Skip to content

Releases: ashrafiucse/security-audit-skills

v1.4.2

Choose a tag to compare

@ashrafiucse ashrafiucse released this 23 Sep 19:34
222a0b4

What's new

New skill: dotnet-security — ASP.NET Core / .NET Framework audits: Razor Html.Raw/Blazor MarkupString XSS census, EF Core FromSqlRaw/Dapper/ADO SQL injection (with the FromSqlInterpolated safe-API near-miss), BinaryFormatter/TypeNameHandling/hardcoded-machineKey deserialization pack, [AllowAnonymous] census, antiforgery, CORS, open redirect, Process.Start concat. Measured by the new dotnet-vuln-app fixture (16 findings + safe counterparts).

Three documented coverage gaps closed (COVERAGE.md help-wanted queue is now empty):

  • LDAP authentication in auth-review — anonymous binds, DN injection, filter injection (ldap3 + JNDI), with escape-call triage rules
  • WebAssembly loading discipline in config-hardening (WSTG 4.13) — client-controlled wasm source, blob provenance
  • Framework rows in injection-flaws — Gin+sqlx, Flask-RESTful, ASP.NET Web Forms

Also in this release

  • container-iac-security: wildcard-RBAC census grep (resources/apiGroups/verbs: ["*"]) — the IBM-Concert KEV class, converted from issue-triage #23
  • secrets-detection: ADO.NET connection-string pattern (Server=…;Password=… — value-embedded credentials key-value patterns miss)
  • vuln-db: Telerik UI for ASP.NET AJAX CVE-2019-18935 (KEV; first NuGet entry, detection-first)
  • Triage watchers (update-kev.yml, critical-cve-digest.yml) now dedupe against the append-only kev-triage-log.md — decided CVEs no longer re-surface after their issue closes
  • Detection self-test: 122 match + 52 no-match + 2 multi-line rules; eval rounds scored 100/100/0 (IN-PROCESS labeled)

Full details: #21

v1.4.1 — moderation-queue XSS hardening, completeness gate v2, shift-left, design-phase skill

Choose a tag to compare

@ashrafiucse ashrafiucse released this 22 Sep 19:41
8ebf177

Patch release driven by a real-world miss: a live audit shipped a student→staff stored-XSS chain (moderation queue → admin account takeover). This release hardens the entire class, turns completeness into a contract, moves detection earlier, and adds a proactive real-world intake layer.

The live-miss class (student→staff XSS)

  • laravel-security Step 4: *.blade.php glob (kills React/TSX !! noise), mandatory wc -l census with per-hit disposition, privilege-direction severity table — unprivileged author + privileged viewer = Critical
  • course-platform-security §6.5: moderation-queue content-flow trace (write path → staff render path → approval = delivery mechanism)
  • security-audit: enumeration-discipline rule + census receipts + "Moderation-queue XSS → admin ATO" chain row
  • Fixtures: the exact chain, plus support/email and quiz/grading channels, with escaped safe counterparts and CI guards
  • Validated on the live project: class 0/5 → 5/5 channels, census 15/206 → 183/183, precision 22/22

Completeness gate v2

Every audit now ends with an actor×surface matrix where every cell is dispositioned (FINDING / VERIFIED-SAFE / NOT-ASSESSED listed by name); census receipts record hits-vs-dispositioned and flag INCOMPLETE audits.

Shift-left

  • Incremental (PR/diff) audit mode with read-only pr_diff_scope.sh skill dispatch → SECURITY-AUDIT-PR.md + CI VERDICT: BLOCK/PASS
  • New skill: design-threat-review — spec in → THREAT-MODEL.md out (actor×asset matrix, trust boundaries, STRIDE→detector mapping, acceptance criteria); the audit's Phase 0 loads it as the coverage-matrix seed

Class propagation (self-audit)

Generic privilege-direction table in injection-flaws XSS; django/rails/spring point to it. Fixed two live-verified broken greps (django rg --type+glob AND-trap; rails trailing-space pattern). Moderation-direction plants across all framework fixtures.

