OWASP A07:2021-Identification and Authentication Failures.

securityrustgo
0
14
Sh Kb CryptoA

Knowledge base for finding cryptographic failures - weak hashing/encryption, insecure randomness, hardcoded/static keys and IVs, ECB mode, missing integrity, and predictable tokens. Use when hunting crypto misuse. CWE-327/328/330/326/916, OWASP A02:2021-Cryptographic Failures.

securitypythonrust
0
14
Sh Kb CsrfA

Knowledge base for finding Cross-Site Request Forgery - state-changing requests that rely only on ambient credentials (cookies) with no anti-CSRF token or SameSite protection. Use when hunting CSRF. CWE-352, OWASP A01:2021-Broken Access Control.

ai-agentsrustexpress
0
14
Sh Kb DeserializationA

Knowledge base for finding insecure deserialization - untrusted data fed to object-deserialization APIs that can trigger RCE or object injection via gadget chains. Use when hunting deserialization issues. CWE-502, OWASP A08:2021-Software and Data Integrity Failures.

developmentjavascriptpython
0
14
Sh Kb File UploadA

Knowledge base for finding unrestricted/insecure file upload - uploads that allow dangerous file types, execution in the upload dir, path control over the stored name, or missing content validation, leading to RCE, XSS, or overwrite. Use when hunting file-upload issues. CWE-434/436/616, OWASP A04/A05:2021.

ai-agentsrustphp
0
14
Sh Kb InjectionA

Knowledge base for finding command/OS injection, template injection (SSTI), code injection (eval), and LDAP/NoSQL/expression injection. Use when hunting injection into shells, template engines, interpreters, or directory queries. CWE-77/78/94/917, OWASP A03:2021-Injection.

ai-agentspythonrust
0
14
Sh Kb Open RedirectA

Knowledge base for finding open/unvalidated redirects - user-controlled redirect targets that send victims to attacker sites, enabling phishing, token leakage, and OAuth/SSO abuse. Use when hunting open redirects. CWE-601, OWASP A01:2021-Broken Access Control.

developmentjavascriptpython
0
14
Sh Kb Path TraversalB

Knowledge base for finding path/directory traversal and local/remote file inclusion - user-controlled paths reaching filesystem or include operations, enabling arbitrary file read/write or code inclusion. Use when hunting traversal/LFI/RFI. CWE-22/23/98, OWASP A01:2021-Broken Access Control.

ai-agentsrustphp
0
14
Sh Kb Race ConditionsA

Knowledge base for finding race conditions and TOCTOU flaws - concurrent requests exploiting non-atomic check-then-act logic (double-spend, limit bypass, balance manipulation, file TOCTOU). Use when hunting concurrency/business-logic race bugs. CWE-362/367/366, OWASP A04:2021-Insecure Design.

ai-agentsawsbackend
0
14
Sh Kb SecretsA

Knowledge base for finding hardcoded secrets and sensitive-data exposure - API keys, passwords, tokens, private keys, and connection strings embedded in source/config, or secrets leaked to logs/errors/URLs. Use when hunting secret exposure. CWE-798/259/312/532, OWASP A05/A02:2021.

ai-agentsgosql
0
14
Sh Kb SqliA

Knowledge base for finding SQL injection (and query-language injection). Use when hunting SQLi, or when a hunter/reviewer needs sources, sinks, detection queries, payloads, false-positive filters, and remediation for injection into SQL/ORM raw queries. CWE-89, OWASP A03:2021-Injection.

ai-agentspythonrust
0
14
Sh Kb SsrfA

Knowledge base for finding Server-Side Request Forgery - when the server makes outbound requests to attacker-controlled destinations. Use when hunting SSRF or reviewing URL/host inputs that reach HTTP/network clients. CWE-918, OWASP A10:2021-SSRF.

toolspythonrust
0
14
Sh Kb XssA

Knowledge base for finding Cross-Site Scripting - reflected, stored, and DOM-based XSS. Use when hunting XSS or reviewing untrusted data rendered into HTML/JS/attributes without context-correct encoding. CWE-79, OWASP A03:2021-Injection.

developmentjavascriptrust
0
14
Sh Kb XxeB

Knowledge base for finding XML External Entity injection - XML parsers configured to resolve external/general entities on untrusted input, enabling file read, SSRF, and DoS. Use when hunting XXE. CWE-611/776/827, OWASP A05:2021-Security Misconfiguration.

ai-agentspythonrust
0
14
Sh Pr ReviewA

Security-review a GitHub pull request, post the result as inline review comments on the PR, and set a pass/fail commit status that branch protection can enforce. Fails the PR for vulnerabilities it introduces or makes worse; passes with a warning for pre-existing ones. Triages the diff first and scales depth to risk, dedupes across re-pushes, and never posts without an explicit yes. Use when reviewing a pull request rather than a whole codebase.

ai-agentspythonrust
0
14
Sh RouterA

Entry point / dispatcher for the security-harness. Use when the user asks for any application-security work - 'security review', 'audit this codebase', 'pentest', 'find vulnerabilities', 'check for SQLi/XSS/IDOR/SSRF', 'generate a security report/SARIF'. Interprets the request and routes it to the full sh-security-review pipeline, a single stage, or a single vulnerability-class knowledge base.

securitysqlgit
0
14
Sh Security ReviewA

Run the full multi-agent security review pipeline on a codebase - recon/mapping (Graft + SBOM/CVE), parallel vulnerability hunting backed by ~15 per-class knowledge bases, escalation chaining, impact verification, and reporting to README/JSON/SARIF/doc/PDF. Use when the user asks to security-review, audit, pentest, or find vulnerabilities in a codebase. Usually invoked via the sh-router skill.

ai-agentssqlnode
0
14