Template catalog
What cxg can actually find. Every check in cert-x-gen-templates, the open-source template corpus, each one with a page setting out what it looks for and a link to the file it is written in.
Browse
Section titled “Browse”Checks live at templates/<category>/<subject>/, one file per check, and
the category set is fixed. See
The template corpus for why. Each link
below opens the table at the bottom of this page with that filter applied.
By category
ai · cli-baseline · databases · devops · messaging · monitoring · network · recon · tooling · web
By severity
critical · high · medium · low · info
By language
c · cpp · go · java · javascript · perl · php · python · ruby · rust · shell · yaml
By target kind
A minority of templates declare @target_kinds. It is a convention of the
templates repository rather than a field cxg’s parser reads, so a template
without one is not restricted to any target. Its header does not say. The
Target column below is blank for those.
By weakness class
Every CWE the corpus names, with the checks that name it.
Where these fields come from
Section titled “Where these fields come from”Each row is read from the template file itself, never from a summary of it.
For the eleven annotation languages that means the @field: header cxg
parses out of the first 50 lines; for YAML templates it
means the document’s own keys, because the YAML engine deserializes the
document and never reads comments. The
template schemas reference is the
authority for both.
A blank cell means the file does not carry that field. It is not a gap this page filled in from somewhere else.
Templates
Section titled “Templates”No template matches those filters.
| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
agent-extension-install-path-containment |
Agent extension installer joins untrusted skill/plugin names and archive members without containing them | shell |
high | cli |
file |
agent-plugin-loader-conformance |
Agent-plugin launch client violates Agent Plugins 1.0 loader containment and executes load-time side effects | shell |
high | cli |
file |
agent-skill-hidden-instruction-trust |
Agent skill executes a concealed directive with no consent boundary between loaded and executed | python |
high | cli |
file |
ai-assisted-fuzzing-sqli-seed-corpus |
AI-Assisted Fuzzing SQLi Seed Corpus | python |
info | file | |
api-pull-access-check |
Unauthorized API Pull Access Check | yaml |
critical | file | |
claude-code-sed-bypass-usage |
Claude Code sed DSL Bypass Indicators (Static Scan) | python |
medium | file | |
coding-agent-command-trace-composition |
Coding-agent command validator approves a command trace whose composition executes a dangerous action | shell |
high | cli |
file |
coding-agent-config-allowlist-trust |
Coding-agent CLI takes its command allowlist from attacker-writable configuration, or matches it by command name | shell |
high | cli |
file |
coding-agent-cross-tool-config-bleed |
Coding agent honours another agent’s configuration, and one marketplace consent arms more than one agent | shell |
high | cli |
file |
coding-agent-deny-rule-reachability |
A coding agent’s strongest deny rule is reachable around - the same protected file is read through syntactically different channels, and through a symlink swapped between check and use | shell |
high | cli |
file |
coding-agent-git-config-exec |
Coding-agent CLI lets an untrusted workspace’s own .git/config execute code through its background git calls (GitSpawn) | shell |
high | cli |
file |
coding-agent-hook-gate-integrity |
User-installed hook gate does not hold - a pre-execution security hook is bypassed, disarmed by repo-scoped config, or fails open | shell |
high | cli |
file |
coding-agent-project-local-config-trust |
Coding-agent CLI executes project-local hooks from a world-writable workspace or a world-writable ancestor of one | shell |
high | cli |
file |
coding-agent-repo-config-autoexec |
Coding-agent CLI honours repo-supplied configuration on first open, before any workspace-trust prompt | shell |
high | cli |
file |
coding-agent-repo-config-credential-redirect |
Coding-agent CLI applies repo-supplied endpoint environment, sending its own API credential to a host the repository chose | shell |
critical | cli |
file |
coding-agent-sandbox-perimeter-enforcement |
Declared agent sandbox is decorative - sandboxEnabled removes the human approval gate but does not confine the process | shell |