Real-world intake layer

real-world-sources.md (automated feeds + weekly manual sweep + conversion decision table), weekly community detection-rule watch (watch-semgrep-rules.yml), MAINTENANCE §3.1 intake SOP.

Harness

Scorer: T-NNN threat sections + opt-in --check-severity. Validator: unguarded-fixture warnings (zero remain). Self-tests: 98 match / 38 no-match / 2 multi-line (up from 80/33/1).

Full changelog: PR #17

v1.4.0 — Forge, Feed, Verify

Choose a tag to compare

@ashrafiucse ashrafiucse released this 22 Sep 14:43
bb12c37

Minor release (new skills). Consumers: git pull.

🔨 Skill forge — build your own skills, zero dependencies

skill-forge + scaffold script + 8 authoring laws from the eval LEARNINGS + blind-test protocol. Proof: course-platform-security — a domain skill walked as public/student/admin personas (gating truth, preview leaks, enrollment state machines, cohort scoping) with fixture. The core was already self-contained (rg/grep + stdlib; OSV/KEV are fact feeds); now the extension path is too.

📡 New knowledge sources (same stateless digest contract)

  • watch-0days.yml (weekly Mon 06:30): Project Zero 0days-in-the-wild — per-CVE markdown discovery (the documented JSON 404s), commits-window diffing
  • watch-metasploit.yml (weekly Mon 06:45): new CVE-backed exploit modules (modules/exploits, plural, verified + fail-loudly guard) — weaponization status as severity ammunition
  • Both now live lookups in cve-research Step 3; expanded web-source order

🛡️ Verified read-only guarantee

  • audit_readonly.py CI gate: 8 executables + 117 skill bash blocks, zero mutations
  • Empirical sha256 proof: scanners byte-identical; full audit adds exactly SECURITY-AUDIT.md
  • external-sources.md egress inventory: OSV package@version is the one real egress (offline mode documented); prompt-injection stance codified

Full changelog: PR #16 · Prior: v1.3.1

v1.3.1 — Knowledge Enrichment

Choose a tag to compare

@ashrafiucse ashrafiucse released this 22 Sep 12:48
abb3d7d

Knowledge-focused enrichment release (owner-directed version number). Consumers: git pull — skills reload on next session.

🧠 C/C++ native security — the last uncovered language family

Format strings (printf(user) → %n write primitive) · strcpy/strcat/gets/sprintf · system()/popen shell injection · integer-overflow→tiny-alloc · off-by-N · TOCTOU races · use-after-free — with memory-safe idioms (std::string, smart pointers, ASan) noted as positives. New fixture c-vuln-app with safe counterparts. (Hidden gap: Go's Sprintf false-matched the coverage grep until sink-name verification.)

☁️ AWS IAM privilege-escalation pack

PassRole + compute-create chains (EC2/Lambda/Glue/CloudFormation/SageMaker) · CreateAccessKey on other users · policy self-modification · wildcard trust policies · confused-deputy ExternalId · credential-exfil chains — judgment rules (narrow PassRole is normal) + fix patterns. Wired into container-iac-security.

🔑 API-keys-as-authentication (auth-review)

Keys in URLs · unscoped god-keys · no rotation · non-constant-time compare · weak generation · verify+encrypt key reuse.

🤫 Secrets: 3 modern providers

Sentry (sntrys_) · Netlify (nfp_ — site-takeover grade) · OpenRouter (sk-or-v1-).

📚 vuln-db: 44 → 47 entries

  • Drupalgeddon2 (CVE-2018-7600) — mass-exploited render RCE; version-constant detection for composer-less sites
  • PHP-FPM × nginx (CVE-2019-11043) — the config+bug compound: both conditions greppable
  • node-serialize (CVE-2017-5929) — no fix has ever existed; migration-only advisory

Also: GraphQL aliasing-amplification DoS row.

