Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,14 +1,12 @@
---
name: exploiting-excessive-data-exposure-in-api
description: 'Tests APIs for excessive data exposure where endpoints return more data
than the client application needs, relying on the frontend to filter sensitive fields.
The tester intercepts API responses and analyzes them for leaked PII, internal identifiers,
debug information, or sensitive business data that the UI does not display but the
API transmits. This maps to OWASP API3:2023 Broken Object Property Level Authorization.
Activates for requests involving API data leakage testing, excessive data exposure,
response filtering bypass, or API over-fetching.
'
description: >-
Tests APIs for excessive data exposure (OWASP API3:2023) by intercepting raw API
responses and comparing them against what the UI actually renders, looking for
leaked PII, internal identifiers, debug data, or business-sensitive fields the
frontend filters but the API still transmits. Use when auditing REST or mobile-app
APIs for over-fetching, response filtering bypass, or unintended data leakage in
endpoint responses.
domain: cybersecurity
subdomain: api-security
tags: