Skip to content

Template catalog

What cxg can actually find. Every check in cert-x-gen-templates, the open-source template corpus, each one with a page setting out what it looks for and a link to the file it is written in.

Checks live at templates/<category>/<subject>/, one file per check, and the category set is fixed. See The template corpus for why. Each link below opens the table at the bottom of this page with that filter applied.

By category

ai · cli-baseline · databases · devops · messaging · monitoring · network · recon · tooling · web

By severity

critical · high · medium · low · info

By language

c · cpp · go · java · javascript · perl · php · python · ruby · rust · shell · yaml

By target kind

cli · http

A minority of templates declare @target_kinds. It is a convention of the templates repository rather than a field cxg’s parser reads, so a template without one is not restricted to any target. Its header does not say. The Target column below is blank for those.

By weakness class

Every CWE the corpus names, with the checks that name it.

Each row is read from the template file itself, never from a summary of it. For the eleven annotation languages that means the @field: header cxg parses out of the first 50 lines; for YAML templates it means the document’s own keys, because the YAML engine deserializes the document and never reads comments. The template schemas reference is the authority for both.

A blank cell means the file does not carry that field. It is not a gap this page filled in from somewhere else.

Template What it checks Language Severity Target Source
agent-extension-install-path-containment Agent extension installer joins untrusted skill/plugin names and archive members without containing them shell high cli file
agent-plugin-loader-conformance Agent-plugin launch client violates Agent Plugins 1.0 loader containment and executes load-time side effects shell high cli file
agent-skill-hidden-instruction-trust Agent skill executes a concealed directive with no consent boundary between loaded and executed python high cli file
ai-assisted-fuzzing-sqli-seed-corpus AI-Assisted Fuzzing SQLi Seed Corpus python info file
api-pull-access-check Unauthorized API Pull Access Check yaml critical file
claude-code-sed-bypass-usage Claude Code sed DSL Bypass Indicators (Static Scan) python medium file
coding-agent-command-trace-composition Coding-agent command validator approves a command trace whose composition executes a dangerous action shell high cli file
coding-agent-config-allowlist-trust Coding-agent CLI takes its command allowlist from attacker-writable configuration, or matches it by command name shell high cli file
coding-agent-cross-tool-config-bleed Coding agent honours another agent’s configuration, and one marketplace consent arms more than one agent shell high cli file
coding-agent-deny-rule-reachability A coding agent’s strongest deny rule is reachable around - the same protected file is read through syntactically different channels, and through a symlink swapped between check and use shell high cli file
coding-agent-git-config-exec Coding-agent CLI lets an untrusted workspace’s own .git/config execute code through its background git calls (GitSpawn) shell high cli file
coding-agent-hook-gate-integrity User-installed hook gate does not hold - a pre-execution security hook is bypassed, disarmed by repo-scoped config, or fails open shell high cli file
coding-agent-project-local-config-trust Coding-agent CLI executes project-local hooks from a world-writable workspace or a world-writable ancestor of one shell high cli file
coding-agent-repo-config-autoexec Coding-agent CLI honours repo-supplied configuration on first open, before any workspace-trust prompt shell high cli file
coding-agent-repo-config-credential-redirect Coding-agent CLI applies repo-supplied endpoint environment, sending its own API credential to a host the repository chose shell critical cli file
coding-agent-sandbox-perimeter-enforcement Declared agent sandbox is decorative - sandboxEnabled removes the human approval gate but does not confine the process shell high cli file
