Rewrite 548 skill descriptions to the activation rubric

Each rewritten description now states both what the skill does (concrete
capability, named tools/artifacts) and an explicit when-to-use trigger,
improving agent discovery/activation. Grounded in each skill's own body;
changes confined to the `description` field only (bodies and all other
frontmatter untouched). Produced by a gated audit->rewrite->recheck loop
(548 -> 0 flagged) with a sampled anti-invention check (0 ungrounded).

Schema: 817/817 pass. Framework-ID gate: 0 defects.
This commit is contained in:
Mahipal
2026-08-02 09:32:13 -07:00
parent 04a207702e
commit 2fb6a9faff
548 changed files with 2189 additions and 1915 deletions
+5 -10
View File
@@ -1,15 +1,10 @@
---
name: testing-websocket-api-security
description: 'Tests WebSocket API implementations for security vulnerabilities including
missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH),
injection attacks through WebSocket messages, insufficient input validation, denial-of-service
via message flooding, and information leakage through WebSocket frames. The tester
intercepts WebSocket handshakes and messages using Burp Suite, crafts malicious
payloads, and tests for authorization bypass on WebSocket channels. Activates for
requests involving WebSocket security testing, WS penetration testing, CSWSH attack,
or real-time API security assessment.
'
description: Tests WebSocket API implementations for missing upgrade-handshake authentication,
Cross-Site WebSocket Hijacking (CSWSH), message injection, insufficient input validation,
message-flooding DoS, and information leakage, using Burp Suite's WebSocket interception
and the wscat CLI to craft malicious payloads. Use for real-time API penetration testing
or CSWSH/authorization-bypass assessments on WebSocket channels.
domain: cybersecurity
subdomain: api-security
tags: