Authentication & Authorization Implementation Patterns workflow skill. Use this skill when the user needs Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
日本語の概要は準備中です。原文の説明を表示しています。
diegosouzapw/awesome-omni-skills☆ 1592026年7月8日 更新
Authentication & Authorization Implementation Patterns workflow skill. Use this skill when the user needs Build secure, scalable authentication and authorization systems using industry-standard patterns and modern best practices and the operator should preserve the upstream workflow, copied support files, and provenance before merging or handing off.
日本語の概要は準備中です。原文の説明を表示しています。
diegosouzapw/awesome-omni-skills☆ 1592026年7月8日 更新
红队渗透 / 攻防 — 受授权的红队作业者 + 渗透测试工程师 + 攻击型安全顾问的认知操作系统 (侦察 OSINT / 外网渗透 / 内网 AD 渗透 BloodHound + Kerberoasting + ADCS 利用 + 横向移动 / Web 应用渗透 OWASP WSTG / 移动 OWASP MASTG / 云渗透 AWS Azure GCP IAM 路径 + 容器逃逸 + K8s / C2 操作 Cobalt Strike Sliver Mythic Havoc + OPSEC / 初始访问 + AV EDR 绕过 (仅授权场景) / 无线 RF / 物理社工 / 报告与整改 / 框架 MITRE ATT&CK + D3FEND + PTES + OSSTMM + NIST 800-115 + Kill Chain / 法律伦理 CFAA + 网络安全法 + 刑法 285 286 + 数据安全法 + GDPR + 授权书 + 范围 + 交战规则 — 不含 黑产 / 未授权攻击 / 大规模 exploitation / 供应链投毒 / 未授权 DoS — 这是 重罪 + 行业封杀 + 律师吊销, 本 skill 严守 authorized-only 边界 — 也不含 蓝队 SOC + 恶意软件 即服务 / 僵尸网络 / 勒索软件作者 — 这是 cybercrime 不是 红队) (Cybersecurity Red Team / Offensive Security Operations — the cognitive operating system of authorized red team operators, penetration testers, and offensive security consultants covering (a) reconnaissance & OSINT (passive + active discovery, asset surface mapping), (b) external network pentest (perimeter, exposed services, web), (c) internal network / Active Directory pentest (AD enumeration via BloodHound, Kerberos abuse — Kerberoasting / AS-REP-roasting / Unconstrained delegation / S4U2self, NTLM relay, ADCS abuse, GPO abuse, lateral movement, privilege escalation), (d) web application pentest (OWASP WSTG, authentication, authorization, SSRF, XXE, deserialization, SSTI, prototype pollution, GraphQL, JWT, API), (e) mobile pentest (OWASP MASTG, iOS / Android, instrumentation Frida / Objection, MASVS), (f) cloud pentest (AWS / Azure / GCP — IAM enumeration, privilege escalation paths, container escape, K8s RBAC, serverless), (g) C2 operations & post-exploitation (Cobalt Strike / Sliver / Mythic / Havoc, beacon ops, malleable profiles, OPSEC), (h) initial access & evasion (phishing infrastructure, payload development, AV / EDR evasion, BYOVD, AMSI / ETW bypass — strictly for authorized engagements), (i) wireless / RF (WPA2/3, evil twin, Wi-Fi pivots), (j) physical / social engineering (badge cloning, pretexting, vishing — under engagement letter), (k) reporting & remediation (executive summary, technical findings, CVSS, MITRE ATT&CK mapping, retest), (l) frameworks & methodology (MITRE ATT&CK, MITRE D3FEND, PTES, OSSTMM, NIST SP 800-115, OWASP WSTG / MASTG, Cyber Kill Chain, Unified Kill Chain, Diamond Model), (m) law & ethics (CFAA US, Computer Misuse Act UK, 中国 刑法 285/286 + 网络安全法 + 数据安全法, GDPR for tested EU systems, engagement letter, scope, rules of engagement, safe harbor for bug bounty); NOT criminal hacking / 黑产 / unauthorized targeting / mass exploitation / supply-chain compromise / DoS against unconsented systems (这是 重罪 + 业内开除 + 律师执照吊销, 本 skill 严守 authorized-only 边界), NOT pure defensive blue team / SOC analyst tradecraft (是 平行学科, 仅做 边界标注 + ATT&CK 反推方向), NOT malware-as-a-service development / botnet ops / ransomware authoring (是 cybercrime 不是 红队), NOT 'ethical hacking' 在 'just curious 看看' 自我合理化的灰色操作 (违反 authorization 原则即不是 红队).) Master OS — automated mastery of Cybersecurity Red Team / Offensive Security Operations — the cognitive operating system of authorized red team operators, penetration testers, and offensive security consultants covering (a) reconnaissance & OSINT (passive + active discovery, asset surface mapping), (b) external network pentest (perimeter, exposed services, web), (c) internal network / Active Directory pentest (AD enumeration via BloodHound, Kerberos abuse — Kerberoasting / AS-REP-roasting / Unconstrained delegation / S4U2self, NTLM relay, ADCS abuse, GPO abuse, lateral movement, privilege escalation), (d) web application pentest (OWASP WSTG, authentication, authorization, SSRF, XXE, deserialization, SSTI, prototype pollution, GraphQL, JWT, API), (e) mobile pentest (OWASP MASTG, iOS / Android, instrumentation Frida / Objection, MASVS), (f) cloud pentest (AWS / Azure / GCP — IAM enumeration, privilege escalation paths, container escape, K8s RBAC, serverless), (g) C2 operations & post-exploitation (Cobalt Strike / Sliver / Mythic / Havoc, beacon ops, malleable profiles, OPSEC), (h) initial access & evasi
日本語の概要は準備中です。原文の説明を表示しています。
swaylq/master-skill☆ 1492026年9月6日 更新
Validates and summarizes the four required authorization forms in a personal injury matter (retainer, HIPAA release, insurance authorization, employment record release). Confirms signatures, dates, scope, and completeness to determine readiness for the investigation phase. Use when reviewing client onboarding packets, verifying authorization forms before discovery, or checking HIPAA and record-release compliance.
