安全

安全扫描与漏洞检测

显示 1393-1416 / 共 2332 个技能
vchirrav

sast-gosec

vchirrav

Run gosec SAST scans on Go code. Detects SQL injection, hardcoded credentials, insecure TLS, command injection, and other Go security issues.

数据处理 17 6个月前
vchirrav

cloud-security-prowler

vchirrav

Run Prowler for comprehensive cloud security posture assessment. Audits AWS, Azure, and GCP against CIS Benchmarks, PCI-DSS, HIPAA, GDPR, and other compliance frameworks.

云服务 17 6个月前
vchirrav

api-security-spectral

vchirrav

Run Spectral to lint OpenAPI and AsyncAPI specs for security issues. Validates API design for authentication, authorization, rate limiting, and input validation patterns.

API 开发 17 6个月前
vchirrav

secure-coding-audit

vchirrav

Audit code for security vulnerabilities using OWASP Secure Coding rules. Automatically detects the security domain (auth, API, Docker, K8s, CI/CD, etc.) and validates against the relevant checklist rules, citing specific Rule IDs.

CI/CD 17 6个月前
vchirrav

sast-eslint-security

vchirrav

Run ESLint with security plugins on JavaScript/TypeScript code. Detects eval usage, non-literal RegExp, prototype pollution, and other JS/TS security anti-patterns.

数据处理 17 6个月前
vchirrav

cloud-security-scoutsuite

vchirrav

Run ScoutSuite for multi-cloud security auditing. Collects configuration data from AWS, Azure, GCP, Oracle, and Alibaba Cloud and generates an interactive security report.

云服务 17 6个月前
vchirrav

sast-psalm

vchirrav

Run Psalm with taint analysis on PHP code. Detects SQL injection, XSS, command injection, path traversal, and other taint-flow vulnerabilities in PHP applications.

数据处理 17 6个月前
vchirrav

secure-coding-generate

vchirrav

Generate secure code following OWASP Secure Coding rules. Automatically detects the security domain and produces code with inline Rule ID citations (e.g., [INPUT-04], [AUTH-07]) plus a rules-applied summary.

认证鉴权 17 6个月前
vchirrav

iac-scan-tfsec

vchirrav

Run tfsec (now part of Trivy) to scan Terraform code for security misconfigurations. Deep HCL analysis with support for Terraform modules, variables, and expressions.

云服务 17 6个月前
vchirrav

dast-zap

vchirrav

Run OWASP ZAP for Dynamic Application Security Testing. Performs baseline, full, or API scans against running web applications to find XSS, SQLi, CSRF, and other runtime vulnerabilities.

API 开发 17 6个月前
vchirrav

secret-scan-gitleaks

vchirrav

Run Gitleaks to detect hardcoded secrets in git repositories. Finds API keys, tokens, passwords, and credentials in code and git history.

数据处理 17 6个月前
vchirrav

sca-npm-audit

vchirrav

Run npm audit for Node.js dependency vulnerability scanning. Built-in SCA for npm projects with automatic fix suggestions.

代码评审 17 6个月前
vchirrav

container-scan-dockle

vchirrav

Run Dockle to audit container images against CIS Docker Benchmark and best practices. Checks for running as root, sensitive files, HEALTHCHECK, and more.

数据处理 17 6个月前
vchirrav

sast-semgrep

vchirrav

Run Semgrep SAST scans on code. Supports 30+ languages with OWASP, security, and custom rulesets. Parses results and provides remediation guidance.

CI/CD 17 6个月前
vchirrav

sca-pip-audit

vchirrav

Run pip-audit for Python dependency vulnerability scanning. Checks installed packages and requirements files against the OSV and PyPI advisory databases.

代码评审 17 6个月前
vchirrav

dast-nuclei

vchirrav

Run Nuclei template-based vulnerability scanner. Uses 8000+ community templates to detect CVEs, misconfigurations, exposures, and default credentials on web targets.

代码生成 17 6个月前
vchirrav

license-scan-scancode

vchirrav

Run ScanCode Toolkit for comprehensive license and copyright detection. Identifies license types, copyright holders, and compliance obligations across codebases.

数据处理 17 6个月前
vchirrav

sast-brakeman

vchirrav

Run Brakeman SAST scans on Ruby on Rails applications. Detects SQL injection, XSS, mass assignment, CSRF, command injection, and other Rails-specific vulnerabilities.

数据处理 17 6个月前
vchirrav

dependency-confusion-detect

vchirrav

Run Confused and GuardDog to detect dependency confusion and typosquatting risks. Checks if internal package names exist on public registries and identifies malicious packages.

代码评审 17 6个月前
vchirrav

sca-grype

vchirrav

Run Anchore Grype for SCA vulnerability scanning on filesystems and container images. Matches dependencies against multiple vulnerability databases (NVD, GitHub, OS advisories).

数据处理 17 6个月前
vchirrav

container-scan-trivy

vchirrav

Run Trivy to scan container images for OS and library vulnerabilities, misconfigurations, and secrets. Comprehensive multi-target security scanner.

数据处理 17 6个月前
vchirrav

sast-detekt

vchirrav

Run detekt static analysis on Kotlin code with security-focused rules. Detects hardcoded secrets, insecure crypto, and code quality issues affecting security.

CLI 工具 17 6个月前
vchirrav

mobile-security-mobsf

vchirrav

Run MobSF (Mobile Security Framework) for automated static and dynamic analysis of Android and iOS apps. Detects insecure storage, weak crypto, hardcoded secrets, and permission issues.

API 开发 17 6个月前
vchirrav

tls-scan-testssl

vchirrav

Run testssl.sh to analyze TLS/SSL configurations. Checks cipher suites, protocols, certificate validity, known vulnerabilities (Heartbleed, POODLE, ROBOT), and compliance.

数据处理 17 6个月前