Skip to content

Add browser print export redaction review skill#2267

Open
tiandashu wants to merge 1 commit into
UnitOneAI:mainfrom
tiandashu:new-skill/browser-print-export-redaction-review
Open

Add browser print export redaction review skill#2267
tiandashu wants to merge 1 commit into
UnitOneAI:mainfrom
tiandashu:new-skill/browser-print-export-redaction-review

Conversation

@tiandashu

Copy link
Copy Markdown

Summary

  • add a new browser-print-export-redaction-review AppSec skill for print, PDF, CSV/XLSX/JSON, clipboard, and scheduled report export paths
  • cover redaction bypasses where exports expose raw fields that are masked or hidden on screen
  • add reason codes for raw print output, broad API serialization, CSS-only masking, missing field-level auth, service-scope scheduled exports, and weak audit trails
  • add 3 vulnerable and 3 benign YAML fixtures

Closes #590

Validation

  • git diff --check
  • Parsed 6 YAML fixtures under skills/appsec/browser-print-export-redaction-review/tests
  • Checked required markers: PRINT-EXPORT-01, PRINT-EXPORT-06, redaction matrix, common pitfalls, OWASP ASVS references

Bounty Info

Requested bounty: $200 (new standard skill)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[NEW SKILL] browser-print-export-redaction-review

1 participant