diff --git a/strix/skills/cloud/aws.md b/strix/skills/cloud/aws.md index 299e5f677..82cc61371 100644 --- a/strix/skills/cloud/aws.md +++ b/strix/skills/cloud/aws.md @@ -94,6 +94,8 @@ curl https://BUCKET.s3.amazonaws.com/ ### IAM Privilege Escalation +**Resource control policies:** AWS Organizations RCPs impose an organization-level limit on supported resources, including access by external principals. Map resource-account RCPs as well as principal-account SCPs, identity/resource policies, session policies, and permission boundaries when assessing a cross-account or leaked-key path. RCPs do not grant access and do not apply uniformly to every service; an identity-policy allow alone does not describe the effective permission ([AWS RCP documentation](https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_rcps.html)). + Common escalation paths (verify with `aws iam simulate-principal-policy` when possible): | Permission | Escalation | diff --git a/strix/skills/cloud/kubernetes.md b/strix/skills/cloud/kubernetes.md index 09a335853..42ecfeeaa 100644 --- a/strix/skills/cloud/kubernetes.md +++ b/strix/skills/cloud/kubernetes.md @@ -32,6 +32,10 @@ Kubernetes clusters expose a large attack surface through their API server, kube ## Key Vulnerabilities +### Ingress-NGINX Admission + +Inventory validating-webhook reachability from the pod network and the controller's service-account permissions. IngressNightmare illustrates controller execution without a Kubernetes account ([advisory](https://kubernetes.io/blog/2025/03/24/ingress-nginx-cve-2025-1974/)). Identify the controller implementation/image, then verify affected builds, backports, and maintenance status against current project or vendor notices; distinguish community ingress-nginx from other NGINX controllers and the Ingress API ([project notice](https://kubernetes.io/blog/2026/01/29/ingress-nginx-statement/)). + ### RBAC Misconfigurations - Wildcard verbs or resources in ClusterRole/Role bindings: `verbs: ["*"]`, `resources: ["*"]` diff --git a/strix/skills/frameworks/django.md b/strix/skills/frameworks/django.md index 17f45b50f..143e6e905 100644 --- a/strix/skills/frameworks/django.md +++ b/strix/skills/frameworks/django.md @@ -57,6 +57,11 @@ Map endpoints, authentication classes, and permission classes per route. ## Key Vulnerabilities +### Request and Spatial Input Handling + +- Under ASGI, compare underscore/hyphen forms of proxy-injected identity headers through `ASGIRequest` normalization into `request.META`. Resolve the installed branch, vendor backports, and support status from package metadata and current Django release/advisory information ([header-collision advisory](https://www.djangoproject.com/weblog/2026/apr/07/security-releases/)). +- For GeoDjango, trace attacker-controlled spatial lookup strings/dictionaries into `GDALRaster`: driver behavior can turn them into server-side requests or file writes. Include custom filter APIs and admin changelist filtering; direct model-field assignment is a separate input path ([spatial lookup advisory](https://www.djangoproject.com/weblog/2026/aug/04/security-releases/)). + ### Authentication & Authorization **Permission Class Gaps** @@ -207,7 +212,7 @@ Static analysis is the fastest way to reach the sinks above in white-box scope. - **pip-audit** (PyPA) — dependency CVE scanner for known-vuln Django/DRF/simplejwt versions: `pipx install pip-audit && pip-audit -r requirements.txt` - **ast-grep** (preinstalled) — quick structural grep for risky calls without a full SAST run: `ast-grep run -p 'mark_safe($X)' -l python` -For the `SECRET_KEY` → signed-cookie/reset-token forgery path noted under Session Issues, Django's own `django.core.signing` is the "tool": with a leaked key you can mint valid `signing.dumps()` values (session cookies, password-reset tokens, and `PickleSerializer`-backed session RCE). +For the `SECRET_KEY` → signed-cookie forgery path noted under Session Issues, Django's own `django.core.signing` is the "tool": with a leaked key you can mint valid `signing.dumps()` values using the consumer's serializer and signing salt. Inspect `SESSION_SERIALIZER` and the installed implementation: the session-RCE path requires a reachable pickle-backed serializer; JSON sessions do not provide it. Password-reset tokens instead use `PasswordResetTokenGenerator`, with user state and timestamp in the digest, rather than the generic `signing.dumps()` format ([Django 5.0 removals](https://docs.djangoproject.com/en/5.0/releases/5.0/#features-removed-in-5-0), [token implementation](https://github.com/django/django/blob/stable/5.2.x/django/contrib/auth/tokens.py)). ## Summary diff --git a/strix/skills/frameworks/fastapi.md b/strix/skills/frameworks/fastapi.md index 81163bf2d..5cd6d14db 100644 --- a/strix/skills/frameworks/fastapi.md +++ b/strix/skills/frameworks/fastapi.md @@ -58,6 +58,12 @@ For each route, identify: ## Key Vulnerabilities +### Starlette Request Handling + +Resolve Starlette's version independently of FastAPI and identify the ASGI server/front proxy. Check current upstream advisories and any vendor backports for the installed build before treating a parser issue as applicable. Compare middleware authorization against the actual routed path: malformed Host values can alter reconstructed `request.url` without changing routing ([URL parsing advisory](https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr)). + +For `request.form()`, test URL-encoded and multipart limits separately; a limit enforced on one parser may not constrain the other. Check whether crossing an upload's memory-to-disk spool threshold blocks the event loop ([form limits](https://github.com/Kludex/starlette/security/advisories/GHSA-82w8-qh3p-5jfq), [file spooling](https://github.com/Kludex/starlette/security/advisories/GHSA-2c2j-9gv5-cj73)). + ### Authentication & Authorization **Dependency Injection Gaps** diff --git a/strix/skills/frameworks/nestjs.md b/strix/skills/frameworks/nestjs.md index 51cf924fc..7fcfafec4 100644 --- a/strix/skills/frameworks/nestjs.md +++ b/strix/skills/frameworks/nestjs.md @@ -78,6 +78,13 @@ For each controller and method, identify: ## Key Vulnerabilities +### Adapter and Schema Version Boundaries + +- **Express adapter:** resolve the installed Nest/Express versions and effective query-parser setting from configuration or a harmless nested-query probe. Apply `qs`/nested-operator attacks only when the parser constructs nested objects. Check the matching router documentation and test both root and child paths against authentication middleware ([migration reference](https://nestjs.io/tutorials/what-s-new-in-express-5-eeb51579)). +- **Fastify adapter:** inspect the installed version's schema requirements and any custom validator configuration. Verify whether the route schema is actually enforced before relying on a DTO or shorthand-schema declaration ([migration reference](https://fastify.dev/docs/v5.0.x/Guides/Migration-Guide-V5/)). +- **Standard Schema, where supported:** `@Body({ schema })`, `@Query({ schema })`, `@Param(..., { schema })`, and `@RawBody({ schema })` attach metadata; enforcement requires `StandardSchemaValidationPipe`. Probe schema-decorated routes for accepted invalid values when the pipe is absent or transport-local. Outgoing schema enforcement uses `StandardSchemaSerializerInterceptor`; check actual output rather than relying only on class-transformer decorators. +- **GraphQL transport:** inspect installed packages, enabled IDE, and negotiated WebSocket subprotocol. Verify supported/deprecated transports against the matching Nest documentation, then recheck connection and per-operation authentication on the deployed transport ([migration guide](https://docs.nestjs.com/migration-guide)). + ### Guard Bypass **Decorator Stack Gaps** diff --git a/strix/skills/frameworks/nextjs.md b/strix/skills/frameworks/nextjs.md index 5ae88604a..4bdb0be91 100644 --- a/strix/skills/frameworks/nextjs.md +++ b/strix/skills/frameworks/nextjs.md @@ -12,7 +12,7 @@ Security testing for Next.js applications. Focus on authorization drift across r **Routers** - App Router (`app/`) and Pages Router (`pages/`) often coexist - Route Handlers (`app/api/**`) and API routes (`pages/api/**`) -- Middleware: `middleware.ts` at project root +- Middleware/proxy: inspect `middleware.ts`, `proxy.ts`, installed Next.js metadata, and runtime configuration. Check the matching framework docs for supported filenames, Node/Edge behavior, and feature status before selecting runtime-specific probes ([migration guide](https://nextjs.org/docs/app/guides/upgrading/version-16)). **Runtimes** - Node.js (full API access) @@ -43,6 +43,8 @@ Security testing for Next.js applications. Focus on authorization drift across r ## Reconnaissance +At each assessment, establish the deployed build from package metadata, lockfiles, or runtime evidence. Verify release/support status and applicable fixes through current official docs, advisories, or upstream source; linked advisories are starting points, not a complete or permanently current list. Recheck when the target build or proposed remediation changes, and mark status unverified if evidence is unavailable. + **Route Discovery** ```javascript @@ -83,10 +85,15 @@ Inspect Network tab for POST requests with `Next-Action` header. Extract action ## Key Vulnerabilities +### RSC and Image Processing + +- **React2Shell (CVE-2025-55182):** App Router applications can expose the vulnerable RSC decoder without explicit Server Actions. Identify the bundled `react-server-dom-*` implementation and trace requests into decoding; client-only React and Pages-only apps have different exposure. Check the framework's patched branch, including source-disclosure and DoS fixes ([RCE advisory](https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components), [RSC advisories](https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-components)). +- Treat `/_next/image` optimization and Node `next/og` `ImageResponse` as separate input paths. Trace attacker-controlled image bytes into native decoders, and SVG content/attributes/styles into image construction. URL allowlisting does not make image contents trusted; match the decoder, runtime, and Next.js version to the relevant advisory ([optimizer](https://nextjs.org/blog/august-2026-security-release), [ImageResponse](https://github.com/vercel/next.js/security/advisories/GHSA-vcvr-r3jv-pc5j)). + ### Middleware Bypass **Known Techniques** -- `x-middleware-subrequest` header crafting (CVE-class bypass) +- `x-middleware-subrequest` header crafting (CVE-2025-29927): middleware-only authorization can be skipped on affected deployments. Resolve the installed branch and hosting protections from the advisory and provider configuration, then check whether external headers reach the origin and the destination enforces authorization independently ([advisory](https://github.com/vercel/next.js/security/advisories/GHSA-f82v-jwr5-mffw)). - `x-nextjs-data` probing - Look for 307 + `x-middleware-rewrite`/`x-nextjs-redirect` headers @@ -118,7 +125,7 @@ Middleware checks first value, handler uses last or array. **Cache Boundary Failures** - User-bound data cached without identity keys (ETag/Set-Cookie unaware) - Personalized content served from shared cache/CDN -- Missing `no-store` on sensitive fetches +- Missing `no-store` on sensitive fetches matters only when they enter a shared cache. Determine `fetch` and GET Route Handler defaults for the deployed version from docs/configuration and observed responses. Where Cache Components are enabled, inspect `use cache` arguments/closed-over values, `cacheTag`, `cacheLife`, and invalidation for user/tenant separation ([caching documentation](https://nextjs.org/docs/app/getting-started/cache-components)). **Flight Data Leakage** diff --git a/strix/skills/protocols/graphql.md b/strix/skills/protocols/graphql.md index 749f8717d..095ab8417 100644 --- a/strix/skills/protocols/graphql.md +++ b/strix/skills/protocols/graphql.md @@ -134,6 +134,10 @@ Parser precedence varies; may bypass validation. Also test default argument valu Send unexpected keys in input objects; backends may pass