Sean Nejad avatar

Sean Nejad

Community

@allsmog

9Followers
|
67Public Repos
|
17Published Skills

Security researcher & builder focused on ProdSec/AppSec, with interests in NatSec, OSINT, and applied security systems.

Agent Skills by Sean Nejad

Showing 17 vetted skills indexed across 1 GitHub repositories.

allsmogallsmog
22

Security Misconfiguration

Detect security misconfigurations across programming languages and frameworks.

Community
Intermediate
allsmogallsmog
22

OWASP 2025 Mapping

Map OWASP Top 10 2025 categories to CWEs with grep detection patterns.

Community
Basic
allsmogallsmog
22

Data Flow Tracing

Trace data from input sources to security-sensitive sinks in application codebases.

Community
Intermediate
allsmogallsmog
22

Workspace Discovery

Identifies and analyzes monorepo workspace structures across multiple programming languages and package managers for security scoping.

Community
Intermediate
allsmogallsmog
22

Exploit Techniques

Generate Python exploit templates for SQL and command injection vulnerabilities.

Community
Advanced
allsmogallsmog
22

Cache Poisoning

Detect HTTP cache poisoning and web cache deception vulnerabilities across proxies and CDNs.

Community
Advanced
allsmogallsmog
22

cpg-analysis

Trace data flows and verify vulnerabilities using Code Property Graphs and CPGQL.

Community
Advanced
allsmogallsmog
22

DOM XSS via postMessage

Detects DOM XSS vulnerabilities from insecure postMessage usage in JavaScript and TypeScript codebases.

Community
Intermediate
allsmogallsmog
22

Threat Modeling

Identify security threats via STRIDE analysis and data flow diagrams.

Community
Advanced
allsmogallsmog
22

Vulnerability Patterns

Identify web vulnerability patterns and exploitation flows for whitebox penetration testing.

Community
Intermediate
allsmogallsmog
22

Dangerous Functions

Identify security-sensitive functions and sinks across multiple programming languages.

Community
Advanced
allsmogallsmog
22

Cryptographic Failures

Detects cryptographic failures including weak hashing algorithms and insecure encryption across multiple languages.

Community
Intermediate
allsmogallsmog
22

Mixed-Language Monorepos

Audit security of polyglot monorepos with language detection and cross-service threat modeling.

Community
Advanced
allsmogallsmog
22

Exception Handling Vulnerabilities

Detect and mitigate exception handling vulnerabilities across Java, Python, PHP, Go, and TypeScript.

Community
Intermediate
allsmogallsmog
22

Sensitive Data Leakage

Detect sensitive data flow to logs, errors, and HTTP responses in Go, Python, Java, and JavaScript/TypeScript.

Community
Advanced
allsmogallsmog
22

Logging Failures

Detect logging failures and apply secure coding practices across Python, Java, Go, TypeScript, and PHP.

Community
Intermediate
allsmogallsmog
22

Business Logic Analysis

Analyze application business logic for flaws in workflows and trust boundaries.

Community
Advanced