← all publishers

rwcod

@rwcod source repo

8 published skills

  1. Endpoint Pentest · rwcod bundle
    Authorized, conservative security assessment of the HTTP/API endpoints beside an MCP server. Covers route discovery, OpenAPI/Swagger leakage, auth bypass, IDOR/BOLA, broken function-level authorization, mass assignment, excessive data exposure, SSRF, injection, file upload, webhook signature bypass, CORS, CSRF, rate limiting, and error/debug leakage. Safe-by-default and read-only. Use when testing REST/HTTP APIs in an authorized environment.
    0
    installs
  2. MCP Server Pentest · rwcod bundle
    Authorized security assessment of MCP servers and their tool handlers. Treats every tool handler as a public API endpoint with an unusual AI client. Covers transport exposure, authN/authZ, tool metadata review, sink classification, per-tool abuse testing, resources/prompts, and agent-specific abuse paths. Safe-by-default, read-only, deny-by-default. Use when reviewing MCP server code and its tool handlers.
    0
    installs
  3. Agent Abuse Pentest · rwcod bundle
    Authorized testing of AI-agent + tool misuse paths for an MCP system. Covers direct and indirect prompt injection (via docs/issues/PRs/READMEs/tool results/resources/prompt templates), poisoned tool and parameter descriptions, client metadata poisoning, unconfirmed dangerous tool calls, secret exfiltration attempts, context/memory poisoning, cross-tenant mixups, and multi-server trust propagation. Safe-by-default; benign markers only; never triggers real destruction. Use when assessing how injected content can become tool misuse.
    0
    installs
  4. Connected MCP Pentest · rwcod
    Authorized security testing of an MCP server ALREADY CONNECTED to your agent via mcp.json / settings (Claude Code, Cursor, Codex) — remote or local, any hosting. Tests the server IN-PLACE through the agent's own MCP tool calls: no cloning, no re-hosting, no raw endpoint URL or token needed. Covers tool inventory, per-tool authz reasoning, tenant/project tampering, IDOR, tool poisoning, consent gates, and input handling. Safe-by-default, read-only, writes human-gated. Use when the user says "test the MCP in my mcp.json" or points you at a connected MCP.
    0
    installs
  5. Security Report Writer · rwcod bundle
    Turns raw pentest notes for a remote OAuth MCP system into a professional, internal security report with severity ratings, remediation, and regression tests. Produces executive summary, methodology, flow/attack-surface maps, matrices, confirmed vs suspected findings, passed checks, prioritized fixes, and a regression plan. Enforces safe redaction (secrets as type+location+ fingerprint). Use when converting findings into a deliverable report.
    0
    installs
  6. Remote OAUTH MCP Pentest · rwcod bundle
    Authorized security assessment of REMOTE MCP servers that use browser-based OAuth/OIDC login (Jira/Rovo-style). Drives an 18-phase review of the OAuth flow, discovery metadata, token validation, scope-to-tool mapping, per-tool and per-tenant authorization, API-token fallback, consent boundaries, and audit logging. Safe-by-default, read-only, deny-by-default. Use when auditing a remote MCP server reached over HTTP with an OAuth login step.
    0
    installs
  7. MCP Autopentest Orchestrator · rwcod
    Semi-autonomous orchestrator for authorized MCP security assessment. Drives the deterministic probe_runner (read-only battery) plus optional parallel read-only sub-agents (discovery / authz-sweep / injection-probe), holds engagement state (tokens, discovered IDs), reasons over structured results, and produces the report. Safe-by-default: read-only, write/destructive tools are human-gated, scope-locked to one host. Use to run the kit with minimal manual curl.
    0
    installs
  8. Anti AI Slop UI · rwcod bundle
    Prevents generic AI-generated UI by enforcing product-specific design direction, design tokens, layout strategy, and anti-slop review. Use when generating or reviewing landing pages, SaaS UI, dashboards, onboarding flows, app screens, desktop/mobile UI, frontend components, Figma/mockups, UI redesigns, or shadcn/Tailwind refactors. Do not use for pure backend, database, DevOps, data processing, CLI-only scripts, or text-only tasks unless visible UI is involved.
    0
    installs