Sec Scan Auth — AI skill for Claude Code
인증/인가/어뷰징 취약점 진단 — Auth Bypass / IDOR / Mass Assignment / Rate Limit / 멱등성 / 클라이언트 신뢰 로직 — scan_api.py + scan_auth_baseline.py(후보 태깅) + LLM 전량 수동진단.
How to install Sec Scan Auth
Installs to ~/.claude/commands/hssg1109-palantir-sec-scan-auth.md
mkdir -p ~/.claude/commands && curl -fsSL https://raw.githubusercontent.com/hssg1109/palantir/HEAD/.claude/commands/sec-scan-auth.md -o ~/.claude/commands/hssg1109-palantir-sec-scan-auth.md Restart Claude Code, or start a new session, for it to be picked up.
What Sec Scan Auth does
allowed-tools: Read, Glob, Grep, Bash, Edit, Write, Agent, WebFetch description: 인증/인가/어뷰징 취약점 진단 — Auth Bypass / IDOR / Mass Assignment / Rate Limit / 멱등성 / 클라이언트 신뢰 로직 — scan_api.py + scan_auth_baseline.py(후보 태깅) + LLM 전량 수동진단
Sec Scan Auth
대상: $ARGUMENTS (미입력 시 testbed/ 내 대상 목록을 먼저 확인)
실행 절차
`sec-scan-auth/SKILL.md` 전체 내용을 읽고 절차대로 실행할 것.
sec-scan-auth/SKILL.md읽기shared/references/task_prompts/task_11_asset_identification.md읽기- `sec-scan-auth/references/task_pro
Alternatives in AI
- Context Dump — Dump current context for model switch or context limit recovery 508 ★
- Browser Search — A skill for AI agents: search the web with SearXNG, browse with Camofox, bypass protections with CloakBrowser 499 ★
- Graymatter — 30 sec to give your AI agents persistent memory 460 ★
Full documentation available on GitHub
View Source RepositoryRelated Skills
Sec Scan File
파일 처리 취약점 진단 — File Upload / Download / LFI / RFI — scan_file_processing.py + LLM 교차검증
Sec Scan XSS
XSS 취약점 진단 — Persistent / Reflected / DOM / Redirect XSS — scan_xss.py + LLM 교차검증
Vibeharness
Hackable, interactive LLM agent harness for the terminal — streaming REPL, tool-using agent loop, persistent P
Scraper Run
Deterministic extraction engine. Loads a blueprint, executes pagination, handles auth refresh, rate limits, an
Market News Alarm
AI agent that monitors SEC, Fed, CFTC, Federal Register, CNBC, Yahoo Finance and crypto news 24/7, uses Claude
Habitusx
The AI Code Outcomes Index. What happens to AI-written code after it lands: revert rate, PR acceptance and sur
Related Agents
API Attacker
API security testing specialist for REST, GraphQL, gRPC, and WebSocket APIs. Handles BOLA/IDOR, mass assignmen
Timps API Security Tester
Run an OWASP API Security Top-10 (2023) audit against an OpenAPI spec or live endpoint — broken auth, BOLA, ma
Kavach API
KAVACH API security + auth/session specialist. Traces every endpoint for BOLA/IDOR, BFLA, broken auth, mass as