them to resolvers or downstream logic. +### OneOf Inputs + +Discover `@oneOf` input types through the schema or `__Type.isOneOf`. They require exactly one non-null field, with every other field omitted. Test both inline literals and variables with zero fields, two selectors, and an extra null-valued selector; all must fail coercion. Then test authorization independently for each valid selector (ID, username, organization/email), since schema exclusivity does not ensure identical tenant checks in each resolver branch. Confirm the deployed implementation supports OneOf before treating acceptance as a specification violation ([GraphQL September 2025](https://spec.graphql.org/September2025/#sec-OneOf-Input-Objects)). + ### Cursor Manipulation Decode cursors (usually base64) to: diff --git a/strix/skills/protocols/oauth.md b/strix/skills/protocols/oauth.md index 819870bb6..ea99aa864 100644 --- a/strix/skills/protocols/oauth.md +++ b/strix/skills/protocols/oauth.md @@ -77,7 +77,7 @@ com.app://callback (mobile custom scheme) ### State and Nonce -- Missing, predictable, or reusable `state` → CSRF on OAuth login (session fixation, account linking) +- Missing, predictable, or reusable `state` → test CSRF on OAuth login (session fixation, account linking); RFC 9700 also permits correctly bound PKCE, or OIDC `nonce`, to provide CSRF protection, so establish whether that protection survives a cross-session callback - Missing `nonce` in OIDC → ID token injection/replay - `state` not bound to client session or PKCE verifier @@ -102,7 +102,7 @@ com.app://callback (mobile custom scheme) ### Scope and Token Issues - Scope escalation: request `admin`/`offline_access`/`openid profile email` beyond app need; server grants all requested scopes -- Refresh token not rotated or reuse not detected → persistent access +- Public-client refresh tokens neither sender-constrained nor rotated with reuse detection → persistent access; a non-rotating token bound to the client's key is permitted by RFC 9700, so test replay without that key - Access token accepted across services (missing audience/resource binding) - Token introspection returns `active:true` without proper auth on introspection endpoint @@ -113,6 +113,10 @@ com.app://callback (mobile custom scheme) - Userinfo endpoint returns PII without matching access token scope - `sub` collision across issuers if `iss` not validated +### OAuth Security BCP (RFC 9700) + +Authorization servers must support PKCE, public clients must use it, and confidential clients are also recommended to use it. Test challenge stripping and verifier injection across both client types. Resource-owner-password grants must not be used; implicit access-token responses are discouraged because tokens can leak or be replayed. For mix-up defenses, bind the selected issuer and endpoints to the authorization transaction; validate an authorization-response `iss` when that defense is used, rather than merely checking the issuer of a later ID token ([RFC 9700](https://www.rfc-editor.org/rfc/rfc9700.html)). + ## Advanced Techniques **Referer Leakage** diff --git a/strix/skills/technologies/active_directory.md b/strix/skills/technologies/active_directory.md index b3962b6d4..4944c2060 100644 --- a/strix/skills/technologies/active_directory.md +++ b/strix/skills/technologies/active_directory.md @@ -100,6 +100,13 @@ certipy find -u @ -p -dc-ip -vulnerable -stdout - **ESC8** — NTLM relay to the CA web-enrollment endpoint (coerce a DC, relay to `/certsrv`) → DC certificate → DCSync. - **ESC others** — ESC2/3 (any-purpose/enrollment-agent), ESC4 (writable template DACL → make it ESC1), ESC6 (`EDITF_ATTRIBUTESUBJECTALTNAME2` on the CA), ESC7 (CA officer rights), ESC9/10 (weak cert mapping), ESC11 (RPC relay), ESC13 (issuance-policy→group), ESC15 (app-policy on v1 templates). `certipy find -vulnerable` flags each. +**Strong certificate mapping:** establish the DC patch level, mapping policy, and vendor backports; consult Microsoft's current enforcement guidance before assuming Compatibility mode is available. Inspect template SID extensions, explicit mappings, and the principal selected at authentication. A requested privileged UPN alone does not establish a working ESC chain ([KB5014754](https://support.microsoft.com/en-us/servicing/os/windows-server/2022/05/kb5014754-certificate-based-authentication-changes-on-windows-domain-controllers)). + +### Windows Server 2025 dMSA / BadSuccessor + +- **CVE-2025-53779:** on unpatched Server 2025 DCs, control sufficient to create/modify a delegated Managed Service Account can establish a one-way migration link to another principal and obtain its authority/keys through the KDC. Enumerate dMSA creation rights, object ACLs, and migration attributes rather than limiting discovery to conventional service accounts and delegation flags. +- **Patched behavior:** the KDC requires mutual dMSA↔target linkage. Writing the dMSA-side attribute still succeeds, so LDAP write success is not proof of exploitation. Determine whether the tester also controls the target object's reciprocal link and whether the KDC actually issues the relevant ticket. Post-patch abuse is a different prerequisite chain from the original low-privilege OU-control escalation ([researchers' patch analysis](https://www.akamai.com/blog/security-research/badsuccessor-is-dead-analyzing-badsuccessor-patch)). + ### NTLM Coercion & Relay Force a privileged machine to authenticate to you, then relay that NTLM auth to a service that doesn't enforce signing/EPA (LDAP, AD CS, SMB). diff --git a/strix/skills/technologies/auth0.md b/strix/skills/technologies/auth0.md index bb7c80239..8c6f559ab 100644 --- a/strix/skills/technologies/auth0.md +++ b/strix/skills/technologies/auth0.md @@ -86,12 +86,14 @@ Authorization: Bearer ### Rules and Actions Abuse +Inventory which Rules, Hooks, and Actions actually execute in the tenant. Check the current Auth0 lifecycle notice and tenant capabilities for retirement or read-only restrictions. During migration, compare claim assignment, MFA, denial decisions, and account-linking checks across every connection; distinguish secret/configuration access from source-code modification ([lifecycle notice](https://auth0.com/docs/troubleshoot/product-lifecycle/deprecations-and-migrations#rules-and-hooks-deprecations)). + **Post-Login Rule/Action Injection** - Rules that add claims based on unvalidated user metadata: ```javascript user.app_metadata.role = 'admin' // if user can set app_metadata via signup/API ``` -- `context.authorization` manipulation in Actions +- Rules use `context`; Actions receive `event` and enforce token/MFA/denial changes through `api` methods. Test migrated checks that only mutate event data: those mutations do not propagate to other Actions or substitute for the corresponding enforcement API ([migration behavior](https://auth0.com/docs/customize/actions/migrate/migrate-from-rules-to-actions)). - Secrets in Rule code exposed to tenant admins or via Management API leak **Signup / Registration Actions** diff --git a/strix/skills/technologies/grafana_prometheus.md b/strix/skills/technologies/grafana_prometheus.md index ee1ae63b9..1d5071b18 100644 --- a/strix/skills/technologies/grafana_prometheus.md +++ b/strix/skills/technologies/grafana_prometheus.md @@ -79,6 +79,13 @@ Unauthenticated view (and, with `public_mode`, delete) of the lowest-key snapsho ### Prometheus / Alertmanager — exposure is the vuln (no auth by default) Prometheus and Alertmanager ship with **no authentication**; the docs explicitly say do not expose them. There is rarely a CVE — reachability itself is the finding, and the payoff is recon + credential leakage + pivoting (below). +## Plugin and MCP Boundaries + +Resolve installed Grafana, plugin, and MCP server builds separately; check current upstream advisories and vendor backports before applying a listed attack path or recommending a release. + +- Plugin archives are extracted before signature verification. Test chained symlinks and containment before trusting a signature failure to prevent filesystem writes; archive installation is the required trigger ([extraction advisory](https://grafana.com/security/security-advisories/cve-2026-15815/)). +- Inventory mcp-grafana separately from Grafana. Trace `grafana_api_request` and `X-Grafana-URL` into destination selection; preventing token forwarding alone does not prevent SSRF ([MCP advisory](https://grafana.com/security/security-advisories/cve-2026-19516/)). + ## Pivoting: Observability → Deeper Compromise This is the core value. Chain each exposure into something that matters. Always articulate the pivot in the finding, not just the exposed endpoint. diff --git a/strix/skills/technologies/llm_applications.md b/strix/skills/technologies/llm_applications.md index e4a4ab9a9..4fcd7b66e 100644 --- a/strix/skills/technologies/llm_applications.md +++ b/strix/skills/technologies/llm_applications.md @@ -78,11 +78,11 @@ Record both forward and reverse reachability: attacker-controlled input to privi ## Optional Tool Routing -Use tools only when they match the deployed surface. Treat generated cases and scanner labels as leads until the application-side boundary is validated. +Use tools only when they match the deployed surface. Resolve compatible versions, runtime requirements, maintenance status, and advisories from registry metadata and current upstream documentation, then pin the exact reviewed versions for the run. Treat generated cases and scanner labels as leads until the application-side boundary is validated. -- **[Promptfoo](https://github.com/promptfoo/promptfoo)** — use for repeatable model/application trials, custom adversarial cases, graders, provider comparisons, and success-rate regression. Install the reviewed version locally with `npm install --save-dev --save-exact promptfoo@0.122.0`, then invoke `./node_modules/.bin/promptfoo redteam run`. Define explicit plugins, assertions, `numTests`, `maxConcurrency`, and `delay`; provider calls may transmit test data and incur cost. Its `owasp:llm` preset still uses the 2025 category mapping in version 0.122.0, so build or select tests from the 2026 matrix above and do not present the preset report as complete 2026 coverage. -- **[MCP Inspector](https://github.com/modelcontextprotocol/inspector)** — use for LLM01/LLM03 surface mapping when MCP servers are present. Install the reviewed version with `npm install --save-dev --save-exact @modelcontextprotocol/inspector@2.2.0`, then use `./node_modules/.bin/mcp-inspector --cli --config --server --method tools/list` and the equivalent `resources/list` / `prompts/list` operations. Starting a stdio server executes that configured process, initialization/list handlers may have side effects, and `tools/call` can perform the real action; inspect the target and credentials before invoking it. -- **[ModelScan](https://github.com/protectai/modelscan)** — use for LLM04 static triage of supported H5, Pickle, and SavedModel artifacts before loading them, for example `uvx modelscan==0.8.8 -p `. Run it as an untrusted-file parser in an isolated analysis environment. A clean result covers only the scanner's supported formats and signatures; it does not establish artifact provenance, integrity, or absence of behavioral backdoors. +- **[Promptfoo](https://github.com/promptfoo/promptfoo)** — use for repeatable model/application trials, custom adversarial cases, graders, provider comparisons, and success-rate regression. Install the reviewed version locally with `npm install --save-dev --save-exact promptfoo@`, then invoke `./node_modules/.bin/promptfoo redteam run`. Define explicit plugins, assertions, `numTests`, `maxConcurrency`, and `delay`; provider calls may transmit test data and incur cost. Inspect the installed `owasp:llm` preset's category mapping and actual tests before claiming coverage; add cases for gaps against the assessment's chosen taxonomy. +- **[MCP Inspector](https://github.com/modelcontextprotocol/inspector)** — use for LLM01/LLM03 surface mapping when MCP servers are present. Install the reviewed version with `npm install --save-dev --save-exact @modelcontextprotocol/inspector@`, then use `./node_modules/.bin/mcp-inspector --cli --config --server --method tools/list` and the equivalent `resources/list` / `prompts/list` operations. Starting a stdio server executes that configured process, initialization/list handlers may have side effects, and `tools/call` can perform the real action; inspect the target and credentials before invoking it. +- **[ModelScan](https://github.com/protectai/modelscan)** — use for LLM04 static triage of supported H5, Pickle, and SavedModel artifacts before loading them, for example `uvx modelscan== -p `. Run it as an untrusted-file parser in an isolated analysis environment. A clean result covers only the scanner's supported formats and signatures; it does not establish artifact provenance, integrity, or absence of behavioral backdoors. ## LLM01:2026 Prompt Injection diff --git a/strix/skills/technologies/supabase.md b/strix/skills/technologies/supabase.md index 0bcdfc378..0a39f176c 100644 --- a/strix/skills/technologies/supabase.md +++ b/strix/skills/technologies/supabase.md @@ -35,7 +35,7 @@ Security testing for Supabase applications. Focus on mis-scoped Row Level Securi - Functions: `https://.functions.supabase.co/` **Headers** -- `apikey: ` — identifies project +- `apikey: ` — identifies the application component; legacy `anon` / `service_role` JWT keys can still coexist - `Authorization: Bearer ` — binds user context **Roles** @@ -45,6 +45,13 @@ Security testing for Supabase applications. Focus on mis-scoped Row Level Securi **Key Principle** `auth.uid()` returns current user UUID from JWT. Policies must never trust client-supplied IDs over server context. +### API Keys and Signing Keys + +- Opaque keys start with `sb_publishable_` or `sb_secret_`; JWT decoding will not classify them. Search bundles, server configuration, and responses for both formats. Publishable keys are intended for public clients; secret keys use `service_role` and bypass RLS. A browser 401 for a leaked secret key is not revocation: the browser restriction uses `User-Agent` and does not stop server-side use. +- Creating new keys does not disable legacy keys. After migration, test whether the old `anon` / `service_role` credential remains accepted; dashboard revocation is a separate action. Verify supported key formats and migration/deprecation status from project settings and current Supabase documentation ([API keys](https://supabase.com/docs/guides/getting-started/api-keys)). +- Edge Functions use user JWTs in `Authorization` and API keys in `apikey`. Verify the deployed platform's `verify_jwt` behavior with current docs and controlled requests, including API keys on either header; passing a platform check with a publishable key does not establish a signed-in user. Test whether the handler verifies user identity before using a privileged client. Conversely, `verify_jwt=false` with explicit secret-key or webhook verification is not necessarily public. Trace the configured `@supabase/server` auth mode or custom verification ([function authorization](https://supabase.com/docs/guides/functions/auth-headers)). +- Asymmetric signing keys are discoverable at `/auth/v1/.well-known/jwks.json`. Test custom API/Edge Function validators for issuer/algorithm binding and stale cached keys after rotation/revocation. Measure cache lifetimes from response headers, SDK configuration, and controlled rotation tests; check service-specific revocation behavior in current documentation rather than assuming platform and custom validators share a cache ([signing keys](https://supabase.com/docs/guides/auth/signing-keys)). + ## High-Value Targets - Tables with sensitive data (users, orders, payments, PII) diff --git a/strix/skills/vulnerabilities/agentic_system_security.md b/strix/skills/vulnerabilities/agentic_system_security.md index bdcb7410f..d87472ce8 100644 --- a/strix/skills/vulnerabilities/agentic_system_security.md +++ b/strix/skills/vulnerabilities/agentic_system_security.md @@ -106,10 +106,16 @@ Classify each discovered integration by data read, data write, external communic - For each tool, validate the same authorization and argument checks through every supported transport. - Treat server-launched subprocess configuration, environment variables, and working directories as sensitive executable configuration. - For HTTP/SSE transports, validate OAuth issuer, signature, expiry, audience/resource, tenant, and scope claims at the server boundary. Reject tokens minted for the wrong audience, and do not treat a session ID as identity. -- For downstream APIs, do not pass through the same bearer token unless the target explicitly authorizes that audience and principal. Separate upstream MCP authentication from downstream target authorization. +- MCP forbids token passthrough: reject access tokens not issued for the MCP server, and use a separate downstream authorization flow instead of forwarding a client's token to another API ([MCP authorization](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization)). - For browser or loopback OAuth, review redirect URI, state/PKCE handling, localhost binding, and consent proxying. Treat metadata fetches and tool discovery on remote servers as SSRF-relevant surfaces. - For stdio servers, the launch command and environment are already code execution. Discovery must not execute an unreviewed server binary or mutable package tag. +#### MCP Protocol Boundaries + +- Identify the protocol revision and client/server SDK builds from configuration and wire traffic, then consult the matching specification and current SDK advisories. Determine whether the transport uses initialization/session IDs or independent requests with client metadata and discovery. Test authorization on every request; client-supplied identity/capabilities in `_meta` are not authenticated identity. +- Where multi-round tool requests use `input_required` and `inputResponses`, trace the retry/resume binding. Test whether a response from another user, tool invocation, or approval round can be substituted, and whether a retry repeats a consequential action ([MCP protocol specification](https://blog.modelcontextprotocol.io/posts/2026-07-28/)). +- For OAuth callbacks, bind the expected issuer from validated discovery to the PKCE transaction. A present `iss` must match exactly, even if metadata did not advertise support; an absent `iss` must be rejected when `authorization_response_iss_parameter_supported` is true. Test issuer changes between discovery, registration, and callback, including error callbacks. Bind client credentials to their authorization-server issuer. Require the MCP server's `resource` in authorization and token requests and validate the token's audience at the server ([authorization requirements](https://modelcontextprotocol.io/specification/2026-07-28/basic/authorization)). + ### Executable Component Supply Chain Every skill, plugin, MCP server, model adapter, package, and update channel is an executable or behavior-shaping dependency. Record: @@ -158,7 +164,7 @@ npx @modelcontextprotocol/inspector@ --cli \ --method tools/list --format json ``` -- Current upstream requirements should be checked before pinning; as of August 12, 2026, MCP Inspector 2.1.0 requires Node.js `>=22.19.0`. +- Before choosing MCP Inspector, inspect package-registry metadata, engine requirements, release notes, and advisories. Select a compatible reviewed version and pin that exact version for the run; do not infer safety from a release tag. - Prefer CLI/TUI and loopback binding over exposing the web UI. - Preserve the generated API token; never disable authentication or bind the process-spawning backend to an external interface. - Do not publish ports 6274/6277 or pass through the Docker socket/host devices. @@ -173,7 +179,7 @@ npx @modelcontextprotocol/inspector@ --cli \ npx promptfoo@ eval ``` -- Current upstream engine constraints should be checked before pinning; as of August 12, 2026, Promptfoo documents Node.js `^20.20.0` or `>=22.22.0`. +- Resolve Promptfoo's runtime requirements, supported features, and security status from registry metadata and current upstream docs before choosing and pinning a version. - Use synthetic prompts/data and a dedicated test provider/project. - Provider calls transmit data externally and can incur cost even when evaluation orchestration is local. Set request/concurrency and spending ceilings. - Pin model, provider, prompt, tool schema, retrieval corpus revision, and evaluator versions. diff --git a/strix/skills/vulnerabilities/browser_security.md b/strix/skills/vulnerabilities/browser_security.md index 490147469..f76ffc641 100644 --- a/strix/skills/vulnerabilities/browser_security.md +++ b/strix/skills/vulnerabilities/browser_security.md @@ -104,6 +104,12 @@ Prove the strongest reliable capability first. If escalation requires a user ges - Treat scriptless disclosure of a nonce or trusted URL as a primitive; prove a second controllable sink before claiming bypass. - For response splitting, consider whether a same-origin endpoint can be turned into a script resource with a controlled body length or framing. +### Local Network and Loopback Access + +Identify the browser build, enabled flags, permission state, and enterprise policy; consult its current Local Network Access documentation and verify actual behavior with controlled requests. Test DNS rebinding and browser-to-local-service chains in both permission-denied and permission-granted states. A successful server-side request does not establish browser reachability ([Chrome LNA](https://developer.chrome.com/blog/local-network-access)). + +Discover which permission names and aliases the target supports, including `local-network`, `loopback-network`, and `local-network-access`. Record which destination class was permitted before claiming access to both LAN and localhost services ([permission reference](https://developer.chrome.com/release-notes/145#local_network_access_split_permissions)). + ### JavaScript Gadget Discovery - When direct calls are blocked, inspect implicit coercions (`toString`, `valueOf`, iterators, getters, proxies) and callbacks invoked by accessible library functions. diff --git a/strix/skills/vulnerabilities/http_request_smuggling.md b/strix/skills/vulnerabilities/http_request_smuggling.md index 5db2bd109..30660e396 100644 --- a/strix/skills/vulnerabilities/http_request_smuggling.md +++ b/strix/skills/vulnerabilities/http_request_smuggling.md @@ -97,6 +97,12 @@ transfer-encoding: chunked SMUGGLED ``` +### CL.0, 0.CL, and Double Desync + +In CL.0, the front end honors `Content-Length` while the back end ignores the body; in 0.CL the front end ignores it while the back end expects it. The latter commonly deadlocks until an early-response gadget responds without consuming the body and keeps the connection open. Test redirects and early errors for that specific connection behavior. A subsequent controlled request can expose the boundary shift; two successive desyncs can convert 0.CL into CL.0. A lone timeout or 400 does not establish that chain. + +Include `Expect: 100-continue` handling and interim/final response sequencing in differential tests. Calculate offsets from what the back end receives, including proxy-added headers. Use controlled follow-up requests to establish which bytes are consumed and which response belongs to each request ([HTTP/1.1 must die](https://portswigger.net/research/http1-must-die), [0.CL walkthrough](https://portswigger.net/blog/http-1-1-must-die-conquering-the-0-cl-challenge)). + ## Key Vulnerabilities ### Front-End Security Control Bypass diff --git a/strix/skills/vulnerabilities/insecure_deserialization.md b/strix/skills/vulnerabilities/insecure_deserialization.md index c0e2fcc21..a35346c01 100644 --- a/strix/skills/vulnerabilities/insecure_deserialization.md +++ b/strix/skills/vulnerabilities/insecure_deserialization.md @@ -79,6 +79,8 @@ JNDI injection is not itself a serialization format. It becomes part of this wor ### Python Pickle +**Model checkpoints:** `torch.load(..., weights_only=True)` does not rule out parser/storage memory corruption. Resolve the installed loader build and check current