wgpsec/aboutsecurity
cors-misconfiguration
CORS 跨域配置错误检测与利用。当目标 API 返回 Access-Control-Allow-Origin 响应头、需要跨域访问敏感数据、或发现 Origin 头被反射回响应中时使用。可导致用户敏感数据窃取
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
>- CORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed …
3K installs>- OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, …
3K installsIdentifying and exploiting Cross-Origin Resource Sharing misconfigurations that allow unauthori…
382 installsIdentifying and exploiting OAuth 2.0 and OpenID Connect misconfigurations including redirect UR…
225 installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 20 installs