unboundcompute/security-agent-skills

194 agent markdown files indexed from unboundcompute/security-agent-skills. Install any of them pinned to an exact hash with mdr add unboundcompute/security-agent-skills/<name>.

adjudicating-dependency-cve-reachability skill
unboundcompute/security-agent-skills · skills/adjudicating-dependency-cve-reachability/SKILL.md · Decide whether a CVE in a dependency actually exposes your application before you scramble to patch: is the vulnerable…
git:20260816.c75b58d · audit A · 5 stars
adjudicating-taint-paths skill
unboundcompute/security-agent-skills · skills/adjudicating-taint-paths/SKILL.md · Decide whether a whitebox lead is a real bug by tracing taint from an untrusted source to a dangerous sink and…
git:20260816.faa9c07 · audit A · 5 stars
auditing-account-abstraction-and-paymaster-trust skill
unboundcompute/security-agent-skills · skills/auditing-account-abstraction-and-paymaster-trust/SKILL.md · Audit an ERC-4337 account-abstraction deployment for trust misplaced in the user-operation lifecycle: a smart account…
git:20260901.f8395d1 · audit A · 5 stars
auditing-account-recovery-and-reset-trust skill
unboundcompute/security-agent-skills · skills/auditing-account-recovery-and-reset-trust/SKILL.md · Audit password reset and account recovery flows for the trust that lets an attacker take over an account: a reset token…
git:20260829.b60f9b2 · audit A · 5 stars
auditing-admission-control-policy-gaps skill
unboundcompute/security-agent-skills · skills/auditing-admission-control-policy-gaps/SKILL.md · Audit cluster admission control for gaps that let a non-compliant or hostile workload through: a validating webhook…
git:20260828.ce55026 · audit A · 5 stars
auditing-ai-agent-permissions skill
unboundcompute/security-agent-skills · skills/auditing-ai-agent-permissions/SKILL.md · Audit what an AI agent is actually allowed to do versus what its task needs. Covers excessive agency (tools, scopes…
git:20260816.a6124f2 · audit A · 5 stars
auditing-android-component-exposure skill
unboundcompute/security-agent-skills · skills/auditing-android-component-exposure/SKILL.md · Audit an Android app for components another app on the device can reach and drive, after the manifest export flags and…
git:20260823.e797ed0 · audit A · 5 stars
auditing-android-intent-redirection-and-pendingintent skill
unboundcompute/security-agent-skills · skills/auditing-android-intent-redirection-and-pendingintent/SKILL.md · Audit Android privilege and access leaks through intent redirection and mutable pending intents, where a privileged…
git:20260908.e3ae18a · audit A · 5 stars
auditing-ansible-become-and-vault-trust skill
unboundcompute/security-agent-skills · skills/auditing-ansible-become-and-vault-trust/SKILL.md · Audit configuration-management privilege escalation and secret handling for trust that runs as root on every managed…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-api-key-and-token-lifecycle skill
unboundcompute/security-agent-skills · skills/auditing-api-key-and-token-lifecycle/SKILL.md · Audit the lifecycle of API keys and access tokens for weaknesses that let one keep working past its intended bounds: a…
git:20260903.19a7174 · audit A · 5 stars
auditing-ble-and-gatt-authorization skill
unboundcompute/security-agent-skills · skills/auditing-ble-and-gatt-authorization/SKILL.md · Audit a Bluetooth Low Energy device for missing authorization on its GATT attributes: a characteristic performing a…
git:20260901.f8395d1 · audit A · 5 stars
auditing-break-glass-account-trust skill
unboundcompute/security-agent-skills · skills/auditing-break-glass-account-trust/SKILL.md · Audit emergency break-glass and privileged-access accounts for the ways their standing power outlives the emergency…
git:20260903.19a7174 · audit A · 5 stars
auditing-browser-extension-trust skill
unboundcompute/security-agent-skills · skills/auditing-browser-extension-trust/SKILL.md · Audit a browser extension (Manifest V3) for a trust boundary another web page or extension can cross to reach a…
git:20260825.70f8609 · audit A · 5 stars
auditing-cicd-oidc-trust skill
unboundcompute/security-agent-skills · skills/auditing-cicd-oidc-trust/SKILL.md · Audit continuous-integration pipelines for the trust they extend to untrusted input: workflows that run on incoming…
git:20260816.a99bfa3 · audit A · 5 stars
auditing-clickjacking-and-ui-redressing skill
unboundcompute/security-agent-skills · skills/auditing-clickjacking-and-ui-redressing/SKILL.md · Audit a web application for UI-redressing attacks where an attacker frames the real site and tricks a user into acting…
git:20260901.f8395d1 · audit A · 5 stars
auditing-container-image-build-hardening skill
unboundcompute/security-agent-skills · skills/auditing-container-image-build-hardening/SKILL.md · Audit container image build definitions (Dockerfile, containerfile, and the compose or run config that sets runtime…
git:20260823.e797ed0 · audit A · 5 stars
auditing-container-image-provenance skill
unboundcompute/security-agent-skills · skills/auditing-container-image-provenance/SKILL.md · Audit how a cluster decides which container images to trust and run: an image referenced by a mutable tag rather than a…
git:20260828.ce55026 · audit A · 5 stars
auditing-container-runtime-and-socket-exposure skill
unboundcompute/security-agent-skills · skills/auditing-container-runtime-and-socket-exposure/SKILL.md · Audit whether a workload can reach the container runtime and thereby control the host: the container runtime socket…
git:20260828.ce55026 · audit A · 5 stars
auditing-cors-and-cross-origin-trust skill
unboundcompute/security-agent-skills · skills/auditing-cors-and-cross-origin-trust/SKILL.md · Audit the code and configuration that decide cross-origin access, for trust a browser turns into a read of…
git:20260821.57dfaf1 · audit A · 5 stars
auditing-cross-account-role-trust-boundaries skill
unboundcompute/security-agent-skills · skills/auditing-cross-account-role-trust-boundaries/SKILL.md · Audit cross-account IAM role assumption for trust policies that let the wrong principal assume a role: a trust policy…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-cross-chain-bridge-and-message-trust skill
unboundcompute/security-agent-skills · skills/auditing-cross-chain-bridge-and-message-trust/SKILL.md · Audit a cross-chain bridge or messaging protocol for misplaced trust in messages that cross chains: a destination…
git:20260901.f8395d1 · audit A · 5 stars
auditing-csrf-and-unsafe-state-changes skill
unboundcompute/security-agent-skills · skills/auditing-csrf-and-unsafe-state-changes/SKILL.md · Audit state-changing endpoints for cross-site request forgery, where a request that rides the victim's ambient cookies…
git:20260903.6dac719 · audit A · 5 stars
auditing-datastore-exposure-and-abuse skill
unboundcompute/security-agent-skills · skills/auditing-datastore-exposure-and-abuse/SKILL.md · Audit in-memory and cache datastores such as Redis and memcached for exposure and command abuse: an instance reachable…
git:20260826.c45369b · audit A · 5 stars
auditing-declarative-authorization skill
unboundcompute/security-agent-skills · skills/auditing-declarative-authorization/SKILL.md · Audit authorization expressed as configuration or framework convention rather than inline code: row-level security and…
git:20260816.e670f56 · audit A · 5 stars
auditing-declared-vs-used-permissions skill
unboundcompute/security-agent-skills · skills/auditing-declared-vs-used-permissions/SKILL.md · Find the consent gap in an agent skill or MCP server: the distance between the permissions and capabilities it declares…
git:20260818.ed96156 · audit A · 5 stars
auditing-device-code-and-pkce-flows skill
unboundcompute/security-agent-skills · skills/auditing-device-code-and-pkce-flows/SKILL.md · Audit the server side of the authorization-code-with-proof-key and device-authorization grants for bugs that let a…
git:20260821.57dfaf1 · audit A · 5 stars
auditing-directory-sync-trust skill
unboundcompute/security-agent-skills · skills/auditing-directory-sync-trust/SKILL.md · Audit bulk directory synchronization (LDAP, HR-system, IdP, or cross-directory feeds) between an external identity…
git:20260903.19a7174 · audit A · 5 stars
auditing-ecs-task-metadata-boundaries skill
unboundcompute/security-agent-skills · skills/auditing-ecs-task-metadata-boundaries/SKILL.md · Audit container task credential and metadata boundaries in orchestrated compute such as ECS: a workload that can reach…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-editor-extension-workspace-trust skill
unboundcompute/security-agent-skills · skills/auditing-editor-extension-workspace-trust/SKILL.md · Audit an editor or IDE extension for actions it runs on untrusted workspace contents, after the workspace-trust…
git:20260825.70f8609 · audit A · 5 stars
auditing-electron-ipc-trust skill
unboundcompute/security-agent-skills · skills/auditing-electron-ipc-trust/SKILL.md · Audit an Electron desktop app for untrusted renderer content that reaches a Node or operating-system capability, after…
git:20260825.70f8609 · audit A · 5 stars
auditing-error-handling-and-information-exposure skill
unboundcompute/security-agent-skills · skills/auditing-error-handling-and-information-exposure/SKILL.md · Audit error handling and diagnostic surfaces for sensitive information a real client receives, where an exception path…
git:20260903.6dac719 · audit A · 5 stars
auditing-file-upload-and-content-handling skill
unboundcompute/security-agent-skills · skills/auditing-file-upload-and-content-handling/SKILL.md · Audit a file-upload and content-handling path for an attacker-supplied file whose bytes, declared type, name, or…
git:20260825.70f8609 · audit A · 5 stars
auditing-graphql-attack-surface skill
unboundcompute/security-agent-skills · skills/auditing-graphql-attack-surface/SKILL.md · Audit the attack surface a GraphQL API exposes that a plain endpoint does not: schema introspection left open…
git:20260819.0218064 · audit A · 5 stars
auditing-group-policy-and-sysvol-trust skill
unboundcompute/security-agent-skills · skills/auditing-group-policy-and-sysvol-trust/SKILL.md · Audit trust placed in group policy content and the domain policy share, where a low-privileged principal can write a…
git:20260908.e3ae18a · audit A · 5 stars
auditing-grpc-service-authorization skill
unboundcompute/security-agent-skills · skills/auditing-grpc-service-authorization/SKILL.md · Audit a gRPC service for a method a caller can reach without the authorization the service assumes an interceptor…
git:20260825.70f8609 · audit A · 5 stars
auditing-guard-gaps skill
unboundcompute/security-agent-skills · skills/auditing-guard-gaps/SKILL.md · Find the missing-check bug by comparing sibling functions that reach the same sink - one validates its input, its peer…
git:20260816.faa9c07 · audit A · 5 stars
auditing-host-mount-and-device-exposure skill
unboundcompute/security-agent-skills · skills/auditing-host-mount-and-device-exposure/SKILL.md · Audit the host paths and devices a workload mounts for reach across the container boundary onto the node: a writable…
git:20260828.ce55026 · audit A · 5 stars
auditing-http2-and-grpc-multiplexing-trust skill
unboundcompute/security-agent-skills · skills/auditing-http2-and-grpc-multiplexing-trust/SKILL.md · Audit HTTP/2 and gRPC edges for framing and multiplexing trust that breaks when a stream is translated or reused: an…
git:20260829.b60f9b2 · audit A · 5 stars
auditing-iac-module-and-provider-supply-chain skill
unboundcompute/security-agent-skills · skills/auditing-iac-module-and-provider-supply-chain/SKILL.md · Audit the supply chain of infrastructure-as-code modules and providers for trust that runs at plan or apply time: a…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-idp-initiated-flow-trust skill
unboundcompute/security-agent-skills · skills/auditing-idp-initiated-flow-trust/SKILL.md · Audit identity-provider-initiated single sign-on for trust placed in an unsolicited assertion the application never…
git:20260903.19a7174 · audit A · 5 stars
auditing-infrastructure-as-code-exposures skill
unboundcompute/security-agent-skills · skills/auditing-infrastructure-as-code-exposures/SKILL.md · Audit existing infrastructure-as-code definitions (Terraform, OpenTofu, CloudFormation, Bicep, Pulumi) for resource…
git:20260823.e797ed0 · audit A · 5 stars
auditing-init-and-sidecar-injection-trust skill
unboundcompute/security-agent-skills · skills/auditing-init-and-sidecar-injection-trust/SKILL.md · Audit the init and sidecar containers a workload runs, including ones injected by a mutating admission webhook, for…
git:20260828.ce55026 · audit A · 5 stars
auditing-ios-app-group-and-pasteboard-exposure skill
unboundcompute/security-agent-skills · skills/auditing-ios-app-group-and-pasteboard-exposure/SKILL.md · Audit sensitive data leaving an iOS app's protection through shared containers and system-wide channels, where a secret…
git:20260908.e3ae18a · audit A · 5 stars
auditing-jit-provisioning-and-role-mapping skill
unboundcompute/security-agent-skills · skills/auditing-jit-provisioning-and-role-mapping/SKILL.md · Audit just-in-time account provisioning at federated (SAML or OIDC) login for trust misplaced in the assertion that…
git:20260903.19a7174 · audit A · 5 stars
auditing-jwt-verification-and-key-trust skill
unboundcompute/security-agent-skills · skills/auditing-jwt-verification-and-key-trust/SKILL.md · Audit how a service verifies JSON Web Tokens for the classic verification bypasses: an algorithm-confusion attack where…
git:20260829.b60f9b2 · audit A · 5 stars
auditing-jwt-verification-trust skill
unboundcompute/security-agent-skills · skills/auditing-jwt-verification-trust/SKILL.md · Audit code that verifies a JSON Web Token for a signature or claims check that trusts token-supplied parameters, so an…
git:20260825.70f8609 · audit A · 5 stars
auditing-kms-key-policy-and-envelope-encryption skill
unboundcompute/security-agent-skills · skills/auditing-kms-key-policy-and-envelope-encryption/SKILL.md · Audit key-management policies and envelope-encryption design for a decrypt path broader than intended: a key policy or…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-kubernetes-workload-and-rbac-hardening skill
unboundcompute/security-agent-skills · skills/auditing-kubernetes-workload-and-rbac-hardening/SKILL.md · Audit Kubernetes manifests for a subject granted more than it needs or a workload that can escape its container, after…
git:20260823.e797ed0 · audit A · 5 stars
