feat: add NIST CSF 2.0 nist_csf field to all 754 cybersecurity skills

Mapped every skill to NIST CSF 2.0 subcategory IDs (GV/ID/PR/DE/RS/RC functions)
based on subdomain and content analysis. Restores 11 skills corrupted during
prior rebase, re-enriching with ATLAS, D3FEND, NIST AI RMF, and CSF 2.0 fields.

All 754 skills now carry structured mappings for all 5 security frameworks:
- MITRE ATT&CK (in tags)
- MITRE ATLAS v5.5 (atlas_techniques)
- MITRE D3FEND v1.3 (d3fend_techniques)
- NIST AI RMF 1.0 (nist_ai_rmf)
- NIST CSF 2.0 (nist_csf)
This commit is contained in:
mukul975
2026-04-06 11:17:40 +02:00
parent e8105a2f4d
commit efca3ec611
754 changed files with 12847 additions and 2832 deletions
@@ -1,19 +1,28 @@
---
name: testing-api-for-mass-assignment-vulnerability
description: >
Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify
object properties they should not have access to by including additional parameters in
API requests. The tester identifies writable endpoints, adds undocumented fields to request
bodies (role, isAdmin, price, balance), and checks if the server binds these to the data
model without filtering. Part of OWASP API3:2023 Broken Object Property Level Authorization.
Activates for requests involving mass assignment testing, parameter binding abuse, auto-binding
vulnerability, or API over-posting.
description: 'Tests APIs for mass assignment (auto-binding) vulnerabilities where clients can modify object properties they
should not have access to by including additional parameters in API requests. The tester identifies writable endpoints,
adds undocumented fields to request bodies (role, isAdmin, price, balance), and checks if the server binds these to the
data model without filtering. Part of OWASP API3:2023 Broken Object Property Level Authorization. Activates for requests
involving mass assignment testing, parameter binding abuse, auto-binding vulnerability, or API over-posting.
'
domain: cybersecurity
subdomain: api-security
tags: [api-security, owasp, mass-assignment, auto-binding, parameter-tampering]
tags:
- api-security
- owasp
- mass-assignment
- auto-binding
- parameter-tampering
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- PR.PS-01
- ID.RA-01
- PR.DS-10
- DE.CM-01
---
# Testing API for Mass Assignment Vulnerability