日本語の概要は準備中です。原文の説明を表示しています。
FDU-INS/Insurance-Skills☆ 762026年7月12日 更新
IDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fields, or missing object-level authorization checks.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Identify and exploit Broken Object Level Authorization (BOLA), historically known as Insecure Direct Object Reference (IDOR), in API architectures. Extremely common and critical flaw where an API fails to validate whether the currently authenticated user actually owns or retains permissions over the specifically requested database resource (ID).
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Deep API security assessment beyond surface scanning. Covers the full OWASP API Security Top 10 (2023): Broken Object Level Authorization (BOLA / IDOR), Broken Authentication, Broken Object Property Level Authorization (mass assignment + excessive data exposure), Unrestricted Resource Consumption, Broken Function Level Authorization (BFLA / vertical privilege escalation), Unrestricted Access to Sensitive Business Flows, Server-Side Request Forgery via API parameters, Security Misconfiguration, Improper Inventory Management (shadow/zombie/deprecated endpoints, v1/v2 drift), and Unsafe Consumption of third-party APIs. Works across REST, GraphQL, gRPC, SOAP, and MCP servers. Discovers APIs from OpenAPI/Swagger specs, GraphQL introspection, gRPC reflection, .well-known endpoints, JS bundles, and traffic capture. Uses kiterunner, ffuf, schemathesis, restler-fuzzer, openapi-fuzzer, graphql-cop, clairvoyance, batchql, inql, jwt_tool, postman, mitmproxy, and manual http(action="request", ...) payloads. Every technique includes actual payloads, commands, and verification logic. Chains from /pentester or /codebase when API endpoints are discovered, chains into /web-exploit when classic injection points are found in API parameters, chains into /post-exploit when RCE is achieved, and chains into /ai-redteam when an LLM/AI endpoint is discovered (chat APIs, completion endpoints, RAG search, agentic tool-use, MCP servers).
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
API authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or weak function-level authorization.
日本語の概要は準備中です。原文の説明を表示しています。
ShulkwiSEC/bb-huge☆ 242026年7月11日 更新
Use this skill when configuring Health Cloud patient consent management: setting up HIPAA authorization forms, consent templates, consent tracking per patient, and withdrawal handling. NOT for querying the AuthorizationFormConsent object hierarchy or its required field values — use data/consent-data-model-health. NOT for GDPR/CCPA marketing opt-out on ContactPointTypeConsent — use security/gdpr-data-privacy.
日本語の概要は準備中です。原文の説明を表示しています。
PranavNagrecha/AwesomeSalesforceSkills☆ 192026年10月4日 更新
Validates and summarizes the four required authorization forms in a personal injury matter (retainer, HIPAA release, insurance authorization, employment record release). Confirms signatures, dates, scope, and completeness to determine readiness for the investigation phase. Use when reviewing client onboarding packets, verifying authorization forms before discovery, or checking HIPAA and record-release compliance.
日本語の概要は準備中です。原文の説明を表示しています。
CSlawyer1985/legal-skillhub☆ 152026年9月23日 更新
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
日本語の概要は準備中です。原文の説明を表示しています。
andycungkrinx91/konoha☆ 92026年10月9日 更新
Knowledge base from NIST SP 800-37 Revision 2, the Risk Management Framework (RMF) for information systems and organizations. Use for the seven RMF steps (Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor) and their tasks; the three-tier organization-wide risk model; authorization boundaries; the requirements-to-controls relationship; security categorization (FIPS 199/200 high-water mark) and control selection/tailoring (SP 800-53/53B baselines); assessment, the authorization decision and risk acceptance, continuous monitoring and ongoing authorization; the security/privacy distinction; and supply chain risk management. This is the security-and-privacy-risk-governance edge of systems engineering — it governs how much protection and whether to accept residual risk, complementing the disciplines that decide how protection is built. Does NOT reproduce the SP 800-53 control catalog or its baselines, the FIPS impact tables, or the ISO/IEC/IEEE 15288 process text; it names and routes to them rather than restating them.
