OWASP Top 10 Triage
Map a change to OWASP risks quickly.
Free market · one skill at a time
214 free skills. Open a skill page to read the full system, then download a single .md. No bulk zip dumps — then go deep with $50 Ultimate packs.
Browse & filter below → · open any card for a full SEO preview
No skills match
Try another category or clear search.
Map a change to OWASP risks quickly.
Find IDOR and missing authZ.
Session, JWT, password flows checklist.
alg, kid, expiry, audience mistakes.
URL fetch sinks and allowlists.
Find HTML/JS sinks and encoding gaps.
Parameterized queries vs string build.
Cookie sessions and state-changing POSTs.
Type, size, storage, execution risks.
Unexpected writable fields.
Auth and expensive endpoints.
CSP, HSTS, frame options basics.
Origins and credentials.
Redirect params to safe allowlists.
File path params and downloads.
Untrusted pickle/JSON gadgets notes.
Field and object checks.
Secrets, replay, raw body verify.
Token entropy and host header.
Discover and lock admin surfaces.
Overbroad roles and keys.
Public ACL and policy mistakes.
Find committed tokens patterns.
Untrusted PR risks.
Root, capabilities, read-only.
ClusterRole binding risks.
169.254.169.254 paths.
Open SG, public IPs.
Redact tokens in logs.
Offline backups and restore test.
What WAF helps vs false safety.
Dangling CNAME checks.
Old protocols and ciphers.
Lockfiles and suspicious installs.
Safe defaults under attack.
Assets, actors, entrypoints.
Allowlists at boundaries.
Context-aware encoding.
Don't roll your own.
Token entropy requirements.
No stack traces to users.
Tenant id in every query.
Idempotency and webhooks.
Redirect URI exact match.
Rotate on login.
Zip bombs and XXE class.
Unsafe merge of JSON.
No shell with user input.
TOCTOU on money/inventory.
Flags default deny.
Severity and false positive notes.
What must be logged.
Contain, communicate, evidence.
Headers and IOCs carefully.
Lab only rules.
Disk encrypt, updates, least admin.
Spoof resistance checklist.
Signals and lockouts.
Unusual egress patterns.
Backups, IR contacts, offline copies.
Exploitability over CVSS alone.
Honest B2B security answers.
Run a 60m incident game.
Who still needs prod access.
Rotate leaked API keys.
Write a clean ROE scope.
Recon methods for owned labs.
Practice order on DVWA-like labs.
Exec summary + technical proof.
Prove a fix actually fixed.
Only your hashes in lab.
Own hardware only.
In-scope vs out-of-scope discipline.
Minimal PoC without damage.
Turn test into hardening backlog.
What PII you store where.
How long logs and PII live.
Ask SaaS vendors the right things.
Kill tokens same day.
Phased MFA without lockout chaos.
Embed security in eng teams.
Short AUP people read.
Who to tell and when (high level).
Likelihood impact owner.
When security review is mandatory.
How customers should store keys.
No secrets in mobile binaries.
Untrusted content into tools.
Never let LLM hit prod unchecked.
Security Roadmap 90 Days
Threat Model Before Feature
AuthZ Matrix From Routes
Secure PR Checklist Strict
Secret and Log Leak Scan
Dependency Diff Risk Review
Incident First Hour Lite
Keep changes minimal and reviewable.
Plan when 3+ files may change.
Commit messages from real diffs.
Blockers vs nits with paths.
Repro -> isolate -> fix -> regress.
Red-green for pure logic.
Behavior-preserving mechanical steps.
AuthZ, validation, errors.
Nullability, expand/contract.
Never leak tokens to chat/logs.
Teach a file in plain English.
Read breaks before upgrade.
User-safe errors + loggable detail.
Labels, keyboard, focus basics.
Find obvious hot spots.
Plan bisect for regressions.
User-facing changelog.
Map folders and entrypoints.
Replace any with safe types.
When to use client components.
