feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,18 +1,28 @@
---
name: conducting-api-security-testing
description: >
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in
authentication, authorization, rate limiting, input validation, and business logic. The tester
uses the OWASP API Security Top 10 as the testing framework, combining Burp Suite interception
with Postman collections and custom scripts to test endpoint security at every privilege level.
Activates for requests involving API security testing, REST API pentest, GraphQL security
assessment, or API vulnerability testing.
description: 'Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization,
rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framework,
combining Burp Suite interception with Postman collections and custom scripts to test endpoint security at every privilege
level. Activates for requests involving API security testing, REST API pentest, GraphQL security assessment, or API vulnerability
testing.
'
domain: cybersecurity
subdomain: penetration-testing
tags: [API-security, OWASP-API-Top10, REST, GraphQL, authorization-testing]
tags:
- API-security
- OWASP-API-Top10
- REST
- GraphQL
- authorization-testing
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- ID.RA-01
- ID.RA-06
- GV.OV-02
- DE.AE-07
---
# Conducting API Security Testing