AGENTS.md instructions for jinyimeng01/net-code-audit-skill-master, covering agent guide: net-code-audit-skill-master, project overview, architecture, how to use and method 1: master orchestrator (recommended).
An automated security-review workflow for authorised .NET web applications and compiled .NET files such as DLLs. It coordinates code decompilation, attack-surface mapping, authentication checks, vulnerability checks, call tracing, and a final report.
A security-audit workflow for authentication and authorization in .NET applications. Authentication checks who a user is; authorization checks what that user is allowed to do.
A security-audit workflow for Blazor applications, Microsoft’s .NET framework for building interactive web interfaces with C#. It examines server circuits, browser-side code, component rendering, events, state, and live SignalR connections.
A .NET security review tool for code that starts processes or loads and runs code dynamically. It follows user-controlled input to execution points such as Process.Start, PowerShell, Roslyn and Assembly.Load.
A .NET security review tool for file reads and path-traversal risks. It follows user-controlled input into file operations such as FileStream, StreamReader, PhysicalFile and Path.Combine.
A .NET security review tool for file-upload code. It follows uploaded files from request handling to storage and checks path, extension and MIME-type validation.
A security-audit guide for ASP.NET Core Minimal APIs, a lightweight way to build web APIs in .NET. It traces user-controlled input through routes and request handling to sensitive operations such as files, commands, databases, or deserialization.
A security-audit workflow for .NET applications and deployment files, including ASP.NET, WCF, IIS packages, and decompiled programs. It examines how requests, permissions, data, and configuration flow through an application.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\api-auth-and-jwt-abuse\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\cmdi-command-injection\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\cors-cross-origin-misconfiguration\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\csrf-cross-site-request-forgery\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\deserialization-insecure\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\http-host-header-attacks\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\idor-broken-object-authorization\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\oauth-oidc-misconfiguration\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\open-redirect\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\path-traversal-lfi\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\request-smuggling\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\saml-sso-assertion-attacks\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.
Source: G:\tmp\安全项目研究\.netskill\hack-skills\skills\ssrf-server-side-request-forgery\SKILL.md Archived as: raw hack-skill reference for authorized .NET audit synthesis. Purpose: provenance-only material; load only when structured references are insufficient. -->.