Self-test: 64 match + 28 no-match + 1 multi-line, all CI-gated. · Full changelog: PR #15 · Prior: v1.3.0

v1.3.0 — Blind Spots, Closed

Choose a tag to compare

@ashrafiucse ashrafiucse released this 22 Sep 11:44
81e0115

Minor release (new skills, patterns, and knowledge-base entries). Consumers: git pull + re-run install.sh if you symlink globally.

This release converts user-reported audit blind spots into capabilities — each validated by blind end-to-end agent audits (24 audits: recall 100%, precision 100%, phantoms 0 on every scored fixture).

🧭 New skill: flow-security

For the case where "order, payment, and invoice each look fine alone — the compromise only appears across the flow." Flow reconstruction → invariant table → 8 vulnerability classes: unguarded state transitions, cross-step data provenance (client-supplied totals at terminal steps), association/chained IDOR, replay, step-skipping, post-boundary mutation, amount drift, privilege transitions between hops.

📦 Dependency risk beyond CVEs

"Main system clean, risk lives in the packages." OSV/npm-audit are silent on four classes — now covered:

  • Discontinued/unfixable packages (vm2, request…) — flagged by presence + usage
  • Compromised releases with no CVE (event-stream 3.3.6, ua-parser-js 0.7.29…) — exact-version greps; matches mean rotate credentials
  • Safe package, dangerous usage (_.merge(req.body), compile(userInput))
  • Vendored copies (old jQuery under public/vendor/) — invisible to manifest scanners; version-banner thresholds
  • Plus reachability verdicts: present → used → dormant

📚 Knowledge base: 30 → 44 entries + incident knowledge

  • Mass-exploited CVEs with in-repo detection: Jenkins CVE-2024-23897, Confluence CVE-2023-22515, Spring Cloud Gateway CVE-2022-22947, PHPUnit eval-stdin, ThinkPHP, Exim, Apache httpd, + express/body-parser/path-to-regexp/braces/Go/jackson batch
  • notable-incidents.md: 15 real breaches (Equifax, Capital One, SolarWinds, Log4Shell, MOVEit, Uber, Toyota, Twitch, LastPass…) mapped to the exact check that catches the same exposure
  • Durable KEV/NVD triage log (batches #12, #13 recorded)

🔎 10+ new detection classes

Multi-tenant scoping census · deferred SSRF via registered webhooks · zip-slip/symlink extraction · unicode comparison hygiene · weak CSP · cookie prefixes · SRI · CRLF · API4/API10 · gRPC/MQ route census · JWT algorithm confusion/kid/PKCE · CI script injection · alerting-config checks · Rust & Phoenix framework rows

⚙️ Audit machinery (e2e-proven)

  • Re-audit mode: per-finding FIXED / STILL PRESENT verification with stable SEC ids
  • Attack-chain phase: 10 named chains, chain-critical tagging
  • Eval scorer + scoreboard: file-level anchors, dotfile/extension-less support; 20 drift rows
  • Training loops: [miss] + [fp] issue templates → MISSES ledger → fixture + pattern; adversarial drill; every e2e "phantom" triaged (all were real fixture gaps, zero fabrications)

🧪 Evals

27 fixtures, reports archived per round; self-test 61 match + 26 no-match + 1 multi-line, all CI-gated.

Full changelog: PR #14 · Prior release: v1.2.0

v1.2.0 — Recall Engine

Choose a tag to compare

@ashrafiucse ashrafiucse released this 22 Sep 08:02
feb64ab

Minor release (new skills, patterns, and knowledge-base entries per the semver policy). Consumers: git pull + re-run install.sh if you symlink globally.

What's new

🔎 16 new detection classes

NoSQL operator injection · prototype pollution · XXE · ReDoS · open redirect · unsafe file upload · trusted-header authz · TOCTOU races · WebSocket/SSE authz · generic mass assignment · postMessage handlers · SSRF egress review (NetworkPolicy/IMDSv2) · supply-chain hygiene (dependency confusion/typosquats) · JWT algorithm confusion + JWKS kid injection + PKCE · CI workflow script injection

Plus a route census (framework-aware route→authz table), a second-order taint pass (stored XSS, queue/webhook sinks, builder-raw SQL, multi-line queries), and new framework rows (NestJS, Ktor, Django REST, Rails API-only, Java library sinks).

