Software Data Integrity Failures

Security testing skill for OWASP A08:2025 — Software or Data Integrity Failures in Python web applications (FastAPI and Flask). Use this skill whenever the user wants to audit, detect, test, or fix integrity vulnerabilities including: insecure deserialization (pickle, yaml, jsonpickle, dill), mass assignment flaws, untrusted CDN/module inclusion, unsigned updates, CI/CD pipeline integrity, or Subresource Integrity (SRI) checks. Trigger this skill for ANY task involving pickle/deserialization security, CWE-502, CWE-915, CWE-829, CWE-345, or CWE-494, even if the user doesn't explicitly mention OWASP A08.

scholarly360 61974eb 2 files · 16.1 KB Updated

File contents

scholarly360/owasp-top10-web-skills/tree/main/skills/software-data-integrity-failures commit 61974ebb46

Frequently asked questions

npx skillmds@latest add scholarly360/software-data-integrity-failures