sast-idor
Automated detection of IDOR vulnerabilities using a three-phase subagent workflow to verify authorization and ownership checks on sensitive endpoints.
Discover reusable agent skills, browse implementation details, and find the right skill for your workflow.
88 skills found
Automated detection of IDOR vulnerabilities using a three-phase subagent workflow to verify authorization and ownership checks on sensitive endpoints.
Automated security scanning for n8n workflows: detects credential exposure, validates OAuth flows, tests API key management, and checks data sanitization.
A security scanner for Claude Skills to detect malicious code, data exfiltration risks, and unauthorized system access before installation.
Automated security validation, RLS enforcement, OWASP compliance, and vulnerability scanning for AI-assisted development workflows.
Detects timing side-channel vulnerabilities in cryptographic code through static and dynamic analysis across multiple programming languages.
Create, test, and validate custom Semgrep rules for security vulnerabilities and code pattern detection.
Perform deep security analysis on codebases using CodeQL for interprocedural data flow, taint tracking, and automated vulnerability detection across multiple languages.
Security-first auditing framework for AI-generated code. Provides multi-level protection including hardcoded secret detection, dangerous pattern identification, and comprehensive vulnerability audits for modern web applications.
Map the attack surface of smart contract codebases by identifying and categorizing state-changing entry points.
Diagnose and resolve connection, sync, subscription, and type issues in Dojo.js applications. Use for troubleshooting Torii, entity queries, and state updates.
Analyze C++ code for real-time safety violations including heap allocations, locks, blocking calls, and non-deterministic operations in high-performance audio threads.
Extracts Supabase anonymous API keys from client-side source code to facilitate RLS testing and security auditing.