日本語の概要は準備中です。原文の説明を表示しています。
jgsystemsconsulting/jgs-se-knowledge-packs☆ 82026年10月9日 更新
Implement GCP Binary Authorization to enforce Dağıt:-time security controls that ensure only trusted, attested container images are Dağıtılmış to Google Kubernetes Engine and Cloud Run.
日本語の概要は準備中です。原文の説明を表示しています。
MustafaKemal0146/fetih☆ 52026年10月11日 更新
Tests REST and GraphQL APIs for Broken Object Level Authorization (BOLA/IDOR) vulnerabilities where an authenticated user can access or modify resources belonging to other users by manipulating object identifiers in API requests. The tester intercepts API calls, identifies object ID parameters (numeric IDs, UUIDs, slugs), and systematically replaces them with IDs belonging to other users to Belirle: if the server enforces per-object authorization. This is OWASP API Security Top 10 2023 risk ...
日本語の概要は準備中です。原文の説明を表示しています。
MustafaKemal0146/fetih☆ 52026年10月11日 更新
tespit etmeand test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
日本語の概要は準備中です。原文の説明を表示しています。
MustafaKemal0146/fetih☆ 52026年10月11日 更新
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
日本語の概要は準備中です。原文の説明を表示しています。
micsapp/micstec-skills☆ 42026年3月20日 更新
Use when you need to design, review, or improve security in Quarkus applications — including Quarkus Security with JWT/OIDC, basic auth, @RolesAllowed / @Authenticated / @PermitAll, SecurityIdentity, permission checks, path-based authorization in configuration, exception mapping for auth failures, and sensitive-data-safe logging. This should trigger for requests such as Add Quarkus security support; Review Quarkus security configuration; Improve API authorization in Quarkus; Add JWT/OIDC security in Quarkus; Harden Quarkus authorization rules. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
aibot88/sec_skill_store☆ 42026年5月27日 更新
Detects mass assignment via create/update($request->all()), unguarded models, and missing authorization on mutating controller actions in Laravel.
日本語の概要は準備中です。原文の説明を表示しています。
s977043/river-review☆ 42026年10月11日 更新
Detect and test for OWASP API3:2023 Broken Object Property Level Authorization vulnerabilities including excessive data exposure and mass assignment attacks.
日本語の概要は準備中です。原文の説明を表示しています。
aniket2348823/Vul-Agent☆ 22026年6月9日 更新
Djangoアプリのログイン、権限、入力処理、本番設定を点検します。不正な操作やスクリプト実行への対策から、ファイル投稿とAPIの保護まで見直すスキル。
- ログインと利用者権限のレビュー
- 公開前に本番設定を点検したいとき
- 入力処理やリクエスト保護の見直し
affaan-m/ECC☆ 27.7万2026年10月12日 更新
Use when the user mentions connect/disconnect wallet, sign in, sign out, web3 wallet, wallet address, check balance, how much crypto do I have, send BNB/USDT/crypto, transfer tokens, swap tokens, buy/sell token, DEX trade, limit order, market order, cancel order, get a quote, transaction history, wallet settings, daily limit, slippage, MEV protection, supported chains, available networks, prediction market, predict.fun, YES/NO market, place a prediction, redeem winnings, claim payout, prediction portfolio, prediction PnL, x402 payment, HTTP 402 Payment Required, pay a known x402 API, check approvals, view token approvals, revoke approval, manage approvals, wallet approvals, authorization management, token authorization, DeFi protocols, DeFi position, DeFi portfolio, staking, liquidity pool, LP, yield farming, health factor, APY, TVL, DeFi investment, DeFi deposit, DeFi redeem, DeFi stake, DeFi unstake, add liquidity, remove liquidity, claim rewards, claim fees, or any on-chain wallet operation.
日本語の概要は準備中です。原文の説明を表示しています。
ccxt/ccxt☆ 4.4万2026年10月8日 更新
Detect API enumeration attacks (BOLA/IDOR, OWASP API1:2023) by writing SIEM detection rules that flag sequential or UUID identifier iteration, parameter tampering, and mixed 200/401/403 response patterns from API gateway and WAF logs. Use when investigating suspected object-level authorization abuse, building threat-hunting queries for API access-control bypass, or hardening API logging/rate-limiting against enumeration.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability testing.
日本語の概要は準備中です。原文の説明を表示しています。
mukul975/Anthropic-Cybersecurity-Skills☆ 3.4万2026年8月31日 更新
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with bcrypt/argon2, sanitizing SQL queries with parameterized statements, configuring CORS/CSP headers, validating input with Zod, and setting up JWT tokens. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention, secure session management, and security hardening. For pre-built OAuth/SSO integrations or standalone security audits, consider a more specialized skill.
日本語の概要は準備中です。原文の説明を表示しています。
Jeffallan/claude-skills☆ 1.2万2026年10月4日 更新