auditing-machine-identity-issuance skill
unboundcompute/security-agent-skills · skills/auditing-machine-identity-issuance/SKILL.md · Audit how a platform issues machine and workload identities (certificate authorities, workload-identity federation…
git:20260903.19a7174 · audit A · 5 stars
auditing-mcp-tool-integrations skill
unboundcompute/security-agent-skills · skills/auditing-mcp-tool-integrations/SKILL.md · Red-team the tool layer of an AI agent: the tool definitions, metadata, and outputs that a model reads and trusts…
git:20260816.4aab195 · audit A · 5 stars
auditing-message-broker-topic-authorization skill
unboundcompute/security-agent-skills · skills/auditing-message-broker-topic-authorization/SKILL.md · Audit message-broker topic and queue authorization for reach a client should not have: a wildcard subscription that…
git:20260829.b60f9b2 · audit A · 5 stars
auditing-mfa-enrollment-and-reset-abuse skill
unboundcompute/security-agent-skills · skills/auditing-mfa-enrollment-and-reset-abuse/SKILL.md · Audit multi-factor authentication enrollment, reset, and recovery for paths that let an attacker add their own factor…
git:20260903.19a7174 · audit A · 5 stars
auditing-ml-inference-endpoint-abuse skill
unboundcompute/security-agent-skills · skills/auditing-ml-inference-endpoint-abuse/SKILL.md · Audit a hosted model inference endpoint for abuse that costs money or steals the asset: an unauthenticated or weakly…
git:20260901.f8395d1 · audit A · 5 stars
auditing-ml-model-supply-chain skill
unboundcompute/security-agent-skills · skills/auditing-ml-model-supply-chain/SKILL.md · Audit the machine-learning models you load as untrusted code, not just data. Covers deserialization RCE from unsafe…
git:20260816.a0bc1d1 · audit A · 5 stars
auditing-mobile-backend-and-firebase-exposure skill
unboundcompute/security-agent-skills · skills/auditing-mobile-backend-and-firebase-exposure/SKILL.md · Audit the backend a mobile app talks to for authorization that lives only in the client, where a mobile-backend…
git:20260908.e3ae18a · audit A · 5 stars
auditing-mobile-biometric-and-local-auth-bypass skill
unboundcompute/security-agent-skills · skills/auditing-mobile-biometric-and-local-auth-bypass/SKILL.md · Audit local authentication on a mobile app, where a biometric or device-passcode gate protects sensitive access but can…
git:20260908.e3ae18a · audit A · 5 stars
auditing-mobile-deeplink-trust skill
unboundcompute/security-agent-skills · skills/auditing-mobile-deeplink-trust/SKILL.md · Audit how a mobile app handles a deep link, app link, or custom-scheme URL, so an attacker-supplied URL cannot drive a…
git:20260823.e797ed0 · audit A · 5 stars
auditing-mobile-root-jailbreak-and-tamper-resistance skill
unboundcompute/security-agent-skills · skills/auditing-mobile-root-jailbreak-and-tamper-resistance/SKILL.md · Audit whether a mobile app's integrity and environment checks actually enforce a security decision, where the app runs…
git:20260908.e3ae18a · audit A · 5 stars
auditing-mobile-webview-bridge-exposure skill
unboundcompute/security-agent-skills · skills/auditing-mobile-webview-bridge-exposure/SKILL.md · Audit the trust a mobile app places in web content loaded in an embedded WebView, where a native bridge exposes app…
git:20260908.e3ae18a · audit A · 5 stars
auditing-move-resource-ownership skill
unboundcompute/security-agent-skills · skills/auditing-move-resource-ownership/SKILL.md · Audit a Move smart contract (Aptos or Sui) for a public entry function or a passed object or resource that acts without…
git:20260825.70f8609 · audit A · 5 stars
auditing-multi-tenant-isolation skill
unboundcompute/security-agent-skills · skills/auditing-multi-tenant-isolation/SKILL.md · Audit whether every data operation is scoped to the caller's tenant, so a request in one tenant cannot read or write…
git:20260821.57dfaf1 · audit A · 5 stars
auditing-namespace-as-tenant-boundary skill
unboundcompute/security-agent-skills · skills/auditing-namespace-as-tenant-boundary/SKILL.md · Audit a Kubernetes namespace that is treated as a tenant isolation boundary for the isolation it does not actually…
git:20260828.ce55026 · audit A · 5 stars
auditing-network-policy-segmentation-gaps skill
unboundcompute/security-agent-skills · skills/auditing-network-policy-segmentation-gaps/SKILL.md · Audit cluster network segmentation for the reachability a workload should not have: a namespace with no default-deny so…
git:20260828.ce55026 · audit A · 5 stars
auditing-oauth-token-audience-and-scope-trust skill
unboundcompute/security-agent-skills · skills/auditing-oauth-token-audience-and-scope-trust/SKILL.md · Audit how a resource server trusts OAuth access tokens for confusion it should reject: a token minted for one audience…
git:20260829.b60f9b2 · audit A · 5 stars
auditing-observability-pipeline-collector-trust skill
unboundcompute/security-agent-skills · skills/auditing-observability-pipeline-collector-trust/SKILL.md · Audit telemetry collectors and observability pipelines for trust they should not extend: a collector endpoint that…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-open-redirect-and-forced-navigation skill
unboundcompute/security-agent-skills · skills/auditing-open-redirect-and-forced-navigation/SKILL.md · Audit redirect and navigation flows where an untrusted return, next, or callback URL, a stored value, or a referer…
git:20260903.6dac719 · audit A · 5 stars
auditing-ota-and-firmware-update-channel-trust skill
unboundcompute/security-agent-skills · skills/auditing-ota-and-firmware-update-channel-trust/SKILL.md · Audit an over-the-air or firmware update channel for a device that accepts an image it should reject: an update whose…
git:20260901.f8395d1 · audit A · 5 stars
auditing-payment-callback-and-amount-integrity skill
unboundcompute/security-agent-skills · skills/auditing-payment-callback-and-amount-integrity/SKILL.md · Audit payment provider callbacks and settlement notifications for the trust that lets an attacker forge or alter a…
git:20260829.b60f9b2 · audit A · 5 stars
auditing-payment-state-machine-and-idempotency skill
unboundcompute/security-agent-skills · skills/auditing-payment-state-machine-and-idempotency/SKILL.md · Audit payment and checkout state machines for transitions an attacker can drive out of order or replay for value: an…
git:20260829.b60f9b2 · audit A · 5 stars
auditing-presigned-url-scope-abuse skill
unboundcompute/security-agent-skills · skills/auditing-presigned-url-scope-abuse/SKILL.md · Audit presigned object-storage URLs for scope that grants more than the request intended: a signature that covers a…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-randomness-and-nonce-quality skill
unboundcompute/security-agent-skills · skills/auditing-randomness-and-nonce-quality/SKILL.md · Audit security-sensitive values for weak randomness: a non-cryptographic generator, a predictable or constant seed, a…
git:20260821.57dfaf1 · audit A · 5 stars
auditing-s3-object-ownership-trust skill
unboundcompute/security-agent-skills · skills/auditing-s3-object-ownership-trust/SKILL.md · Audit object-storage ownership and per-object access for trust the bucket policy does not cover: an object uploaded by…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-saml-and-oidc-federation-trust skill