Validate at edges.
Structured logs without PII spam.
Safe defaults and kill switch.
List likely dead exports carefully.
Definition of done for a slice.
Build a tight CLAUDE/AGENTS memory.
Capture a decision with consequences.
Owners and dates from notes.
Questions and experiments first.
Impact, facts, hypothesis labels.
Day-one path for a contractor.
Stable vs volatile prompt parts.
Score outputs 1-5 on a rubric.
When to call tools vs reason.
What to delete from project memory.
Go/no-go with clear signals.
Problem, deliverables, out-of-scope, price.
Lock success metric and access.
Done/Doing/Blocked/Decision/Next.
Price the quick favor.
Polite to pause cadence.
Hours, response, boundaries.
Firm no without burning bridge.
30-minute diagnose call.
WhatsApp pushback lines.
Short ask + prompts.
Good/better/best without lies.
Two-flag rule.
Rules from sample posts.
Eight structural hooks.
Lead with the answer.
One idea to eight assets.
Cut AI tells and filler.
Slide jobs + CTA.
Hook body CTA visuals.
One idea one story one CTA.
7 days themes.
Kill or double-down.
Entities FAQs links - no stuffing.
Curiosity without clickbait lies.
Budget authority need timing lite.
Pain impact decision process.
Their pain not feature tour.
Value carve walk-away.
Next step or nurture.
Proof and honest risk reverse.
No just checking in.
One clear ask.
Weekly deal truth.
Learn without delusion.
Pick register by market/channel.
UAE/KSA polite commercial tone.
Scroll-stopping first lines.
Benefit proof price CTA.
Acknowledge next step truth.
Catch machine translation tells.
Respectful seasonal offers.
Faithful gloss not reverse-write.
Secret header + validate body.
Keys so retries do not double-send.
Alert without PII spam.
Dedupe keys and limits.
domain/action/env names.
Schema check before side effects.
Dev to prod without live-edit.
Purpose trigger owner replay.
Weekly review of systems.
Share learnings without leaking secrets.
Problem approach result proof.
Ask For Help Well
Systematic Debugging Loop
Verification Before Ship
Test-Driven Micro Loop
Writing Implementation Plans
Parallel Agent Dispatch
Receiving Code Review Well
Git Worktree Isolation
Finishing a Branch Cleanly
Project Memory Hygiene
Choose the smallest set of files/logs that let the model do the job without drowning.
Debug by asking sharp questions that force clarity — before writing code.
Score agent outputs with a simple rubric so quality doesn't drift week to week.
Run a discovery call that qualifies fit, budget, timeline, and red flags in 30 minutes.
Freeze scope after kickoff and route new asks through a calm change-order path.
Weekly status in five lines clients actually read — progress, risks, asks, next.
Collect late payment with escalating, calm messages that keep the relationship.
Open with the answer, then proof — kill buried ledes and AI throat-clearing.
Strip generic AI phrasing so the piece sounds like a specific human with a point of view.
One idea becomes eight platform-native assets without diluting the point.
Qualify budget, authority, need, timeline in short WhatsApp/email threads without interrogation vibes.
Handle 'too expensive' with calm value math — not discounts as a reflex.
Close a simple digital offer in three short WA messages without sleaze.
Choose Gulf / Egyptian / Fusha (or dual) before generating Arabic copy — prevent cringe mix.
Catch machine-translation tells and cultural misses before Arabic goes live.
Design webhook handlers that safe-retry without double side effects.
Alert on actionable failures — silence noise that trains humans to ignore pages.
30-minute weekly review: what multiplied you, what wasted you, what to automate or skill-ify.
Audit which AI skills you actually use vs collect — prune and sequence learning.
Cyber skills: authorized use only.
Ready for depth?
Staff OS, security, revenue, content, automation, Arabic GTM, evals, crisis, leverage — depth above the free library.
Web pentest method, API deep dive, cloud, secure code review, IR, AppSec program, LLM appsec.