007
Provides comprehensive security audits, threat modeling, and incident response for projects, ensuring robust infrastructure security.
Install this skill
Security score
The 007 skill was audited on May 14, 2026 and we found 23 security issues across 3 threat categories, including 4 critical. Review the findings below before installing.
Categories Tested
Security Issues
Direct command execution function call
| 207 | - [ ] Nenhum uso de eval(), exec() com input externo |
Direct command execution function call
| 386 | - Novo codigo contendo `eval()`, `exec()`, `subprocess`, `os.system()` |
Eval function call - arbitrary code execution
| 207 | - [ ] Nenhum uso de eval(), exec() com input externo |
Eval function call - arbitrary code execution
| 386 | - Novo codigo contendo `eval()`, `exec()`, `subprocess`, `os.system()` |
System command execution
| 386 | - Novo codigo contendo `eval()`, `exec()`, `subprocess`, `os.system()` |
Node child_process module reference
| 125 | - Onde ha execucao de codigo (eval, exec, subprocess, child_process) |
Python os.system command execution
| 386 | - Novo codigo contendo `eval()`, `exec()`, `subprocess`, `os.system()` |
Webhook reference - potential data exfiltration
| 52 | | **APIs** | REST, GraphQL, OAuth, JWT, webhooks, CORS, rate limit | |
Webhook reference - potential data exfiltration
| 54 | | **Pagamentos** | PCI-DSS mindset, antifraude, idempotencia, webhooks financeiros | |
Webhook reference - potential data exfiltration
| 114 | - De onde vem dados? (usuario, API, arquivo, banco, agente, webhook) |
Webhook reference - potential data exfiltration
| 153 | | **S**poofing | Alguem pode se passar por outro? | Token roubado, webhook falso | |
Webhook reference - potential data exfiltration
| 222 | - [ ] Assinatura de webhooks verificada |
Webhook reference - potential data exfiltration
| 390 | - Configuracao de API, webhook ou autenticacao sendo alterada |
Webhook reference - potential data exfiltration
| 408 | | **whatsapp-cloud-api** | 007 verifica compliance, anti-ban, seguranca de webhooks | |
Webhook reference - potential data exfiltration
| 410 | | **telegram** | 007 verifica seguranca de bot, token storage, webhook validation | |
Webhook reference - potential data exfiltration
| 521 | ## Playbook: Webhook Falso / Replay Attack |
Webhook reference - potential data exfiltration
| 528 | - Suspender processamento de webhooks |
Webhook reference - potential data exfiltration
| 532 | - Quais webhooks foram aceitos indevidamente? |
Webhook reference - potential data exfiltration
| 533 | - Houve acao financeira baseada em webhook falso? |
Webhook reference - potential data exfiltration
| 543 | - Assinatura obrigatoria em TODOS os webhooks |
Webhook reference - potential data exfiltration
| 546 | - Alertas para webhooks de fontes desconhecidas |
Webhook reference - potential data exfiltration
| 619 | - `references/payment-security.md` — PCI-DSS, antifraude, webhooks financeiros |
Access to .env file
| 387 | - Arquivo `.env` ou segredo sendo commitado/modificado |