coding-agent-sandbox-trust-handoff Agent sandbox contains the process but not the files it writes - deferred consumers execute agent-authored surfaces after the sandbox exits shell high cli file
coding-agent-shared-config-trust Coding-agent CLI honours managed configuration from a world-writable shared path shell high cli file
coding-agent-workspace-interpreter-shadowing Coding-agent CLI runs an interpreter in an untrusted workspace whose files shadow the standard library shell high cli file
copilot-yolo-autoapprove-enabled GitHub Copilot YOLO Mode Enabled (Static Scan) python high file
cursor-mcpoison-config-risk Cursor MCP Config Command Risk (MCPoison) python high file
exposed-ollama-api-version Exposed Ollama API Version Endpoint yaml medium file
flowise-custommcp-command-endpoint-exposed Flowise CustomMCP Command Endpoint Exposed yaml critical file
flowise-custommcp-js-eval-exposed Flowise CustomMCP JS Eval Endpoint Exposed yaml critical file
invokeai-model-install-exposed InvokeAI Unauthenticated Model Install Endpoint yaml critical file
mcp-broken-token-validation MCP Broken Token Validation (Accepts Forged Tokens) python high file
mcp-cache-scope-identity-leak MCP CacheableResult Cross-Identity Leak (identity-dependent response marked publicly cacheable) python high http file
mcp-child-env-inheritance MCP host hands a locally-spawned stdio server the operator’s entire environment shell high cli file
mcp-client-header-value-encoding MCP Client x-mcp-header Value-Encoding Failure (Model-Controlled HTTP Header Injection) python high cli file
mcp-client-mrtr-conformance MCP Client MRTR Conformance (inputRequests Provenance Boundary and the resultType Default) python high cli file
mcp-client-oauth-issuer-binding MCP Client OAuth Issuer Binding (Authorization-Server Mix-Up / Cross-Issuer Credential Reuse) python high cli file
mcp-client-untrusted-annotation-approval MCP Client Auto-Approves a Tool on an Untrusted Server’s readOnlyHint Annotation python high cli file
mcp-credential-exposure MCP Credential / Secret Exposure via Resources python critical http file
mcp-excessive-scope-proof MCP Out-of-Scope Tool Action (Behavioural Scope Proof) python high http, cli file
mcp-excessive-tool-permissions MCP Excessive Tool Permissions (Dangerous Capability Exposure) python high file
mcp-handle-binding-integrity MCP Handle Binding and requestState Integrity (Stateless Core) python high http, cli file
mcp-invisible-unicode-poisoning MCP Invisible-Unicode Tool Poisoning (Approval-View Fidelity Gap) python high http file
mcp-manifest-runtime-divergence MCP Declared-Manifest / Runtime-Surface Divergence python high http file
mcp-method-desync MCP Routing-Header / Body Method Desync (Gateway Authz Bypass) python high http file
mcp-oauth-consent-dcr-abuse MCP OAuth Consent-Layer Confused Deputy via Open Dynamic Client Registration python high http file
mcp-rug-pull-detection MCP Rug Pull (Silent Tool Definition Mutation) python high file
mcp-token-audience-confusion MCP Token Passthrough / Audience Confusion (Confused Deputy) python high http file
mcp-tool-poisoning MCP Tool Poisoning (Model-Directed Instructions in Tool Metadata) python high http file
mcp-unauthenticated-access Unauthenticated MCP Server Exposure python high file
ml-unsafe-deserialization-usage ML Unsafe Deserialization Usage (Static Scan) python medium file
ollama-unauth-api-generate Ollama Unauthenticated /api/generate Access yaml high file
pytorch-unsafe-load-usage PyTorch Unsafe torch.load Usage (Static Scan) python high file
torchserve-management-api-exposed TorchServe Management API Exposed yaml high file
triton-model-control-exposed NVIDIA Triton Model Repository Control Exposed yaml high file
Template What it checks Language Severity Target Source
cli-baseline-b01-argument-injection CLI Baseline B01 - argument injection via un-separated argv shell high cli file
cli-baseline-b02-command-injection CLI Baseline B02 - OS command injection through an argument shell critical cli file
cli-baseline-b03-path-traversal CLI Baseline B03 - path traversal in a file-naming argument shell high cli file
cli-baseline-b04-archive-traversal CLI Baseline B04 - zip-slip / archive extraction traversal shell high cli file
cli-baseline-b05-argv-secrets CLI Baseline B05 - credentials exposed in the process table shell high cli file
cli-baseline-b06-insecure-temp-files CLI Baseline B06 - insecure temporary file creation shell medium cli file
cli-baseline-b07-path-hijack CLI Baseline B07 - untrusted search path / PATH hijack shell high cli file
cli-baseline-b08-terminal-escape CLI Baseline B08 - terminal escape sequence injection shell medium cli file
cli-baseline-b09-environment-trust CLI Baseline B09 - unvalidated trust in environment variables shell medium cli file
cli-baseline-b10-config-credential-handling CLI Baseline B10 - insecure config and credential file handling shell high cli file
cli-baseline-b11-memory-safety CLI Baseline B11 - memory-safety defect (instrumentation-dependent) shell critical cli file
cli-baseline-b12-crash-hang CLI Baseline B12 - crash or hang on malformed input shell medium cli file
cli-baseline-b13-toctou-symlink-race CLI Baseline B13 - TOCTOU / symlink race shell high cli file
cli-baseline-b14-format-string CLI Baseline B14 - format-string defect shell high cli file
Template What it checks Language Severity Target Source
clickhouse-auth-bypass ClickHouse Authentication Bypass python high file
cockroachdb-unauthenticated-access CockroachDB Unauthenticated Access Detection yaml critical file
couchdb-default-credentials CouchDB Default Credentials Detection rust critical file
elasticsearch-data-exposure Elasticsearch Cluster Data Exposure python critical file
elasticsearch-query-injection Elasticsearch Query DSL Injection Detector python high file
elasticsearch-unauthenticated Elasticsearch Unauthenticated Access Detection rust critical file
influxdb-health-exposed InfluxDB Health Endpoint Exposed yaml medium file
memcached-unauthenticated-access Memcached Unauthenticated Access Detection yaml critical file
mongodb-injection-deep MongoDB NoSQL Injection Deep Analysis python high file
mongodb-unauthenticated MongoDB Unauthenticated Access Detection python critical file
mysql-default-credentials MySQL Default/Weak Credentials Detection python critical file
postgresql-default-credentials PostgreSQL Default Credentials Detection go critical file
postgresql-extension-rce postgresql extension rce python medium file
redis-cluster-takeover Redis Cluster Takeover Detection go critical file
redis-unauthenticated-access Redis Unauthenticated Access Detection yaml critical file
redis-unauthenticated-c Redis Unauthenticated Access Detection (C) c critical file
redis-unauthenticated-cpp Redis Unauthenticated Access Detection (C++) cpp critical file
redis-unauthenticated-go Redis Unauthenticated Access Detection (Go) go critical file
redis-unauthenticated-java Redis Unauthenticated Access Detection (Java) java critical file
redis-unauthenticated-javascript Redis Unauthenticated Access Detection (JavaScript) javascript critical file
redis-unauthenticated-perl Redis Unauthenticated Access Detection (Perl) perl critical file
redis-unauthenticated-php Redis Unauthenticated Access Detection (PHP) php critical file
redis-unauthenticated-python Redis Unauthenticated Access Detection (Python) python critical file
redis-unauthenticated-ruby Redis Unauthenticated Access Detection (Ruby) ruby critical file
redis-unauthenticated-rust Redis Unauthenticated Access Detection (Rust) rust critical file
redis-unauthenticated-shell Redis Unauthenticated Access Detection (Shell) shell critical file
Template What it checks Language Severity Target Source
actions-injection-scanner GitHub Actions Injection Scanner python high file
ci-variable-exposure CI/CD Variable Exposure Detection python critical file
docker-api-unauth Docker API Unauthenticated Access go critical file
docker-registry-unauthenticated Docker Registry Unauthenticated Access Detection shell high file
etcd-auth-check Etcd Authentication Check yaml info file
etcd-instead-http-request Etcd Member List Security Check yaml medium file
etcd-running-unauthenticated-port Unauthenticated etcd Service Detection shell critical file
etcd-think-path-wrong Etcd Unauthenticated Access yaml medium file
etcd-unauth Etcd Unauthenticated Access - Members List yaml high file
etcd-unauthenticated Etcd Unauthenticated Member List Detection shell high file