unboundcompute/security-agent-skills · skills/auditing-saml-and-oidc-federation-trust/SKILL.md · Audit federated single sign-on for assertions a relying party should not trust: a SAML response whose signature is not…
git:20260829.b60f9b2 · audit A · 5 stars
auditing-saml-and-oidc-flows skill
unboundcompute/security-agent-skills · skills/auditing-saml-and-oidc-flows/SKILL.md · Audit federated single sign-on for the flaws that let an attacker forge or replay an identity: signature wrapping and…
git:20260816.e670f56 · audit A · 5 stars
auditing-scim-provisioning-trust skill
unboundcompute/security-agent-skills · skills/auditing-scim-provisioning-trust/SKILL.md · Audit a SCIM 2.0 provisioning endpoint for trust misplaced in the identity provider that drives it: a provisioning API…
git:20260903.19a7174 · audit A · 5 stars
auditing-secure-boot-and-firmware-signing skill
unboundcompute/security-agent-skills · skills/auditing-secure-boot-and-firmware-signing/SKILL.md · Audit updater and bootloader code for a firmware trust boundary that lets an unsigned or downgraded image be flashed or…
git:20260821.57dfaf1 · audit A · 5 stars
auditing-security-logging-completeness skill
unboundcompute/security-agent-skills · skills/auditing-security-logging-completeness/SKILL.md · Audit whether an application actually records the security events an investigation would need, and whether the logs…
git:20260821.4f2a732 · audit A · 5 stars
auditing-serverless-event-source-trust skill
unboundcompute/security-agent-skills · skills/auditing-serverless-event-source-trust/SKILL.md · Audit event-driven function handlers that trust the event because it arrived from inside the platform: a handler that…
git:20260821.4f2a732 · audit A · 5 stars
auditing-service-account-key-lifecycle skill
unboundcompute/security-agent-skills · skills/auditing-service-account-key-lifecycle/SKILL.md · Audit cloud and platform service-account keys for lifecycle weaknesses that turn a non-human credential into standing…
git:20260903.19a7174 · audit A · 5 stars
auditing-service-mesh-mtls-and-authz-trust skill
unboundcompute/security-agent-skills · skills/auditing-service-mesh-mtls-and-authz-trust/SKILL.md · Audit a service mesh for the trust it claims but does not enforce: a mesh in permissive mode that accepts plaintext…
git:20260828.ce55026 · audit A · 5 stars
auditing-session-lifecycle-and-fixation skill
unboundcompute/security-agent-skills · skills/auditing-session-lifecycle-and-fixation/SKILL.md · Audit how an application issues, rotates, and destroys session identifiers, so an attacker cannot fixate or outlive a…
git:20260823.e797ed0 · audit A · 5 stars
auditing-skill-and-mcp-instructions skill
unboundcompute/security-agent-skills · skills/auditing-skill-and-mcp-instructions/SKILL.md · Lint the natural-language instruction text of an agent skill or MCP server, not its code: the skill body, the…
git:20260818.ed96156 · audit B · 5 stars
auditing-smart-contract-access-control skill
unboundcompute/security-agent-skills · skills/auditing-smart-contract-access-control/SKILL.md · Audit a smart contract for a privileged action any caller can reach, so an attacker invokes a function that should be…
git:20260823.e797ed0 · audit A · 5 stars
auditing-ssh-trust-and-agent-forwarding skill
unboundcompute/security-agent-skills · skills/auditing-ssh-trust-and-agent-forwarding/SKILL.md · Audit secure-shell trust hygiene, not cipher hardening: a forwarded authentication agent a remote host can abuse to log…
git:20260819.61df029 · audit A · 5 stars
auditing-sso-logout-and-session-revocation skill
unboundcompute/security-agent-skills · skills/auditing-sso-logout-and-session-revocation/SKILL.md · Audit single sign-on logout and session revocation for sessions that outlive the event meant to end them: a logout that…
git:20260903.19a7174 · audit A · 5 stars
auditing-system-prompt-and-context-leakage skill
unboundcompute/security-agent-skills · skills/auditing-system-prompt-and-context-leakage/SKILL.md · Audit an AI application for confidential material bleeding out of the model context: a system prompt that carries…
git:20260901.f8395d1 · audit A · 5 stars
auditing-terraform-state-and-backend-trust skill
unboundcompute/security-agent-skills · skills/auditing-terraform-state-and-backend-trust/SKILL.md · Audit infrastructure-state storage and its backend for exposure and tampering: a state file holding plaintext secrets…
git:20260827.b5f41a4 · audit A · 5 stars
auditing-the-lethal-trifecta skill
unboundcompute/security-agent-skills · skills/auditing-the-lethal-trifecta/SKILL.md · Find where an AI agent becomes dangerous: the trust context in which access to private data, exposure to untrusted…
git:20260816.4aab195 · audit A · 5 stars
auditing-third-party-script-and-sri-trust skill
unboundcompute/security-agent-skills · skills/auditing-third-party-script-and-sri-trust/SKILL.md · Audit a web application for trust placed in third-party scripts it loads into its own page: an external script tag with…
git:20260901.f8395d1 · audit B · 5 stars
auditing-tls-and-certificate-validation skill
unboundcompute/security-agent-skills · skills/auditing-tls-and-certificate-validation/SKILL.md · Audit client code for transport security that is disabled or defeated, so an attacker on the network path can intercept…
git:20260823.e797ed0 · audit A · 5 stars
auditing-webauthn-and-passkey-flows skill
unboundcompute/security-agent-skills · skills/auditing-webauthn-and-passkey-flows/SKILL.md · Audit the server side of passwordless authentication for ceremony-verification bugs that let an attacker-shaped…
git:20260821.57dfaf1 · audit A · 5 stars
auditing-webhook-authenticity-and-callback-trust skill
unboundcompute/security-agent-skills · skills/auditing-webhook-authenticity-and-callback-trust/SKILL.md · Audit both directions of webhook trust: an inbound handler that acts on a payload without proving it authentic, and an…
git:20260821.57dfaf1 · audit A · 5 stars
auditing-websocket-connection-trust skill
unboundcompute/security-agent-skills · skills/auditing-websocket-connection-trust/SKILL.md · Audit a WebSocket endpoint for trust established once at the handshake and never re-checked, so a cross-site page or a…
git:20260825.70f8609 · audit A · 5 stars
auditing-windows-named-pipe-and-rpc-exposure skill
unboundcompute/security-agent-skills · skills/auditing-windows-named-pipe-and-rpc-exposure/SKILL.md · Audit local privilege escalation through Windows inter-process interfaces, where a privileged service exposes a named…
git:20260908.e3ae18a · audit A · 5 stars
auditing-windows-token-and-privilege-abuse skill
unboundcompute/security-agent-skills · skills/auditing-windows-token-and-privilege-abuse/SKILL.md · Audit privilege escalation through Windows access token and privilege abuse, where a process holds a sensitive…
git:20260908.e3ae18a · audit A · 5 stars
auditing-windows-uac-and-integrity-boundaries skill
unboundcompute/security-agent-skills · skills/auditing-windows-uac-and-integrity-boundaries/SKILL.md · Audit elevation and integrity boundaries on Windows, where a medium-integrity process reaches a high- integrity context…
git:20260908.e3ae18a · audit A · 5 stars
auditing-workload-secret-exposure-surface skill