upstream advisories/backports before trusting that flag. Trace untrusted checkpoints through the exact loader and inspect safe-global allowlists ([example advisory](https://github.com/pytorch/pytorch/security/advisories/GHSA-63cw-57p8-fm3p)). + Pickle executes arbitrary code during unpickling by design: ```python import pickle, os, base64 @@ -101,13 +103,15 @@ When `yaml.load` used instead of `yaml.safe_load`. - POP chains through framework classes (Laravel, Symfony, WordPress plugins) **Phar Deserialization** -- Upload or reference `phar://` wrapper triggering metadata deserialization on file operations +- Trace `phar://` file operations and explicit `Phar::getMetadata()` / `PharFileInfo::getMetadata()` calls. Verify the installed PHP version's metadata-deserialization behavior and `allowed_classes` handling from source/docs; archive opening alone does not establish a deserialization sink ([migration reference](https://www.php.net/manual/en/migration80.incompatible.php#migration80.incompatible.phar)). ### .NET Deserialization **BinaryFormatter / LosFormatter** - Never safe on untrusted input; full RCE with known gadget chains (ysoserial.net) +Inspect the target framework and resolved serialization packages to establish whether `BinaryFormatter` executes, throws, or is restored through a compatibility package. Check the matching runtime documentation before choosing gadget chains; `LosFormatter` and other serializers are separate surfaces ([Microsoft guide](https://learn.microsoft.com/en-us/dotnet/standard/serialization/binaryformatter-migration-guide/)). + **Json.NET** ```json {"$type":"System.Windows.Data.ObjectDataProvider, PresentationFramework", ...} @@ -193,7 +197,7 @@ Payload generation is the practitioner's core tool here. The sandbox has `git`/` | **ysoserial** (frohoff) | Java native | Gadget-chain payloads: `CommonsCollections1-7`, `Groovy1`, `Spring1/2`, and `URLDNS` for a safe no-exec DNS oracle. Needs a JRE. | | **phpggc** (ambionics) | PHP `unserialize` / Phar | Framework POP chains (Laravel, Symfony, WordPress, Drupal, Monolog). Needs `php-cli`. | | **ysoserial.net** | .NET `BinaryFormatter` / Json.NET | Windows/.NET gadget payloads. Needs .NET/mono — usually out of scope in a Linux sandbox. | -| **marshalsec** | Java Hessian/Burlap, Kryo, JSON, and JNDI reference tooling | Use only from a reviewed, pinned upstream commit when a non-native Java marshaller requires it. It has no stable release and intentionally bundles historical gadget dependencies; do not treat it as a globally installed default tool. | +| **marshalsec** | Java Hessian/Burlap, Kryo, JSON, and JNDI reference tooling | Use only from a reviewed, pinned upstream commit when a non-native Java marshaller requires it. Check upstream release status and bundled gadget dependencies before selecting a commit; do not treat it as a globally installed default tool. | ``` # Java: prove the sink with a no-exec DNS oracle BEFORE any RCE chain diff --git a/strix/skills/vulnerabilities/nosql_injection.md b/strix/skills/vulnerabilities/nosql_injection.md index dda478fb3..18f9c539c 100644 --- a/strix/skills/vulnerabilities/nosql_injection.md +++ b/strix/skills/vulnerabilities/nosql_injection.md @@ -91,7 +91,7 @@ Binary search the character space to minimize requests. Works on any string fiel ### `$where` JavaScript Injection -If `$where` operator is enabled (disabled by default in MongoDB 7.0+; MongoDB 4.4–6.x deprecated it but left `javascriptEnabled` defaulting to `true`), inject arbitrary server-side JavaScript: +If `$where` is enabled, inject server-side JavaScript. Inspect `security.javascriptEnabled` / `--noscripting`, managed-service restrictions, and the installed engine version. Verify operator availability, defaults, and supported functions against that build's documentation or controlled probes; deprecation alone does not mean execution is disabled ([MongoDB documentation](https://www.mongodb.com/docs/manual/reference/operator/query/where/)): ```json {"$where": "function(){return this.role == 'admin'}"} // direct filter — returns matching documents {"$where": "function(){return this.username == 'admin' && sleep(2000)}"} // timing oracle only — sleep() returns undefined (falsy), so no documents are returned; observe latency diff --git a/strix/skills/vulnerabilities/path_traversal_lfi_rfi.md b/strix/skills/vulnerabilities/path_traversal_lfi_rfi.md index f04819af5..6de0b0e0d 100644 --- a/strix/skills/vulnerabilities/path_traversal_lfi_rfi.md +++ b/strix/skills/vulnerabilities/path_traversal_lfi_rfi.md @@ -148,6 +148,8 @@ Improper file path handling and dynamic inclusion enable sensitive file disclosu - Verify symlink handling and path canonicalization prior to write - Impact: overwrite config/templates or drop webshells into served directories +**Python extraction filters:** Determine the effective `filter` and `TarFile.extraction_filter` from the installed Python runtime, caller configuration, and matching documentation; verify patch/backport status against current advisories ([documentation](https://docs.python.org/3/library/tarfile.html#extraction-filters)). Filters do not eliminate link-handling bugs: test archive link ordering and post-extraction reads for outside-file disclosure or permission/timestamp changes, separately from content overwrite ([security advisory](https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/)). + ### File Write to Execution Characterize the write primitive before choosing a payload: diff --git a/strix/skills/vulnerabilities/prototype_pollution.md b/strix/skills/vulnerabilities/prototype_pollution.md index 145ed8ce2..21be5a8dc 100644 --- a/strix/skills/vulnerabilities/prototype_pollution.md +++ b/strix/skills/vulnerabilities/prototype_pollution.md @@ -51,7 +51,7 @@ Prototype pollution corrupts shared object prototypes (`Object.prototype`, `Arra **Common Sinks** - `lodash.merge`, `lodash.defaultsDeep`, `deep-extend`, `merge-options` - Express/query parsers accepting nested objects -- YAML `load()` (not `safeLoad`) with prototype keys +- YAML merge-key handling with