Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
@@ -1,13 +1,10 @@
---
name: testing-api-for-mass-assignment-vulnerability
description: 'Tests APIs for mass assignment (auto-binding) vulnerabilities where
clients can modify object properties they should not have access to by including
additional parameters in API requests. The tester identifies writable endpoints,
adds undocumented fields to request bodies (role, isAdmin, price, balance), and
checks if the server binds these to the data model without filtering. Part of OWASP
API3:2023 Broken Object Property Level Authorization. Activates for requests involving
mass assignment testing, parameter binding abuse, auto-binding vulnerability, or
API over-posting.
description: 'Tests APIs for mass assignment (auto-binding), OWASP API3:2023, by identifying
writable endpoints, adding undocumented fields to request bodies (role, isAdmin,
price, balance), and checking whether the server binds them to the data model without
filtering. Use when testing an API for mass assignment, parameter binding abuse,
or over-posting on profile, registration, or object-creation endpoints.
'
domain: cybersecurity