Search

By cyberful

85 skills found.
Search results
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

cyberful/cyberful135—~649Automated safety check: PassAGPL-3.01 mo ago
2

Audit Kubernetes admission and policy-as-code enforcement against local workload manifests, exception paths, namespace scope, and deployment evidence.

cyberful/cyberful135—~610Automated safety check: PassAGPL-3.01 mo ago
3

Audit PCI DSS penetration-test methodology, scope, internal and external reports, segmentation results, tester independence, remediation, retesting, retention, and multi-tenant support evidence.

cyberful/cyberful135—~1kAutomated safety check: PassAGPL-3.01 mo ago
4

Design and interpret advanced content discovery with ffuf and complementary web fuzzers.

cyberful/cyberful135—~1.5kAutomated safety check: PassAGPL-3.01 mo ago
5

Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
6

Operate Semgrep and source-oriented static analysis as a hypothesis, coverage, and regression system during advanced code audits.

cyberful/cyberful135—~1.3kAutomated safety check: PassAGPL-3.01 mo ago
7

Operate Syft, Grype, Trivy, Gitleaks, Retire.js, package-manager metadata, and build evidence for advanced software-supply-chain assessment.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
8

Assemble reviewed compliance evidence into a versioned, traceable draft report for PCI DSS or GDPR.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
9

Assess race conditions, transactional invariants, idempotency, retries, replay, rate and quota enforcement, algorithmic complexity, resource amplification, and cost abuse during authorized…

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
10

Test native or language object reconstruction, polymorphic type selection, gadget reachability, schema bypass, mass object binding, and unsafe serializer configuration in authorized applications or…

cyberful/cyberful135—~654Automated safety check: PassAGPL-3.01 mo ago
11

Assess WebSocket, Server-Sent Events, webhook, event-stream, callback, and asynchronous integration security during authorized penetration tests or code audits.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
12

Test executable smart-contract properties with deterministic, offline Foundry harnesses over a confined source snapshot.

cyberful/cyberful135—~745Automated safety check: PassAGPL-3.01 mo ago
13

Test authorized web-cache key construction, variation, partitioning, authenticated response handling, revalidation, poisoning, deception, purge, and TTL behavior.

cyberful/cyberful135—~631Automated safety check: PassAGPL-3.01 mo ago
14

Trace how clients, CDNs, proxies, protocol translators, gateways, frameworks, and origins derive HTTP message boundaries, authority, paths, queries, and trusted forwarding metadata.

cyberful/cyberful135—~711Automated safety check: PassAGPL-3.01 mo ago
15

Deterministically compare OpenAPI JSON operations with implementation and observation inventories to expose undocumented, unimplemented, unexercised, and security-declaration coverage gaps.

cyberful/cyberful135—~585Automated safety check: PassAGPL-3.01 mo ago
16

Audit local AI model, adapter, tokenizer, configuration, and packaging artifacts for provenance, integrity, dependency, serialization, license, and loading-risk evidence.

cyberful/cyberful135—~535Automated safety check: PassAGPL-3.01 mo ago
17

Test whether authorized direct or indirect untrusted content can alter an AI system's protected behavior, context use, memory, retrieval, output handling, or downstream capability.

cyberful/cyberful135—~538Automated safety check: PassAGPL-3.01 mo ago
18

Test deterministic authorization around AI tool discovery, selection, canonical arguments, credentials, tenants, destinations, approvals, delegation, retries, and effects.

cyberful/cyberful135—~549Automated safety check: PassAGPL-3.01 mo ago
19

Reconstruct how instructions, retrieved content, memory, identities, approvals, tool schemas, arguments, outputs, delegation, and fallbacks propagate through an AI system.

cyberful/cyberful135—~517Automated safety check: PassAGPL-3.01 mo ago
20

Extract bounded, deterministic evidence from crash and sanitizer logs, including signals, sanitizer classes, memory-safety indicators, stack-frame hashes, and source provenance, while reserving…

cyberful/cyberful135—~563Automated safety check: PassAGPL-3.01 mo ago
21

Normalize and compare authorized fraud-control observations from local evidence, highlighting decision drift, coverage gaps, and conflicting outcomes without making a fraud or vulnerability verdict.

cyberful/cyberful135—~649Automated safety check: PassAGPL-3.01 mo ago
22

Parse bounded classic PCAP files offline into deterministic capture metadata, packet-length and timestamp summaries, link and network protocol counts, truncation indicators, and source digests…

cyberful/cyberful135—~590Automated safety check: PassAGPL-3.01 mo ago
23

Model fraud and abuse threats across actors, account states, value flows, controls, and monetization paths.

cyberful/cyberful135—~716Automated safety check: PassAGPL-3.01 mo ago
24

Coordinate a PCI DSS penetration-testing and CDE-scoping readiness assessment across methodology, scope, segmentation, execution evidence, remediation, and retesting.

cyberful/cyberful135—~895Automated safety check: PassAGPL-3.01 mo ago
25

Assess the security of a smart-contract system across protocol economics, trust roles, upgrade and governance paths, oracle and bridge dependencies, deployment state, and off-chain operators.

cyberful/cyberful135—~651Automated safety check: PassAGPL-3.01 mo ago
26

Audit application database access layers for query construction, authorization placement, tenant scoping, transaction boundaries, consistency, credential authority, and observable durable effects.

cyberful/cyberful135—~599Automated safety check: PassAGPL-3.01 mo ago
27

Audit desktop client source, binaries, packaging, updater, local storage, IPC, protocol handlers, WebViews, plugins, native bridges, credential use, and OS integration for trust-boundary failures.

cyberful/cyberful135—~637Automated safety check: PassAGPL-3.01 mo ago
28

Audit extracted embedded firmware for boot and update trust, credential and secret handling, service exposure, privilege boundaries, parsers, persistence, cryptography, hardening, recovery, and…

cyberful/cyberful135—~644Automated safety check: PassAGPL-3.01 mo ago
29

Audit security logging and telemetry from event creation through transport, storage, access, correlation, retention, and response use.

cyberful/cyberful135—~597Automated safety check: PassAGPL-3.01 mo ago
30

Audit smart-contract source and build evidence for authorization, accounting, state-machine, external-call, upgrade, signature, oracle, token-integration, and denial-of-service defects.

cyberful/cyberful135—~650Automated safety check: PassAGPL-3.01 mo ago
31

Plan an authorized PCI DSS penetration test around the cardholder data environment, critical systems, internal and external coverage, segmentation, tester independence, remediation, retesting, and…

cyberful/cyberful135—~943Automated safety check: PassAGPL-3.01 mo ago
32

Test browser capability transfer across postMessage, opener, frame, portal, worker, service-worker, BroadcastChannel, MessagePort, and extension messaging boundaries.

cyberful/cyberful135—~583Automated safety check: PassAGPL-3.01 mo ago
33

Test whether every segmentation and scope-reduction control isolates the cardholder data environment from claimed out-of-scope systems and differing security levels.

cyberful/cyberful135—~928Automated safety check: PassAGPL-3.01 mo ago
34

Test application email generation, recipient authority, template and header construction, link and token binding, inbound parsing, threading, reply handling, bounce processing, and tenant isolation.

cyberful/cyberful135—~599Automated safety check: PassAGPL-3.01 mo ago
35

Test payment decision and value-movement invariants with authorized synthetic instruments and reversible sandbox transactions.

cyberful/cyberful135—~668Automated safety check: PassAGPL-3.01 mo ago
36

Test service accounts, OAuth clients, workload federation, token exchange, audience binding, delegated actors, credential rotation, and machine-identity authorization.

cyberful/cyberful135—~895Automated safety check: PassAGPL-3.01 mo ago
37

Trace uploaded, imported, generated, archived, converted, scanned, rendered, and downloaded files across storage, naming, extraction, parser, sandbox, and cleanup boundaries.

cyberful/cyberful135—~646Automated safety check: PassAGPL-3.01 mo ago
38

Reconstruct how principal, actor, issuer, audience, assurance, scopes, and delegated authority change across requests, tokens, services, queues, and stored artifacts.

cyberful/cyberful135—~730Automated safety check: PassAGPL-3.01 mo ago
39

Reconstruct how tenant and organization context is authenticated, selected, routed, cached, queued, and bound to resources across distributed request paths.

cyberful/cyberful135—~679Automated safety check: PassAGPL-3.01 mo ago
40

Reconstruct transaction state across services, ledgers, queues, and compensations from local artifacts, identifying causal gaps, duplicate effects, and value mismatches without active traffic.

cyberful/cyberful135—~635Automated safety check: PassAGPL-3.01 mo ago
41

Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
42

Route broad AI-agent security reviews to focused Cyberful skills across risk, model supply chain, context and capabilities, prompt injection, tool authorization, and RAG isolation.

cyberful/cyberful135—~723Automated safety check: PassAGPL-3.01 mo ago
43

Audit whether API handlers, gateways, serializers, validators, and generated clients implement the effective contract and its security invariants.

cyberful/cyberful135—~666Automated safety check: PassAGPL-3.01 mo ago
44

Coordinate a repository-wide white-box application security audit across architecture, source, configuration, dependencies, build, and deployment paths.

cyberful/cyberful135—~774Automated safety check: PassAGPL-3.01 mo ago
45

Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk.

cyberful/cyberful135—~829Automated safety check: PassAGPL-3.01 mo ago
46

Coordinate an authorized software-supply-chain audit from dependency resolution through build, artifact, release, deployment, and runtime trust.

cyberful/cyberful135—~737Automated safety check: PassAGPL-3.01 mo ago
47

Operate Cyberful as an authorized application-security control room.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.0-only1 mo ago
48

Operate Ghidra headless analysis, radare2, platform binary utilities, decompilers, and targeted dynamic evidence for advanced native and bytecode security review.

cyberful/cyberful135—~1.2kAutomated safety check: PassAGPL-3.01 mo ago