Fynd Dyrka

Security review in seven layers: SAST, secrets, dependencies, IaC, DAST, external recon of a live service (exposed .git, secrets in production JS, security headers/CORS, open ports and CVEs via Shodan, mail spoofability via SPF/DMARC), and platform — the real state of the production deployment (public database address, runtime variables, deploy permissions, backups, config drift from the repository). Orchestrates semgrep/gitleaks/osv-scanner/trivy/nuclei and does what scanners cannot: logic flaws (auth bypass, IDOR, SSRF, races over money) confirmed by running them, availability and cost (missing rate limits, unbounded queries, ReDoS, cost-DoS), observability, MITRE mapping, attack chains, and the agentic surface (LLM agents, MCP, RAG: excessive agency, tool poisoning, memory isolation, prompt injection). Every HIGH/CRITICAL finding is put through an attempt to refute it. Use on 'check the security', 'security review', 'security audit', 'scan for vulnerabilities', 'are there any holes', 'pentest', 'any leaked

Socialpranker Updated

File contents

socialpranker/fynd-dyrka-plugin/tree/main/plugins/fynd-dyrka/skills/fynd-dyrka commit 515fca7b7e

Frequently asked questions

npx skillmds@latest add socialpranker/fynd-dyrka