Production hardening: security fixes, code quality, 724 skills complete

- Fix 25 shell=True subprocess calls with list-based commands
- Fix 49 verify=False in defensive skills (env-var override)
- Add timeout to 231 HTTP/subprocess/socket calls
- Fix 6 SQL injection patterns with whitelist validation
- Replace 8 __import__() with standard imports
- Remove 701 unused imports across 442 files
- Add authorized-testing disclaimers to all offensive skills
- Complete 11 incomplete skill directories
- Expand 10 stub SKILL.md files with full content
- Fix 2 YAML parse errors in frontmatter
- Fix 5 pre-existing syntax errors
- Convert 22 hardcoded paths/ports to environment variables
- Back up 21 redundant skill pairs to .bak
- Fix 2 global declaration errors
- 724/724 skills with full folder anatomy (SKILL.md + agent.py + api-reference.md + LICENSE)
- 0 compile errors across all 724 agent.py files
This commit is contained in:
mukul975
2026-03-19 13:26:49 +01:00
parent 63b442d347
commit c47eed6a64
900 changed files with 23085 additions and 2720 deletions
@@ -17,7 +17,8 @@ urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)
class NessusAPI:
def __init__(self, url="https://localhost:8834", access_key=None, secret_key=None):
def __init__(self, url=None, access_key=None, secret_key=None):
url = url or os.environ.get("NESSUS_URL", "https://localhost:8834")
self.url = url.rstrip("/")
self.session = requests.Session()
self.session.verify = False
@@ -27,17 +28,17 @@ class NessusAPI:
})
def _get(self, endpoint):
resp = self.session.get(f"{self.url}{endpoint}")
resp = self.session.get(f"{self.url}{endpoint}", timeout=30)
resp.raise_for_status()
return resp.json()
def _post(self, endpoint, data=None):
resp = self.session.post(f"{self.url}{endpoint}", json=data)
resp = self.session.post(f"{self.url}{endpoint}", json=data, timeout=30)
resp.raise_for_status()
return resp.json()
def _put(self, endpoint, data=None):
resp = self.session.put(f"{self.url}{endpoint}", json=data)
resp = self.session.put(f"{self.url}{endpoint}", json=data, timeout=30)
resp.raise_for_status()
return resp.json()
@@ -138,7 +139,7 @@ class NessusAPI:
if status.get("status") == "ready":
break
time.sleep(5)
resp = self.session.get(f"{self.url}/scans/{scan_id}/export/{file_id}/download")
resp = self.session.get(f"{self.url}/scans/{scan_id}/export/{file_id}/download", timeout=30)
return resp.content
def check_auth_status(self, scan_id):