unboundcompute/security-agent-skills · skills/auditing-workload-secret-exposure-surface/SKILL.md · Audit how a workload holds its secrets for the exposure that outlives the secret's intent: a secret passed as an…
git:20260828.ce55026 · audit A · 5 stars
detecting-memory-safety-bugs skill
unboundcompute/security-agent-skills · skills/detecting-memory-safety-bugs/SKILL.md · Find memory-safety bugs in C/C++ and other unmanaged code - use-after-free, double-free, out-of-bounds read/write…
git:20260816.faa9c07 · audit A · 5 stars
detecting-race-conditions skill
unboundcompute/security-agent-skills · skills/detecting-race-conditions/SKILL.md · Find concurrency and time-of-check/time-of-use bugs - TOCTOU, unsynchronized shared state, check-then-act, and…
git:20260816.faa9c07 · audit A · 5 stars
enumerating-snmp-exposure skill
unboundcompute/security-agent-skills · skills/enumerating-snmp-exposure/SKILL.md · Enumerate network-management exposure through the simple network-management protocol: default and guessable community…
git:20260819.61df029 · audit A · 5 stars
evaluating-model-guardrails skill
unboundcompute/security-agent-skills · skills/evaluating-model-guardrails/SKILL.md · Systematically test whether a model's safety and policy guardrails hold under adversarial pressure, as a repeatable…
git:20260816.a0bc1d1 · audit A · 5 stars
exploiting-ssrf-to-cloud-metadata skill
unboundcompute/security-agent-skills · skills/exploiting-ssrf-to-cloud-metadata/SKILL.md · Adjudicate whether a server-side request-forgery primitive actually reaches high-value internal targets, especially a…
git:20260816.e670f56 · audit A · 5 stars
extracting-nday-from-a-patch skill
unboundcompute/security-agent-skills · skills/extracting-nday-from-a-patch/SKILL.md · Turn a security patch or version diff into fresh findings: infer the fixed vulnerability from what the fix changed…
git:20260816.c75b58d · audit A · 5 stars
finding-crypto-misuse skill
unboundcompute/security-agent-skills · skills/finding-crypto-misuse/SKILL.md · Find exploitable cryptographic misuse, not theoretical weakness: reused nonces (stream and counter/GCM keystream reuse…
git:20260816.e670f56 · audit A · 5 stars
finding-fail-open-flaws skill
unboundcompute/security-agent-skills · skills/finding-fail-open-flaws/SKILL.md · Find security controls that grant access when they should deny it: an authorization check that returns allow on error…
git:20260816.e670f56 · audit A · 5 stars
hunting-active-directory-acl-abuse-paths skill
unboundcompute/security-agent-skills · skills/hunting-active-directory-acl-abuse-paths/SKILL.md · Hunt privilege escalation through Active Directory object permission abuse, where a low-privileged principal holds a…
git:20260908.e3ae18a · audit A · 5 stars
hunting-adcs-certificate-template-abuse skill
unboundcompute/security-agent-skills · skills/hunting-adcs-certificate-template-abuse/SKILL.md · Hunt privilege escalation through Active Directory Certificate Services template and enrollment misconfiguration, where…
git:20260908.e3ae18a · audit A · 5 stars
hunting-blind-and-second-order-sql-injection skill
unboundcompute/security-agent-skills · skills/hunting-blind-and-second-order-sql-injection/SKILL.md · Hunt the SQL injection that first-order testing misses: blind injection where the response carries no error or data and…
git:20260826.c45369b · audit A · 5 stars
hunting-broken-object-level-authorization skill
unboundcompute/security-agent-skills · skills/hunting-broken-object-level-authorization/SKILL.md · Hunt broken object-level authorization (BOLA, also called IDOR): endpoints that accept a client-supplied object…
git:20260819.0218064 · audit A · 5 stars
hunting-bug-variants skill
unboundcompute/security-agent-skills · skills/hunting-bug-variants/SKILL.md · Given one confirmed vulnerability, systematically find its siblings: the same defect shape repeated elsewhere in the…
git:20260816.c75b58d · audit A · 5 stars
hunting-bugs-with-a-code-graph skill
unboundcompute/security-agent-skills · skills/hunting-bugs-with-a-code-graph/SKILL.md · Hunt security bugs across a whole codebase by reasoning over its structure (call graph and dataflow) instead of…
git:20260816.faa9c07 · audit A · 5 stars
hunting-business-logic-flaws skill
unboundcompute/security-agent-skills · skills/hunting-business-logic-flaws/SKILL.md · Hunt for vulnerabilities that live in what an application is allowed to do, not in how it is coded: workflow steps that…
git:20260816.a6124f2 · audit A · 5 stars
hunting-cicd-workflow-injection skill
unboundcompute/security-agent-skills · skills/hunting-cicd-workflow-injection/SKILL.md · Hunt a CI/CD pipeline for attacker-controlled repository data that reaches a privileged execution context, after the…
git:20260825.70f8609 · audit A · 5 stars
hunting-code-interpreter-and-tool-sandbox-escape skill
unboundcompute/security-agent-skills · skills/hunting-code-interpreter-and-tool-sandbox-escape/SKILL.md · Hunt for ways attacker-influenced code or a tool call escapes the sandbox an AI application runs it in: a…
git:20260901.f8395d1 · audit A · 5 stars
hunting-command-argument-and-flag-injection skill
unboundcompute/security-agent-skills · skills/hunting-command-argument-and-flag-injection/SKILL.md · Hunt argument and flag injection where untrusted input occupies a slot in a subprocess argument vector, with no shell…
git:20260903.6dac719 · audit A · 5 stars
hunting-connection-string-and-jdbc-url-injection skill
unboundcompute/security-agent-skills · skills/hunting-connection-string-and-jdbc-url-injection/SKILL.md · Hunt injection into database connection strings and JDBC or driver URLs where untrusted input sets the host, a driver…
git:20260826.c45369b · audit A · 5 stars
hunting-container-escape-surface skill
unboundcompute/security-agent-skills · skills/hunting-container-escape-surface/SKILL.md · Hunt for the configuration that lets a workload break out of its container onto the node: a pod that runs privileged or…
git:20260828.ce55026 · audit A · 5 stars
hunting-content-type-and-parser-confusion skill
unboundcompute/security-agent-skills · skills/hunting-content-type-and-parser-confusion/SKILL.md · Hunt content-type sniffing and parser confusion where untrusted content is served or consumed with an ambiguous or…
git:20260903.6dac719 · audit A · 5 stars
hunting-crlf-and-response-splitting skill
unboundcompute/security-agent-skills · skills/hunting-crlf-and-response-splitting/SKILL.md · Hunt CRLF injection where untrusted input carrying a carriage return and line feed reaches a response header, a log…
git:20260903.6dac719 · audit A · 5 stars
hunting-defi-economic-and-oracle-flaws skill
unboundcompute/security-agent-skills · skills/hunting-defi-economic-and-oracle-flaws/SKILL.md · Hunt a decentralized-finance protocol for a way to profit by moving a price or breaking an economic invariant, rather…
git:20260823.e797ed0 · audit A · 5 stars
hunting-dns-rebinding-and-ssrf-pivots skill
unboundcompute/security-agent-skills · skills/hunting-dns-rebinding-and-ssrf-pivots/SKILL.md · Hunt server-side request forgery and DNS rebinding that turn a server into a proxy for the internal network: a URL or…
git:20260829.b60f9b2 · audit A · 5 stars
hunting-dotnet-deserialization-type-injection skill
unboundcompute/security-agent-skills · skills/hunting-dotnet-deserialization-type-injection/SKILL.md · Hunt .NET deserialization where untrusted input reaches a formatter that resolves the type from the data itself…
git:20260826.c45369b · audit A · 5 stars
hunting-dynamic-linker-hijacks skill
unboundcompute/security-agent-skills · skills/hunting-dynamic-linker-hijacks/SKILL.md · Hunt local privilege escalation and code execution through the dynamic loader: a preload environment variable honored…
git:20260819.61df029 · audit A · 5 stars
hunting-expression-language-injection skill
unboundcompute/security-agent-skills · skills/hunting-expression-language-injection/SKILL.md · Hunt expression-language injection where untrusted input reaches a server-side expression evaluator: Spring Expression…
git:20260826.c45369b · audit A · 5 stars
hunting-firmware-secrets-and-debug-interfaces skill
unboundcompute/security-agent-skills · skills/hunting-firmware-secrets-and-debug-interfaces/SKILL.md · Hunt the attack surface a firmware image ships by mistake: a secret baked into the binary, a debug or diagnostic…
git:20260821.57dfaf1 · audit A · 5 stars
hunting-formula-injection-in-exports skill
unboundcompute/security-agent-skills · skills/hunting-formula-injection-in-exports/SKILL.md · Hunt formula injection, also called CSV injection, where an untrusted field stored by the application is later written…
git:20260903.6dac719 · audit A · 5 stars
hunting-helm-template-and-values-injection skill
unboundcompute/security-agent-skills · skills/hunting-helm-template-and-values-injection/SKILL.md · Hunt injection through Kubernetes packaging templates and their values: an untrusted value rendered into a manifest…
git:20260827.b5f41a4 · audit A · 5 stars
hunting-host-header-and-url-parsing-trust skill
unboundcompute/security-agent-skills · skills/hunting-host-header-and-url-parsing-trust/SKILL.md · Hunt trust placed in the Host or a forwarded host header and in inconsistently parsed URLs, where the app builds…
git:20260903.6dac719 · audit A · 5 stars
hunting-http-parameter-pollution skill
unboundcompute/security-agent-skills · skills/hunting-http-parameter-pollution/SKILL.md · Hunt HTTP parameter pollution, where the same parameter name appears more than once, or a parameter is shaped as an…
git:20260903.6dac719 · audit A · 5 stars
hunting-http-request-smuggling-and-desync skill
unboundcompute/security-agent-skills · skills/hunting-http-request-smuggling-and-desync/SKILL.md · Hunt for request smuggling where two HTTP processors on the same path disagree about where one request ends and the…
git:20260829.b60f9b2 · audit A · 5 stars
hunting-hybrid-app-bundle-and-config-exposure skill
unboundcompute/security-agent-skills · skills/hunting-hybrid-app-bundle-and-config-exposure/SKILL.md · Hunt secrets and abusable configuration shipped inside a mobile app bundle, where the installable package carries…
git:20260908.e3ae18a · audit A · 5 stars
hunting-iam-privilege-escalation-paths skill
unboundcompute/security-agent-skills · skills/hunting-iam-privilege-escalation-paths/SKILL.md · Hunt privilege-escalation paths in cloud identity and access management: a low-privileged principal that chains role…
git:20260816.a99bfa3 · audit A · 5 stars
hunting-ios-keychain-and-data-protection-gaps skill
unboundcompute/security-agent-skills · skills/hunting-ios-keychain-and-data-protection-gaps/SKILL.md · Hunt at-rest exposure of secrets on iOS, where a credential, token, or sensitive value is stored with a keychain…
git:20260908.e3ae18a · audit B · 5 stars
hunting-java-deserialization-gadget-chains skill
unboundcompute/security-agent-skills · skills/hunting-java-deserialization-gadget-chains/SKILL.md · Hunt Java deserialization that turns an untrusted byte stream into code execution: attacker-controlled data reaching…
git:20260826.c45369b · audit A · 5 stars
hunting-kerberos-and-ad-delegation-abuse skill
unboundcompute/security-agent-skills · skills/hunting-kerberos-and-ad-delegation-abuse/SKILL.md · Hunt for Active Directory Kerberos delegation configurations that let one identity act as another: a service account…
git:20260903.19a7174 · audit A · 5 stars
hunting-kubelet-and-node-api-exposure skill
unboundcompute/security-agent-skills · skills/hunting-kubelet-and-node-api-exposure/SKILL.md · Hunt for node-level Kubernetes endpoints that are reachable and under-authenticated: a kubelet API that allows…
git:20260828.ce55026 · audit A · 5 stars
hunting-ldap-injection-and-bind-trust skill
unboundcompute/security-agent-skills · skills/hunting-ldap-injection-and-bind-trust/SKILL.md · Hunt LDAP injection and bind-trust flaws where untrusted input reaches a directory query or an authentication bind: a…
git:20260826.c45369b · audit A · 5 stars
hunting-mass-assignment-and-property-authz skill
unboundcompute/security-agent-skills · skills/hunting-mass-assignment-and-property-authz/SKILL.md · Hunt mass assignment and broken object-property authorization: handlers that bind a client request payload straight…
git:20260819.0218064 · audit A · 5 stars
hunting-mev-and-transaction-ordering-exposure skill
unboundcompute/security-agent-skills · skills/hunting-mev-and-transaction-ordering-exposure/SKILL.md · Hunt for value a validator or searcher can extract by controlling the order of transactions in a block: a swap or trade…
git:20260901.f8395d1 · audit A · 5 stars
hunting-mobile-secret-and-storage-exposure skill
unboundcompute/security-agent-skills · skills/hunting-mobile-secret-and-storage-exposure/SKILL.md · Hunt a mobile app for a real credential shipped in the binary or written to storage another party can read, scoped…
git:20260823.e797ed0 · audit A · 5 stars
hunting-mobile-tapjacking-and-overlay-abuse skill
unboundcompute/security-agent-skills · skills/hunting-mobile-tapjacking-and-overlay-abuse/SKILL.md · Hunt mobile interface redressing, where another app draws over or intercepts a sensitive screen so the user acts on the…
git:20260908.e3ae18a · audit A · 5 stars
hunting-mobile-tls-pinning-and-trust-gaps skill
unboundcompute/security-agent-skills · skills/hunting-mobile-tls-pinning-and-trust-gaps/SKILL.md · Hunt transport trust gaps in a mobile app, where the app accepts a network position it should reject, because it trusts…
git:20260908.e3ae18a · audit A · 5 stars
hunting-mutual-tls-and-service-identity-gaps skill
unboundcompute/security-agent-skills · skills/hunting-mutual-tls-and-service-identity-gaps/SKILL.md · Hunt for gaps in how a service establishes and verifies the identity of the peer calling it: a mutual-TLS endpoint that…
git:20260829.b60f9b2 · audit A · 5 stars
hunting-non-human-identity-and-secret-reachability skill
unboundcompute/security-agent-skills · skills/hunting-non-human-identity-and-secret-reachability/SKILL.md · Hunt machine credentials that are live, over-privileged, and actually reachable, not just present. Covers non-human…
git:20260816.a99bfa3 · audit A · 5 stars
hunting-nosql-operator-and-where-injection skill
unboundcompute/security-agent-skills · skills/hunting-nosql-operator-and-where-injection/SKILL.md · Hunt NoSQL injection where untrusted input becomes query structure rather than a bound value: a request body whose keys…
git:20260826.c45369b · audit A · 5 stars
hunting-ntlm-coercion-and-relay skill
unboundcompute/security-agent-skills · skills/hunting-ntlm-coercion-and-relay/SKILL.md · Hunt authentication coercion and relay on a Windows network, where an attacker induces a privileged machine or account…
git:20260908.e3ae18a · audit A · 5 stars
hunting-orm-and-query-builder-injection skill
unboundcompute/security-agent-skills · skills/hunting-orm-and-query-builder-injection/SKILL.md · Hunt injection that survives an object-relational mapper or query builder: untrusted input reaching a raw-query escape…
git:20260821.4f2a732 · audit A · 5 stars
hunting-os-command-injection skill
unboundcompute/security-agent-skills · skills/hunting-os-command-injection/SKILL.md · Hunt OS command injection where untrusted input reaches a process-spawning API through a shell that interprets…
git:20260903.6dac719 · audit A · 5 stars
hunting-path-traversal-and-file-access skill
unboundcompute/security-agent-skills · skills/hunting-path-traversal-and-file-access/SKILL.md · Hunt path traversal and unsafe file access where untrusted input builds a filesystem path and the resolved path escapes…
git:20260903.6dac719 · audit A · 5 stars
hunting-php-object-injection-pop-chains skill
unboundcompute/security-agent-skills · skills/hunting-php-object-injection-pop-chains/SKILL.md · Hunt PHP object injection where untrusted input reaches unserialize or a framework unserializer and a reachable class…
git:20260826.c45369b · audit A · 5 stars
hunting-price-and-coupon-manipulation skill
unboundcompute/security-agent-skills · skills/hunting-price-and-coupon-manipulation/SKILL.md · Hunt for ways a buyer can control the price the server charges: a price, quantity, or line total taken from the client…
git:20260829.b60f9b2 · audit A · 5 stars
hunting-python-unsafe-deserialization skill
unboundcompute/security-agent-skills · skills/hunting-python-unsafe-deserialization/SKILL.md · Hunt Python deserialization that executes attacker code: untrusted input reaching pickle.loads, an unsafe YAML load…
git:20260826.c45369b · audit A · 5 stars
hunting-redos-and-complexity-dos skill
unboundcompute/security-agent-skills · skills/hunting-redos-and-complexity-dos/SKILL.md · Hunt single-request denial of service from super-linear work: untrusted input reaching a backtracking regular…
git:20260821.4f2a732 · audit A · 5 stars
hunting-reflected-and-stored-xss skill
unboundcompute/security-agent-skills · skills/hunting-reflected-and-stored-xss/SKILL.md · Hunt reflected and stored cross-site scripting in server-rendered responses, where untrusted request or stored data is…
git:20260903.6dac719 · audit A · 5 stars
hunting-scheduled-job-and-search-path-hijacks skill
unboundcompute/security-agent-skills · skills/hunting-scheduled-job-and-search-path-hijacks/SKILL.md · Hunt local privilege escalation through scheduled jobs and the paths privileged processes trust: periodic and timer…
git:20260819.61df029 · audit A · 5 stars
hunting-search-engine-injection skill
unboundcompute/security-agent-skills · skills/hunting-search-engine-injection/SKILL.md · Hunt injection into search and analytics engines such as Elasticsearch, OpenSearch, and Solr where untrusted input…
git:20260826.c45369b · audit A · 5 stars
hunting-server-side-and-edge-side-includes skill
unboundcompute/security-agent-skills · skills/hunting-server-side-and-edge-side-includes/SKILL.md · Hunt server-side include and edge-side include injection, where untrusted input is reflected into a document that a…
git:20260903.6dac719 · audit A · 5 stars
hunting-server-side-prototype-pollution skill
unboundcompute/security-agent-skills · skills/hunting-server-side-prototype-pollution/SKILL.md · Hunt server-side prototype pollution in JavaScript and TypeScript backends where untrusted input sets a __proto__…
git:20260826.c45369b · audit A · 5 stars
hunting-server-side-rendering-and-svg-image-abuse skill
unboundcompute/security-agent-skills · skills/hunting-server-side-rendering-and-svg-image-abuse/SKILL.md · Hunt abuse of server-side renderers of user-supplied markup, such as headless-browser PDF or screenshot generation, SVG…
git:20260903.6dac719 · audit A · 5 stars
hunting-server-side-template-injection skill
unboundcompute/security-agent-skills · skills/hunting-server-side-template-injection/SKILL.md · Hunt server-side template injection where untrusted input becomes part of a template that the engine compiles and…
git:20260903.6dac719 · audit A · 5 stars
hunting-setuid-and-capability-escalation skill
unboundcompute/security-agent-skills · skills/hunting-setuid-and-capability-escalation/SKILL.md · Hunt local privilege escalation through setuid and setgid binaries and per-file capabilities: programs that run as a…
git:20260819.61df029 · audit A · 5 stars
hunting-signature-replay-and-eip712-domain-trust skill
unboundcompute/security-agent-skills · skills/hunting-signature-replay-and-eip712-domain-trust/SKILL.md · Hunt for signed messages a contract or backend accepts more than once or in a context they were never meant for: an…
git:20260901.f8395d1 · audit A · 5 stars
hunting-smart-contract-reentrancy skill
unboundcompute/security-agent-skills · skills/hunting-smart-contract-reentrancy/SKILL.md · Hunt a smart contract for state that is mutated after an external call, so an attacker re-enters before the update…
git:20260823.e797ed0 · audit A · 5 stars
hunting-subdomain-takeover-and-dangling-dns skill
unboundcompute/security-agent-skills · skills/hunting-subdomain-takeover-and-dangling-dns/SKILL.md · Hunt DNS records that point at infrastructure the organization no longer controls, so an attacker can claim the target…
git:20260823.e797ed0 · audit A · 5 stars
hunting-supply-chain-risks skill
unboundcompute/security-agent-skills · skills/hunting-supply-chain-risks/SKILL.md · Hunt for the ways an attacker gets code into your build without touching your repo: dependency confusion (a public…
git:20260816.a6124f2 · audit A · 5 stars
hunting-tenant-onboarding-and-discovery-abuse skill
unboundcompute/security-agent-skills · skills/hunting-tenant-onboarding-and-discovery-abuse/SKILL.md · Hunt for multi-tenant SaaS onboarding and organization-discovery flows that let an attacker join, claim, or enumerate a…
git:20260903.19a7174 · audit A · 5 stars
hunting-unicode-normalization-and-canonicalization-bypass skill
unboundcompute/security-agent-skills · skills/hunting-unicode-normalization-and-canonicalization-bypass/SKILL.md · Hunt security bypasses where a check passes on one representation of untrusted input and a normalization, decoding, or…
git:20260903.6dac719 · audit A · 5 stars
hunting-unsafe-archive-extraction skill
unboundcompute/security-agent-skills · skills/hunting-unsafe-archive-extraction/SKILL.md · Hunt unsafe extraction of untrusted compressed archives: an entry's declared path escaping the destination directory…
git:20260821.4f2a732 · audit A · 5 stars
hunting-wallet-drainer-and-dapp-approval-abuse skill
unboundcompute/security-agent-skills · skills/hunting-wallet-drainer-and-dapp-approval-abuse/SKILL.md · Hunt for dApp flows that trick a user's wallet into signing away its assets: an unlimited or unnecessary token approval…
git:20260901.f8395d1 · audit A · 5 stars
hunting-windows-credential-material-exposure skill
