coldtatooine/vuln-skill-pack

A skill based on "rfdslabs" prompt to have a good hunting session.

2Stars on the repository
26Mods indexed here, across every type
7d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

coldtatooine/vuln-skill-pack

Cursor rule

Next.js & Vercel security footguns — client/server secret leakage via NEXTPUBLIC, unauthenticated Server Actions and Route Handlers, middleware auth bypass, SSRF in server fetches. Apply when reviewing, building, or shipping a Next.js or Vercel app.

2 7d ago B 0 tokens original MIT

coldtatooine/vuln-skill-pack

Cursor rule

Node.js & Express API security footguns — missing auth/authz middleware, IDOR, broken JWT verification, permissive CORS, SQL/NoSQL/command injection, missing rate limiting, mass assignment. Apply when reviewing, building, or shipping a Node/Express (or Fastify/Koa/Nest) backend.

2 7d ago A 0 tokens original MIT

operating-rules

03

coldtatooine/vuln-skill-pack

Cursor rule

Core operating rules for defensive security review with the vun-skill-pack. Always in effect during any security analysis.

2 7d ago B 355 tokens original MIT

stripe-security

04

coldtatooine/vuln-skill-pack

Cursor rule

Stripe security footguns — unverified webhook signatures, trusting price/amount from the client, secret key exposure, missing idempotency, fulfilling on the wrong event. Apply when reviewing, building, or shipping payment or billing flows with Stripe.

2 7d ago A 0 tokens original MIT

supabase-security

05

coldtatooine/vuln-skill-pack

Cursor rule

Supabase security footguns — Row Level Security disabled or too permissive, servicerole key exposed to the client, weak policies, public storage buckets, client-set privilege columns. Apply when the app uses Supabase (Postgres, Auth, Storage, Edge Functions).

2 7d ago A 0 tokens original MIT