etcd-unauthenticated-access Etcd Unauthenticated Access - Version Endpoint yaml medium file
ghes-version-fingerprint GitHub Enterprise Server Version Fingerprint python info file
git-history-secret-scan Git History Secret Scan go critical file
gitlab-version-fingerprint GitLab Version Fingerprint python info file
helm-chart-secrets-leak Helm Chart Secrets Leak Detection python high file
istio-pilot-misconfiguration Istio Pilot Misconfiguration Detection go high file
jenkins-unauth-rce Jenkins Unauthenticated Script Console RCE go critical file
jupyter-unauth-rce Jupyter Notebook Unauthenticated RCE python critical file
k8s-etcd-exposed Kubernetes etcd Secrets Exposure go critical file
k8s-rbac-misconfiguration Kubernetes RBAC Misconfiguration Detection go critical file
kubelet-api-exposure Kubelet API Exposure Detection go critical file
kubernetes-api-unauthenticated Kubernetes API Unauthenticated Access yaml critical file
pwn-request-scanner GitHub Actions Pwn Request Scanner python critical file
runner-token-detection runner token detection go medium file
saml-sso-bypass-gitlab saml sso bypass gitlab python medium file
service-account-token-abuse Kubernetes Service Account Token Abuse go critical file
Template What it checks Language Severity Target Source
kafka-unauthenticated Apache Kafka Unauthenticated Access Detection shell high file
kafka-unauthenticated-access Kafka Unauthenticated Access Detection python critical file
mqtt-unauthenticated MQTT Unauthenticated Access (CONNACK Accepted) yaml high file
nats-unauthenticated-banner NATS Banner Indicates No Authentication yaml medium file
rabbitmq-default-credentials RabbitMQ Default Credentials Detection python critical file
rabbitmq-management-exposed RabbitMQ Management UI Exposed yaml medium file
zookeeper-unauthenticated-access Apache Zookeeper Unauthenticated Access yaml critical file
Template What it checks Language Severity Target Source
cadvisor-exposed-javascript cAdvisor Exposed Without Authentication javascript critical file
cadvisor-exposed-python cAdvisor Metrics Exposed python medium file
check-metrics-endpoint Check /metrics Endpoint Exposure yaml medium file
kibana-api-status-exposed Kibana /api/status Exposed yaml medium file
mysql-exporter-exposed MySQL Exporter Metrics Exposed python medium file
node-exporter-exposed-javascript Node Exporter Exposed Without Authentication javascript high file
node-exporter-exposed-python Node Exporter Metrics Exposed python medium file
postgresql-exporter-exposed PostgreSQL Exporter Metrics Exposed python medium file
prometheus-node-exporter-exposed Prometheus Node Exporter Exposed Without Authentication yaml high file
prometheus-server-exposed-https Prometheus Server Exposed (HTTPS) python high file
prometheus-server-exposed-javascript Prometheus Server Exposed Without Authentication javascript high file
prometheus-server-exposed-python Prometheus Server Exposed python high file
redis-exporter-exposed Redis Exporter Exposed Detection yaml medium file
redis-exporter-exposed-python Redis Exporter Metrics Exposed python high file
splunk-web-login-exposed Splunk Web Login Exposed yaml medium file
splunkd-server-info-exposed Splunkd Server Info Exposed yaml high file
Template What it checks Language Severity Target Source
adb-exposed ADB Over TCP Exposed yaml high file
dhcpv6-solicit-response DHCPv6 Solicit Response Probe python info file
dns-rebinding-attack DNS Rebinding Attack Detection go critical file
dns-udp-service-probe DNS UDP Service Probe python info file
dns-zone-transfer DNS Zone Transfer (AXFR) Detection python high file
echo-service-exposed Echo Service Exposed yaml low file
epmd-node-list-exposed EPMD Node List Exposed yaml medium file
finger-service-exposed Finger Service Exposed yaml low file
ftp-anonymous-access FTP Anonymous Access Detection python high file
grpc-reflection-abuse gRPC Reflection API Exposure Detection go high file
http-service-responding HTTP Service Responding yaml info file
icmp-echo-reachable ICMP Echo Reachability python info file
ident-exposed Ident Service Exposed yaml low file
mdns-service-discovery-probe mDNS Service Discovery Probe python info file
nbns-name-query-probe NBNS Name Query Probe python info file
ndmp-service-exposed NDMP Service Exposed yaml medium file
ntp-udp-service-probe NTP UDP Service Probe python info file
port-scanner-async High-Speed Async TCP Port Scanner rust info file
rmi-service-enumeration RMI Service Enumeration java high file
rsync-banner-exposed Rsync Daemon Banner Exposed yaml medium file
smart-install-exposed Cisco Smart Install Exposed yaml high file
smtp-open-relay SMTP Open Relay Detection python high file
snmp-default-community SNMP Default Community String Detection shell high file
socks5-no-auth SOCKS5 No-Authentication Proxy yaml high file
ssdp-msearch-response SSDP M-SEARCH Response Probe python info file
tacacs-service-exposed TACACS+ Service Exposed yaml medium file
tcp-banner-probe TCP Banner Probe python info file
tcp-port-reachability TCP Port Reachability python info file
tftp-service-exposed TFTP Service Exposed yaml medium file
tls-certificate-deep-analysis TLS Certificate Deep Analysis rust high file
vnc-no-auth VNC No Authentication Detection c critical file
websocket-message-fuzzer websocket message fuzzer javascript medium file
whois-service-exposed WHOIS Service Exposed yaml low file
wsd-probe-response WSD Probe Response python info file
Template What it checks Language Severity Target Source
system-context-recon System Context Reconnaissance shell info file
Template What it checks Language Severity Target Source
supply-chain-install-credential-access Supply chain - install-time credential access and workflow planting shell critical cli file
supply-chain-install-hook-behavior Supply chain - install and import-time hook behaviour shell critical cli file
Template What it checks Language Severity Target Source
auth-bypass-flow Authentication Bypass with Session Flow yaml critical file
auth-token-logout-reuse Authentication Token Reuse After Logout python high file
deserialization-gadget-scan Deserialization Gadget Scan java critical file
directory-listing-common-paths Directory Listing Exposure (Common Paths) yaml medium file
directory-traversal Directory Traversal Detection c high file
example-http-check Example HTTP Security Check yaml info file
forced-browse-auth-bypass Forced Browse Auth Bypass — Protected Endpoints Without Auth python high file
graphql-user-enumeration GraphQL User Enumeration (CVE-2021-4191) python medium file
http-header-injection HTTP Header Injection Detection python medium file
http-service-detection HTTP Service Detection yaml info file
http2-rapid-reset HTTP/2 Rapid Reset Detection (CVE-2023-44487) go critical file
idor-bola-horizontal IDOR / BOLA Horizontal Privilege Escalation python high file
jwt-alg-confusion JWT Algorithm Confusion (RS256 → HS256 / none) python critical file
jwt-role-tampering JWT Role / Privilege Claim Tampering python critical file
log4shell-detection Log4Shell (CVE-2021-44228) Vulnerability Detection shell critical file
mass-assignment-update Mass Assignment via Profile / Object Update Endpoint python high file
password-reset-enum Password Reset User Enumeration via Response Differences python medium file
password-reset-takeover password reset takeover python medium file
prototype-pollution prototype pollution javascript medium file
race-condition-exploit Race Condition Detection (TOCTOU) go critical file
rate-limit-auth-bypass Missing or Bypassable Rate Limit on Authentication Endpoint python high file
response-integrity-audit Response Integrity Audit (Cache Poisoning & HPP) yaml medium file
sensitive-data-exposure Sensitive Data Exposure Detection yaml medium file
server-side-js-injection server side js injection javascript medium file
session-fixation-check Session Fixation — Token Unchanged After Login python high file
spring4shell-detection Spring4Shell Detection (CVE-2022-22965) java critical file
sql-injection-basic SQL Injection Detection (Basic) yaml critical file
sql-injection-detection-c SQL Injection Detection c critical file
ssti-engine-fingerprint Server-Side Template Injection Engine Fingerprint python high file
timing-attack-detection Blind SQL Injection (Time-Based) yaml high file
vertical-privesc-admin Vertical Privilege Escalation to Admin Endpoints python critical file
xss-detection-c Cross-Site Scripting (XSS) Detection c high file