mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-09-03 23:10:50 +03:00
Production hardening: security fixes, code quality, 724 skills complete
- Fix 25 shell=True subprocess calls with list-based commands - Fix 49 verify=False in defensive skills (env-var override) - Add timeout to 231 HTTP/subprocess/socket calls - Fix 6 SQL injection patterns with whitelist validation - Replace 8 __import__() with standard imports - Remove 701 unused imports across 442 files - Add authorized-testing disclaimers to all offensive skills - Complete 11 incomplete skill directories - Expand 10 stub SKILL.md files with full content - Fix 2 YAML parse errors in frontmatter - Fix 5 pre-existing syntax errors - Convert 22 hardcoded paths/ports to environment variables - Back up 21 redundant skill pairs to .bak - Fix 2 global declaration errors - 724/724 skills with full folder anatomy (SKILL.md + agent.py + api-reference.md + LICENSE) - 0 compile errors across all 724 agent.py files
This commit is contained in:
@@ -78,7 +78,8 @@ policy = {
|
||||
}
|
||||
}
|
||||
|
||||
response = requests.post(f"{nessus_url}/scans", headers=headers, json=policy, verify=False)
|
||||
response = requests.post(f"{nessus_url}/scans", headers=headers, json=policy,
|
||||
verify=not os.environ.get("SKIP_TLS_VERIFY", "").lower() == "true") # Set SKIP_TLS_VERIFY=true for self-signed certs in lab environments
|
||||
scan_id = response.json()["scan"]["id"]
|
||||
print(f"Scan created: ID {scan_id}")
|
||||
```
|
||||
@@ -120,7 +121,7 @@ response = requests.get(
|
||||
f"{nessus_url}/scans/{scan_id}/export",
|
||||
headers=headers,
|
||||
params={"format": "csv"},
|
||||
verify=False
|
||||
verify=not os.environ.get("SKIP_TLS_VERIFY", "").lower() == "true", # Set SKIP_TLS_VERIFY=true for self-signed certs in lab environments
|
||||
)
|
||||
|
||||
# Parse and prioritize
|
||||
|
||||
Reference in New Issue
Block a user