Search

Security · By cyberful

61 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Design and interpret advanced content discovery with ffuf and complementary web fuzzers.

cyberful/cyberful135—~1.5kAutomated safety check: PassAGPL-3.01 mo ago
2

Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
3

Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

cyberful/cyberful135—~1.3kAutomated safety check: PassAGPL-3.01 mo ago
4

Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
5

Assess race conditions, transactional invariants, idempotency, retries, replay, rate and quota enforcement, algorithmic complexity, resource amplification, and cost abuse during authorized…

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
6

Test native or language object reconstruction, polymorphic type selection, gadget reachability, schema bypass, mass object binding, and unsafe serializer configuration in authorized applications or…

cyberful/cyberful135—~654Automated safety check: PassAGPL-3.01 mo ago
7

Test authorized web-cache key construction, variation, partitioning, authenticated response handling, revalidation, poisoning, deception, purge, and TTL behavior.

cyberful/cyberful135—~631Automated safety check: PassAGPL-3.01 mo ago
8

Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence.

cyberful/cyberful135—~535Automated safety check: PassAGPL-3.01 mo ago
9

Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability.

cyberful/cyberful135—~538Automated safety check: PassAGPL-3.01 mo ago
10

Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects.

cyberful/cyberful135—~549Automated safety check: PassAGPL-3.01 mo ago
11

Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system.

cyberful/cyberful135—~517Automated safety check: PassAGPL-3.01 mo ago
12

Extract bounded, deterministic evidence from crash and sanitizer logs, including signals, sanitizer classes, memory-safety indicators, stack-frame hashes, and source provenance, while reserving…

cyberful/cyberful135—~563Automated safety check: PassAGPL-3.01 mo ago
13

Normalize and compare authorized fraud-control observations from local evidence, highlighting decision drift, coverage gaps, and conflicting outcomes without making a fraud or vulnerability verdict.

cyberful/cyberful135—~649Automated safety check: PassAGPL-3.01 mo ago
14

Parse bounded classic PCAP files offline into deterministic capture metadata, packet-length and timestamp summaries, link and network protocol counts, truncation indicators, and source digests…

cyberful/cyberful135—~590Automated safety check: PassAGPL-3.01 mo ago
15

Model fraud and abuse threats across actors, account states, value flows, controls, and monetization paths.

cyberful/cyberful135—~716Automated safety check: PassAGPL-3.01 mo ago
16

Assess the security of a smart-contract system across protocol economics, trust roles, upgrade and governance paths, oracle and bridge dependencies, deployment state, and off-chain operators.

cyberful/cyberful135—~651Automated safety check: PassAGPL-3.01 mo ago
17

Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures.

cyberful/cyberful135—~637Automated safety check: PassAGPL-3.01 mo ago
18

Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and…

cyberful/cyberful135—~644Automated safety check: PassAGPL-3.01 mo ago
19

Audit security logging and telemetry from event creation through transport, storage, access, correlation, retention, and response use.

cyberful/cyberful135—~597Automated safety check: PassAGPL-3.01 mo ago
20

Test browser capability transfer across postMessage, opener, frame, portal, worker, service-worker, BroadcastChannel, MessagePort, and extension messaging boundaries.

cyberful/cyberful135—~583Automated safety check: PassAGPL-3.01 mo ago
21

Test whether every segmentation and scope-reduction control isolates the cardholder data environment from claimed out-of-scope systems and differing security levels.

cyberful/cyberful135—~928Automated safety check: PassAGPL-3.01 mo ago
22

Test payment decision and value-movement invariants with authorized synthetic instruments and reversible sandbox transactions.

cyberful/cyberful135—~668Automated safety check: PassAGPL-3.01 mo ago
23

Trace uploaded, imported, generated, archived, converted, scanned, rendered, and downloaded files across storage, naming, extraction, parser, sandbox, and cleanup boundaries.

cyberful/cyberful135—~646Automated safety check: PassAGPL-3.01 mo ago
24

Reconstruct how principal, actor, issuer, audience, assurance, scopes, and delegated authority change across requests, tokens, services, queues, and stored artifacts.

cyberful/cyberful135—~730Automated safety check: PassAGPL-3.01 mo ago
25

Reconstruct how tenant and organization context is authenticated, selected, routed, cached, queued, and bound to resources across distributed request paths.

cyberful/cyberful135—~679Automated safety check: PassAGPL-3.01 mo ago
26

Reconstruct transaction state across services, ledgers, queues, and compensations from local artifacts, identifying causal gaps, duplicate effects, and value mismatches without active traffic.

cyberful/cyberful135—~635Automated safety check: PassAGPL-3.01 mo ago
27

Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
28

Route broad AI-agent security reviews to focused Cyberful skills across risk, model supply chain, context and capabilities, prompt injection, tool authorization, and RAG isolation.

cyberful/cyberful135—~723Automated safety check: PassAGPL-3.01 mo ago
29

Coordinate a repository-wide white-box application security audit across architecture, source, configuration, dependencies, build, and deployment paths.

cyberful/cyberful135—~774Automated safety check: PassAGPL-3.01 mo ago
30

Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk.

cyberful/cyberful135—~829Automated safety check: PassAGPL-3.01 mo ago
31

Coordinate an authorized software-supply-chain audit from dependency resolution through build, artifact, release, deployment, and runtime trust.

cyberful/cyberful135—~737Automated safety check: PassAGPL-3.01 mo ago
32

Operate Cyberful as an authorized application-security control room.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.0-only1 mo ago
33

Operate Ghidra headless analysis, radare2, platform binary utilities, decompilers, and targeted dynamic evidence for advanced native and bytecode security review.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
34

Operate Prowler, Cloudsplaining, cloud CLIs, policy documents, and resource evidence for advanced AWS, Azure, GCP, and Kubernetes-adjacent posture assessment.

cyberful/cyberful135—~907Automated safety check: PassAGPL-3.01 mo ago
35

Operate Cyberful's pinned Foundry toolchain and engagement-owned Anvil lab for authorized EVM smart-contract bug bounty work.

cyberful/cyberful135—~851Automated safety check: PassAGPL-3.01 mo ago
36

Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment.

cyberful/cyberful135—~898Automated safety check: PassAGPL-3.01 mo ago
37

Operate AFL++, libFuzzer with Clang sanitizers, and Jazzer for advanced coverage-guided native and JVM fuzzing.

cyberful/cyberful135—~1.3kAutomated safety check: PassAGPL-3.01 mo ago
38

Use sqlmap to confirm and characterize suspected SQL injection with faithful requests and bounded evidence.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
39

Coordinate testing of product invariants and multi-step workflows across money, entitlements, approvals, quotas, inventory, onboarding, and distributed state.

cyberful/cyberful135—~714Automated safety check: PassAGPL-3.01 mo ago
40

Assess sensitive-data lifecycle, secret handling, cryptographic design and implementation, key management, password storage, randomness, signing, encryption, transport protection, and side channels…

cyberful/cyberful135—~924Automated safety check: PassAGPL-3.01 mo ago
41

Assess server-side URL retrieval and network egress during authorized penetration tests or code audits.

cyberful/cyberful135—~867Automated safety check: PassAGPL-3.01 mo ago
42

Test and audit authenticated session state across cookies, opaque tokens, bearer tokens, refresh tokens, devices, browsers, APIs, and privilege transitions.

cyberful/cyberful135—~915Automated safety check: PassAGPL-3.01 mo ago
43

Reconstruct request and event causality across gateways, services, queues, workers, data stores, and external providers while preserving identity, tenant, authorization, retry, and side-effect…

cyberful/cyberful135—~617Automated safety check: PassAGPL-3.01 mo ago
44

Trace and test untrusted data through SQL, NoSQL, LDAP, XPath, XML, shell, process, template, expression-language, code-evaluation, log, spreadsheet, mail, header, and browser interpreters.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
45

Transform bounded HAR captures into deterministic HTTP evidence about methods, origins, paths, status classes, header presence, redirects, cookies, and body sizes without replaying traffic or…

cyberful/cyberful135—~544Automated safety check: PassAGPL-3.01 mo ago
46

Normalize and correlate bounded SARIF and Cyberful finding exports offline by rule, location, fingerprint, source, level, suppression, and evidence reference without treating scanner severity as…

cyberful/cyberful135—~543Automated safety check: PassAGPL-3.01 mo ago
47

Assess AI-system risk from architecture, intended use, affected actors, model limitations, data lineage, autonomy, human oversight, monitoring, and failure consequences.

cyberful/cyberful135—~566Automated safety check: PassAGPL-3.01 mo ago
48

Audit container runtime isolation across namespaces, capabilities, seccomp, mandatory access control, mounts, devices, daemon sockets, cgroups, identity, and host integration.

cyberful/cyberful135—~545Automated safety check: PassAGPL-3.01 mo ago