bookforge-session-management-security-assessmentSystematically assess web application session management for security vulnerabilities. Use when testing session token generation quality, cookie security con...
Install via ClawdBot CLI:
clawdbot install quochungto/bookforge-session-management-security-assessmentGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://cheatsheetseries.owasp.org/cheatsheets/Session_Management_Cheat_Sheet.htAudited Apr 28, 2026 · audit v1.0
Generated May 21, 2026
Analyze session token generation logic for predictability by reviewing source code using weak randomness like Math.random() or time-based algorithms. Identify vulnerabilities that allow attackers to predict tokens issued to other users, enabling session hijacking.
Check Set-Cookie headers and configuration files for missing Secure, HttpOnly, or SameSite flags, and overly broad domain or path scopes. Misconfigured cookies can expose session tokens to interception via network sniffing or client-side scripts.
Verify if the application accepts a pre-set session token from the attacker and fails to regenerate it upon user login. If vulnerable, an attacker can force a victim to use a known session ID and hijack the session after authentication.
Assess whether state-changing requests are protected by CSRF tokens, same-site cookies, or custom headers. Lack of CSRF protection allows attackers to perform actions on behalf of authenticated users without consent.
Evaluate if logout properly invalidates the session server-side and if idle/absolute timeouts are enforced. Weak logout can leave session tokens active, allowing reuse by attackers who obtained them.
Offer recurring or one-time authorized security assessments focused on session management vulnerabilities. Revenue is generated per assessment or via subscription for continuous testing.
Provide compliance-driven audits for standards like PCI-DSS, HIPAA, or OWASP ASVS, with detailed session security reports. Revenue comes from consulting fees for audit reports and remediation guidance.
Create educational content or automated scanning tools based on this skill to help developers identify session issues early. Revenue from course sales, training workshops, or tool licenses.
💬 Integration Tip
Automate input gathering using Grep and Bash to scan codebases for token generation and cookie configuration patterns, then use TodoWrite to track findings step by step.
Scored May 21, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...