🤖 New skill: llm-security

Prompt injection & data exfiltration via tools, unsafe model deserialization (pickle/torch.load/LangChain), LLM API keys, over-powered agent tools, prompt/PII logging & telemetry — mapped to the OWASP LLM Top 10.

📚 Knowledge base doubled: 14 → 30 vuln-db entries

jsonwebtoken family · qs/lodash pollution · semver ReDoS · PyYAML FullLoader · urllib3/requests credential leaks · Text4Shell · fastjson autoType · Shiro550 · Rails render-file · php-cgi Windows RCE · PwnKit · Grafana traversal · GitLab reset takeover · sudo Baron Samedit · xz backdoor · Next.js middleware bypass · regreSSHion — all detection-first with distro-backport false-positive notes.

🔁 Audit loop

  • Fix-verification (re-audit) mode: per-finding FIXED / STILL PRESENT status, stable SEC ids, delta report
  • Eval scorer (scripts/score_audit.py): recall/precision/phantoms vs ground truth, CI-asserted
  • Optional tool bridges (probe_tools.sh): gitleaks, trufflehog, semgrep, osv-scanner, checkov, kube-linter, tfsec — leads, not verdicts; skills stay rg/grep-only when absent

🧠 Training loops (now symmetric)

[miss] and [fp] issue templates → MISSES.md ledger → fixture + pattern. SCOREBOARD.md drift history with --append. Monthly adversarial drill + drift bisect in MAINTENANCE.

🔑 Secrets

Closed a real gap — hf_ tokens were planted-but-unmatchable. New Anthropic/HF/Groq patterns, asserted in CI across 5 fixtures.

🧪 Evals: 9 new fixtures (20 total)

Every detection change ships with planted findings + near-miss counter-examples. Self-test: 33 match + 14 no-match + 1 multi-line rules, wired into CI.

Full changelog: PR #11

v1.1.0 — Framework coverage: 16 skills

Choose a tag to compare

@ashrafiucse ashrafiucse released this 21 Sep 20:53

What's new since v1.0.0

New skills (6)

  • graphql-security — introspection/GraphiQL, depth limits, resolver authz/IDOR, error leakage, CSRF, batching (Apollo, yoga, graphene, gqlgen, Hasura)
  • mobile-security — Android manifest/WebView RCE bridges, iOS ATS/UserDefaults, RN/Flutter
  • laravel-security — mass assignment, APP_KEY cookie-forgery RCE chain, DB::raw, CSRF $except, Blade
  • django-security — raw()/extra() SQLi, mark_safe/|safe, fields='all', settings misconfig
  • rails-security — interpolated where, permit!, CSRF skips, send_file traversal, secret_key_base
  • spring-security — JPQL concat, MyBatis ${}, th:utext, actuator exposure, Jackson defaultTyping

Knowledge

  • OWASP Top 10 completeness gate (Phase 2 of security-audit)
  • A09 logging pack (audit events, log forging, verbosity)
  • Framework injection packs: Express, Django, Spring, Rails, Laravel, Go + Vue, Angular, Svelte, FastAPI, Gin/Echo/Fiber, Symfony, ASP.NET Core
  • vuln-db: +6 live KEV entries (litellm, starlette, gitlab, artifactory×2, magento)

Tooling

  • osv_scan.py: gradle.lockfile, Package.resolved, conan.lock, mix.lock → 13 ecosystems
  • APP_KEY secret pattern; POSIX-safe connstring regexes
  • CI: parser-coverage step, mobile/framework fixtures

Quality

  • 11 eval fixtures — every skill e2e-proven before shipping (audit runs verified planted findings, excluded planted false positives)
  • Rails audit: 10/10 + both near-misses excluded; Spring audit chained the vuln-db Spring4Shell entry against live OSV

Full compatibility — purely additive; no skill removed/renamed. (SemVer policy: MAINTENANCE.md)