Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,8 +1,12 @@
---
name: exploiting-idor-vulnerabilities
description: Identifying and exploiting Insecure Direct Object Reference vulnerabilities
to access unauthorized resources by manipulating object identifiers in API requests
and URLs.
description: >-
Identifies and exploits Insecure Direct Object Reference (IDOR) vulnerabilities
by manipulating object identifiers (numeric IDs, UUIDs, slugs) in API requests
and URLs, using Burp Suite proxy history, Intruder, and the Authorize extension
to test object-level authorization across sessions. Use during authorized
penetration tests or bug bounty work to validate that CRUD endpoints and
multi-tenant applications enforce per-object access control.
domain: cybersecurity
subdomain: web-application-security
tags: