All categories
Security
Security audits, vulnerabilities, compliance, auth, secrets, and safe automation
- 28,990
- 1,208
Security grades appear on each card once the skill has been scanned. Newly imported skills may briefly show without a grade until the backfill job runs.
Open in full browserBrowse security skills
Showing 985–1,008 of 28,990 skills
- Browser Page Content Injection DefenseUse when a task involves testing whether page text or browser output can improperly change an agent's instructions to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or ...Votes: 0GitHub stars: 2
- Browser Offline Reconnect State ValidationUse when a task involves testing how a web application behaves when browser connectivity is lost and restored to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perfo...Votes: 0GitHub stars: 2
- Browser Network Trace Credential RedactionUse when a task involves redacting credentials and personal data from browser network traces to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform external write...Votes: 0GitHub stars: 2
- Browser Network Response Body MinimizationUse when a task involves minimizing sensitive content collected from browser network responses to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform external wri...Votes: 0GitHub stars: 2
- Browser Network Request Correlation ReviewUse when a task involves correlating a browser action with the network requests and response that support its result to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, o...Votes: 0GitHub stars: 2
- Browser Network Egress Allowlist ReviewUse when a task involves reviewing outbound destinations reachable from browser automation to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform external writes ...Votes: 0GitHub stars: 2
- Browser Navigation To Private Network GuardUse when a task involves reviewing protections against browser navigation to unauthorized internal or local network endpoints to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication...Votes: 0GitHub stars: 2
- Browser Navigation Readiness Condition ReviewUse when a task involves selecting a reliable readiness condition before browser automation continues after navigation to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state,...Votes: 0GitHub stars: 2
- Browser Native Dropdown State ValidationUse when a task involves checking selected values and keyboard behavior in native select controls to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform external ...Votes: 0GitHub stars: 2
- Browser Multi Step Wizard State TransitionUse when a task involves verifying state preservation and navigation in a multi-step browser wizard to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform externa...Votes: 0GitHub stars: 2
- Browser Modal Dialog Approval PolicyUse when a task involves handling modal dialogs that may block a page or request a consequential choice to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform ext...Votes: 0GitHub stars: 2
- Browser Location Camera Microphone Consent ReviewUse when a task involves reviewing when a browser application requests access to sensitive device capabilities to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perf...Votes: 0GitHub stars: 2
- Browser Locale Timezone Form Input AuditUse when a task involves validating dates, times, numbers, and currencies entered through a localized browser interface to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state...Votes: 0GitHub stars: 2
- Browser Local Storage Token HandlingUse when a task involves reviewing local or session storage that contains authentication or account data to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform ex...Votes: 0GitHub stars: 2
- Browser Infinite Scroll Completeness PolicyUse when a task involves defining a bounded stopping rule for collecting items from an infinite-scroll page to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform...Votes: 0GitHub stars: 2
- Browser Iframe Origin Data Boundary ReviewUse when browser automation must identify an embedded frame's owner and origin before reading or interacting with it, especially when data could cross a cross-origin boundary to produce a frame-origin map and bounded evidence of permitted visibility and actions. Success means the selected frame matches the approved target, parent and child data are distinguished, redirects and nested frames are checked, and no hidden or third-party data is extracted. Use an authorized browser context and do n...Votes: 0GitHub stars: 2
- Browser Identity Provider Human HandoffUse when a task involves handling login, identity verification, and multi-factor prompts that require the account holder to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication stat...Votes: 0GitHub stars: 2
- Browser Hover Only Control ReachabilityUse when a task involves checking whether an important control is inaccessible when revealed only by pointer hover to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or ...Votes: 0GitHub stars: 2
- Browser Frontend Error Source Map ExposureUse when a task involves checking whether browser error handling exposes source maps or sensitive stack details to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or per...Votes: 0GitHub stars: 2
- Browser Form Submission Preview GateUse when a task involves reviewing exact browser form values and effects before a submission to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform external write...Votes: 0GitHub stars: 2
- Browser Form Autofill Data BoundaryUse when a task involves reviewing browser autofill exposure before an automation task interacts with a form to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perfor...Votes: 0GitHub stars: 2
- Browser Font Loading Layout Shift DiagnosisUse when a task involves diagnosing layout shifts caused by font loading or fallback in a browser page to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform exte...Votes: 0GitHub stars: 2
- Browser File Upload Type And Size PreflightUse when a task involves checking file type, size, and destination before a browser upload to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform external writes ...Votes: 0GitHub stars: 2
- Browser Download Quarantine And Malware TriageUse when a task involves handling browser downloads as untrusted files before inspection or execution to record the target site and origin, browser and driver version, active account, test or production context, user authorization, data sensitivity, and intended side effects. Use a bounded, reproducible interaction, verify both browser-visible and relevant underlying state, preserve evidence safely, and report uncertainty. Do not reuse profiles, disclose authentication state, or perform exter...Votes: 0GitHub stars: 2