mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-04 09:50:19 +03:00
Rewrite 548 skill descriptions to the activation rubric
Each rewritten description now states both what the skill does (concrete capability, named tools/artifacts) and an explicit when-to-use trigger, improving agent discovery/activation. Grounded in each skill's own body; changes confined to the `description` field only (bodies and all other frontmatter untouched). Produced by a gated audit->rewrite->recheck loop (548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded). Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
@@ -1,14 +1,12 @@
|
||||
---
|
||||
name: exploiting-excessive-data-exposure-in-api
|
||||
description: 'Tests APIs for excessive data exposure where endpoints return more data
|
||||
than the client application needs, relying on the frontend to filter sensitive fields.
|
||||
The tester intercepts API responses and analyzes them for leaked PII, internal identifiers,
|
||||
debug information, or sensitive business data that the UI does not display but the
|
||||
API transmits. This maps to OWASP API3:2023 Broken Object Property Level Authorization.
|
||||
Activates for requests involving API data leakage testing, excessive data exposure,
|
||||
response filtering bypass, or API over-fetching.
|
||||
|
||||
'
|
||||
description: >-
|
||||
Tests APIs for excessive data exposure (OWASP API3:2023) by intercepting raw API
|
||||
responses and comparing them against what the UI actually renders, looking for
|
||||
leaked PII, internal identifiers, debug data, or business-sensitive fields the
|
||||
frontend filters but the API still transmits. Use when auditing REST or mobile-app
|
||||
APIs for over-fetching, response filtering bypass, or unintended data leakage in
|
||||
endpoint responses.
|
||||
domain: cybersecurity
|
||||
subdomain: api-security
|
||||
tags:
|
||||
|
||||
Reference in New Issue
Block a user