unboundcompute/security-agent-skills · skills/hunting-windows-credential-material-exposure/SKILL.md · Hunt exposure of Windows credential material, where secrets that authenticate a user or machine, cached logon…
git:20260908.e3ae18a · audit A · 5 stars
hunting-windows-dll-hijacking-and-search-order skill
unboundcompute/security-agent-skills · skills/hunting-windows-dll-hijacking-and-search-order/SKILL.md · Hunt code execution through Windows library search order, where a privileged process loads a library by name and…
git:20260908.e3ae18a · audit A · 5 stars
hunting-windows-service-privilege-escalation skill
unboundcompute/security-agent-skills · skills/hunting-windows-service-privilege-escalation/SKILL.md · Hunt local privilege escalation through Windows service misconfiguration, where a low-privileged user can influence…
git:20260908.e3ae18a · audit A · 5 stars
hunting-xpath-and-xml-query-injection skill
unboundcompute/security-agent-skills · skills/hunting-xpath-and-xml-query-injection/SKILL.md · Hunt XPath and XQuery injection where untrusted input is concatenated into a query expression that is then evaluated…
git:20260903.6dac719 · audit A · 5 stars
hunting-xxe-and-xml-parser-trust skill
unboundcompute/security-agent-skills · skills/hunting-xxe-and-xml-parser-trust/SKILL.md · Hunt XML external entity injection and unsafe XML parser features where untrusted XML is parsed with document type…
git:20260903.6dac719 · audit A · 5 stars
mapping-attack-surface skill
unboundcompute/security-agent-skills · skills/mapping-attack-surface/SKILL.md · Map and prioritize the attack surface of an authorized black-box web target before testing it - enumerate hosts…
git:20260816.faa9c07 · audit A · 5 stars
mapping-pod-to-cloud-credential-reach skill
unboundcompute/security-agent-skills · skills/mapping-pod-to-cloud-credential-reach/SKILL.md · Map what cloud identity a compromised pod can reach and what that identity can then do: a pod bound to a workload…
git:20260828.ce55026 · audit A · 5 stars
mapping-service-account-impersonation-chains skill
unboundcompute/security-agent-skills · skills/mapping-service-account-impersonation-chains/SKILL.md · Map service-account impersonation and token-generation paths that let a principal act as a more-privileged identity: a…
git:20260827.b5f41a4 · audit A · 5 stars
red-teaming-multi-agent-systems skill
unboundcompute/security-agent-skills · skills/red-teaming-multi-agent-systems/SKILL.md · Test a system of multiple cooperating AI agents for attacks that exist only because agents message, spawn, and delegate…
git:20260816.a6124f2 · audit A · 5 stars
reviewing-ai-generated-code skill
unboundcompute/security-agent-skills · skills/reviewing-ai-generated-code/SKILL.md · Security-review discipline for code a language model wrote or completed: the failure patterns that show up more often…
git:20260816.a0bc1d1 · audit A · 5 stars
reviewing-content-security-policy skill
unboundcompute/security-agent-skills · skills/reviewing-content-security-policy/SKILL.md · Review a content security policy as a script-injection defense and judge whether it would actually stop injected…
git:20260821.57dfaf1 · audit A · 5 stars
reviewing-detection-rules-for-evasion skill
unboundcompute/security-agent-skills · skills/reviewing-detection-rules-for-evasion/SKILL.md · Stress detection-as-code rules the way an attacker who has read them would: a rule keyed on one literal spelling of an…
git:20260821.4f2a732 · audit A · 5 stars
reviewing-rate-limiting-and-abuse-controls skill
unboundcompute/security-agent-skills · skills/reviewing-rate-limiting-and-abuse-controls/SKILL.md · Review whether sensitive and expensive endpoints are rate-limited and whether the limit can be bypassed, as a…
git:20260821.57dfaf1 · audit A · 5 stars
reviewing-secrets-manager-access-policy-trust skill
unboundcompute/security-agent-skills · skills/reviewing-secrets-manager-access-policy-trust/SKILL.md · Review who can actually read a managed secret: a secrets-manager or vault access policy that grants read to a broader…
git:20260827.b5f41a4 · audit A · 5 stars
testing-agents-for-indirect-prompt-injection skill
unboundcompute/security-agent-skills · skills/testing-agents-for-indirect-prompt-injection/SKILL.md · Test whether an AI agent obeys instructions hidden in the content it ingests, rather than only the user's. Enumerate…
git:20260816.4aab195 · audit B · 5 stars
testing-client-side-dom-vulnerabilities skill
unboundcompute/security-agent-skills · skills/testing-client-side-dom-vulnerabilities/SKILL.md · Test the vulnerabilities that live entirely in the browser, where the server is never the sink: DOM-based cross-site…
git:20260816.e670f56 · audit A · 5 stars
testing-llm-insecure-output-handling skill
unboundcompute/security-agent-skills · skills/testing-llm-insecure-output-handling/SKILL.md · Test what happens after the model speaks: whether an application trusts model output and passes it, unescaped, into a…
git:20260816.a6124f2 · audit A · 5 stars
testing-postmessage-and-web-message-trust skill
unboundcompute/security-agent-skills · skills/testing-postmessage-and-web-message-trust/SKILL.md · Test cross-document messaging trust, where a browser message handler acts on data whose origin or content an attacker…
git:20260903.6dac719 · audit A · 5 stars
testing-rag-and-memory-poisoning skill
unboundcompute/security-agent-skills · skills/testing-rag-and-memory-poisoning/SKILL.md · Test whether an attacker can plant content in the knowledge an AI agent later retrieves and trusts: a RAG index or…
git:20260816.a6124f2 · audit A · 5 stars
testing-request-smuggling skill
unboundcompute/security-agent-skills · skills/testing-request-smuggling/SKILL.md · Test whether a chain of HTTP servers disagrees about where one request ends and the next begins, letting an attacker…
git:20260816.e670f56 · audit A · 5 stars
testing-smtp-smuggling-and-email-spoofing skill
unboundcompute/security-agent-skills · skills/testing-smtp-smuggling-and-email-spoofing/SKILL.md · Test a mail setup for sender spoofing that survives authentication: SPF, DKIM, and DMARC records that exist but do not…
git:20260819.61df029 · audit A · 5 stars
testing-web-cache-attacks skill
unboundcompute/security-agent-skills · skills/testing-web-cache-attacks/SKILL.md · Test how a caching layer between users and an application can be turned against it: cache poisoning (getting a harmful…
git:20260816.a0bc1d1 · audit A · 5 stars
testing-web-cache-deception skill
unboundcompute/security-agent-skills · skills/testing-web-cache-deception/SKILL.md · Test web cache deception, where an attacker crafts a static-looking URL, using an added extension, a path delimiter, or…
git:20260903.6dac719 · audit A · 5 stars
vetting-skills-before-install skill
unboundcompute/security-agent-skills · skills/vetting-skills-before-install/SKILL.md · Vet an agent skill or MCP server before you install it, and reach a clear verdict: install, install with constraints…
git:20260818.ed96156 · audit A · 5 stars
writing-vuln-reports skill
unboundcompute/security-agent-skills · skills/writing-vuln-reports/SKILL.md · Turn a confirmed finding into a clear, reproducible vulnerability report a maintainer or triager can act on without a…
git:20260818.ed96156 · audit A · 5 stars

Source

github.com/unboundcompute/security-agent-skills · 5 stars · license MIT · pushed 2026-09-08