prototype keys: identify the js-yaml version/schema and check applicable upstream advisories. Test whether `<<` merges alter the parsed result's prototype, then trace inherited values into a sensitive consumer; global `Object.prototype` modification is not required. Verify the installed API rather than assuming `load` versus `safeLoad` determines safety ([merge advisory](https://github.com/nodeca/js-yaml/security/advisories/GHSA-mh29-5h37-fv8m)). - JSON.parse → merge into existing object without null prototype **RCE Gadget Chains (Node.js)** diff --git a/strix/skills/vulnerabilities/ssti.md b/strix/skills/vulnerabilities/ssti.md index fdc66c052..c5f8d1cd1 100644 --- a/strix/skills/vulnerabilities/ssti.md +++ b/strix/skills/vulnerabilities/ssti.md @@ -76,6 +76,8 @@ When output isn't reflected: ### Jinja2 / Mako (Python) +**Jinja sandbox:** resolve the installed Jinja build and check current sandbox advisories before selecting indirect `str.format` or `|attr` gadgets. Establish template-source control and inspect custom filters; user data passed only as a variable is a different surface ([release notes](https://jinja.palletsprojects.com/en/stable/changes/)). + The classic Python class walk — every object exposes its method-resolution-order, which leads to `object`, which exposes every subclass loaded in the interpreter, which includes things like `subprocess.Popen`: ```jinja @@ -137,7 +139,7 @@ Twig sandbox bypasses are version-specific. The canonical historical gadget (Twi {{_self.env.registerUndefinedFilterCallback("system")}}{{_self.env.getFilter("id")}} ``` -This was patched — in Twig 2.x / 3.x `_self` returns the template name as a string and no longer exposes `.env`. Modern bypasses depend on which extensions are loaded and the active sandbox policy; consult Twig's published security advisories for the current state and probe with the version-specific gadgets (filter/function abuse, reflection on `_context` in some configs). +In Twig 2.x / 3.x, `_self` returns the template name as a string and does not expose `.env`. Bypasses depend on which extensions are loaded and the active sandbox policy; consult Twig's published security advisories and probe with the version-specific gadgets (filter/function abuse, reflection on `_context` in some configs). Smarty `{php}...{/php}` was the historical RCE primitive; deprecated in Smarty 3 and removed in 4. On modern Smarty, the surface is static-method invocation and template-object reflection — `{$smarty.template_object->smarty->...}` walks back to the Smarty engine, and direct static calls on whitelisted classes (e.g. `{Smarty_Internal_Write_File::writeFile(...)}` on misconfigured installs) reach the filesystem. Probe both before assuming Smarty is hardened. diff --git a/strix/skills/vulnerabilities/weak_password_detection.md b/strix/skills/vulnerabilities/weak_password_detection.md index c4d6c1140..d9e52979d 100644 --- a/strix/skills/vulnerabilities/weak_password_detection.md +++ b/strix/skills/vulnerabilities/weak_password_detection.md @@ -49,13 +49,15 @@ Weak or default credentials remain one of the most prevalent and high-impact vul ### Weak Password Policies -- No minimum length or complexity requirements +- Insufficient minimum length for the authentication mode; NIST SP 800-63B-4 requires 15 characters for single-factor passwords and permits a minimum of eight when the password is only used as part of MFA - Allowing common passwords: `password`, `123456`, `qwerty`, `admin`, `letmein` - Not checking against breached password databases (Have I Been Pwned) - Case-insensitive password storage -- No password history enforcement +- Forced periodic changes without compromise evidence, which encourage predictable password changes - Excessively short maximum length (indicates plaintext or weak hashing) +NIST SP 800-63B-4 recommends allowing a maximum of at least 64 characters and requires screening against common/compromised passwords and checking the entire password without truncation. Missing character-class rules is not a weakness: the standard prohibits mandatory composition rules and periodic resets without evidence of compromise. Apply these requirements when that standard is the target's policy baseline ([NIST SP 800-63B-4](https://pages.nist.gov/800-63-4/sp800-63b.html#passwordver)). + ### Default and Hardcoded Credentials - Vendor defaults: `admin/admin`, `admin/password`, `root/root`, `guest/guest` @@ -191,7 +193,7 @@ No password wordlists ship in the sandbox by default — download what you need 5. Test for password spraying (one password, many users) before targeted brute-force 6. Check for concurrent session limits; successful logins may kick out legitimate users 7. GraphQL batching can test multiple credentials in a single request, bypassing per-request limits -8. Document the password policy and recommend minimum standards (length, complexity, breach checking) +8. Document the password policy and recommend minimum standards (length appropriate to single-factor/MFA use, breach checking, and resistance to online guessing) 9. For web logins prefer `ffuf`; for other services use `nmap` NSE `*-brute` scripts or custom scripts with equivalent logic 10. Combine with MFA testing: weak passwords plus missing MFA is a critical finding diff --git a/strix/skills/vulnerabilities/xss.md b/strix/skills/vulnerabilities/xss.md index f9e3dd087..a17db5bb3 100644 --- a/strix/skills/vulnerabilities/xss.md +++ b/strix/skills/vulnerabilities/xss.md @@ -53,6 +53,10 @@ Cross-site scripting persists because context, parser, and framework edges are c ## Key Vulnerabilities +### DOMPurify Live-Node Sanitization + +Distinguish HTML-string input from live DOM objects sanitized with `IN_PLACE`. Resolve the deployed DOMPurify build and check relevant upstream advisories; a controlled observable `nodeName` is one live-node bypass mechanism. Trace same-origin foreign nodes or `adoptNode()` into this mode before selecting the bypass ([example advisory](https://github.com/cure53/DOMPurify/security/advisories/GHSA-x4vx-rjvf-j5p4)). + ### DOM XSS **Sources**