Skill 审计报告
Web Application Security Testing 审计报告.
OWASP Top 10 testing, injection vulnerability detection, API security assessment, authentication testing, and web vulnerability reporting for authorized assessments
OpenAgentSkill 信任评分
OpenAgentSkill 信任评分
Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。
GitHub 采用度
信息62
397 个 GitHub Stars
Star/Fork 活跃度
信息62
397 个 Star,75 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过88
距上次推送 1 个月
许可证清晰度
通过86
MIT
README/SKILL.md 完整度
通过94
元数据包含足够的用法与工作流上下文
依赖与运行时风险
失败28
command execution surface, credential or environment access
安装可用性
通过92
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Web Application Security Testing
安装命令安全性
通过92
标准软件包或运行时安装路径
权限范围
失败18
secrets or environment access, shell or command execution
仓库证据
通过86
https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/09-web-security
审查状态
信息66
可用 AI 审查数据
Agent 验证结果
信息54
暂未有 Agent 结果数据
检查项
安装与采用审查
安装路径
92
npx skills add Masriyan/Claude-Code-CyberSecurity-Skill --skill Web Application Security Testing
仓库
88
https://github.com/Masriyan/Claude-Code-CyberSecurity-Skill/tree/main/skills/09-web-security
许可证
86
MIT
维护
88
距上次推送 1 个月
AI 审查
55
The skill includes WAF bypass techniques, which could be misused if not strictly authorized, but the documentation clearly emphasizes authorization requirements.
README/SKILL.md 完整度
94
Usable description available
依赖风险
28
command execution surface, credential or environment access
安装命令安全性
92
标准软件包或运行时安装路径
权限范围
18
secrets or environment access, shell or command execution
Star/Fork 活跃度
62
397 个 Star,75 个 Fork; 当前元数据中没有议题活跃度信息
采用度
68
397 个 GitHub Stars
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Financial research output is not financial advice; require human review before any live investment decision
- The skill includes WAF bypass techniques, which could be misused if not strictly authorized, but the documentation clearly emphasizes authorization requirements.
- The scripts are provided as-is without explicit testing or guarantee, but they appear functional and include disclaimers.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
方法
本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。
对比相近选项
下一步可审计的相关 Skill
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K Stars · 审计报告
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K Stars · 审计报告
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K Stars · 审计报告