high | cli |
file |
coding-agent-sandbox-trust-handoff |
Agent sandbox contains the process but not the files it writes - deferred consumers execute agent-authored surfaces after the sandbox exits | shell |
high | cli |
file |
coding-agent-shared-config-trust |
Coding-agent CLI honours managed configuration from a world-writable shared path | shell |
high | cli |
file |
coding-agent-workspace-interpreter-shadowing |
Coding-agent CLI runs an interpreter in an untrusted workspace whose files shadow the standard library | shell |
high | cli |
file |
copilot-yolo-autoapprove-enabled |
GitHub Copilot YOLO Mode Enabled (Static Scan) | python |
high | file | |
cursor-mcpoison-config-risk |
Cursor MCP Config Command Risk (MCPoison) | python |
high | file | |
exposed-ollama-api-version |
Exposed Ollama API Version Endpoint | yaml |
medium | file | |
flowise-custommcp-command-endpoint-exposed |
Flowise CustomMCP Command Endpoint Exposed | yaml |
critical | file | |
flowise-custommcp-js-eval-exposed |
Flowise CustomMCP JS Eval Endpoint Exposed | yaml |
critical | file | |
invokeai-model-install-exposed |
InvokeAI Unauthenticated Model Install Endpoint | yaml |
critical | file | |
mcp-broken-token-validation |
MCP Broken Token Validation (Accepts Forged Tokens) | python |
high | file | |
mcp-cache-scope-identity-leak |
MCP CacheableResult Cross-Identity Leak (identity-dependent response marked publicly cacheable) | python |
high | http |
file |
mcp-child-env-inheritance |
MCP host hands a locally-spawned stdio server the operator’s entire environment | shell |
high | cli |
file |
mcp-client-header-value-encoding |
MCP Client x-mcp-header Value-Encoding Failure (Model-Controlled HTTP Header Injection) | python |
high | cli |
file |
mcp-client-mrtr-conformance |
MCP Client MRTR Conformance (inputRequests Provenance Boundary and the resultType Default) | python |
high | cli |
file |
mcp-client-oauth-issuer-binding |
MCP Client OAuth Issuer Binding (Authorization-Server Mix-Up / Cross-Issuer Credential Reuse) | python |
high | cli |
file |
mcp-client-untrusted-annotation-approval |
MCP Client Auto-Approves a Tool on an Untrusted Server’s readOnlyHint Annotation |
python |
high | cli |
file |
mcp-credential-exposure |
MCP Credential / Secret Exposure via Resources | python |
critical | http |
file |
mcp-excessive-scope-proof |
MCP Out-of-Scope Tool Action (Behavioural Scope Proof) | python |
high | http, cli |
file |
mcp-excessive-tool-permissions |
MCP Excessive Tool Permissions (Dangerous Capability Exposure) | python |
high | file | |
mcp-handle-binding-integrity |
MCP Handle Binding and requestState Integrity (Stateless Core) | python |
high | http, cli |
file |
mcp-invisible-unicode-poisoning |
MCP Invisible-Unicode Tool Poisoning (Approval-View Fidelity Gap) | python |
high | http |
file |
mcp-manifest-runtime-divergence |
MCP Declared-Manifest / Runtime-Surface Divergence | python |
high | http |
file |
mcp-method-desync |
MCP Routing-Header / Body Method Desync (Gateway Authz Bypass) | python |
high | http |
file |
mcp-oauth-consent-dcr-abuse |
MCP OAuth Consent-Layer Confused Deputy via Open Dynamic Client Registration | python |
high | http |
file |
mcp-rug-pull-detection |
MCP Rug Pull (Silent Tool Definition Mutation) | python |
high | file | |
mcp-token-audience-confusion |
MCP Token Passthrough / Audience Confusion (Confused Deputy) | python |
high | http |
file |
mcp-tool-poisoning |
MCP Tool Poisoning (Model-Directed Instructions in Tool Metadata) | python |
high | http |
file |
mcp-unauthenticated-access |
Unauthenticated MCP Server Exposure | python |
high | file | |
ml-unsafe-deserialization-usage |
ML Unsafe Deserialization Usage (Static Scan) | python |
medium | file | |
ollama-unauth-api-generate |
Ollama Unauthenticated /api/generate Access | yaml |
high | file | |
pytorch-unsafe-load-usage |
PyTorch Unsafe torch.load Usage (Static Scan) | python |
high | file | |
torchserve-management-api-exposed |
TorchServe Management API Exposed | yaml |
high | file | |
triton-model-control-exposed |
NVIDIA Triton Model Repository Control Exposed | yaml |
high | file |
cli-baseline
Section titled “cli-baseline”| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
cli-baseline-b01-argument-injection |
CLI Baseline B01 - argument injection via un-separated argv | shell |
high | cli |
file |
cli-baseline-b02-command-injection |
CLI Baseline B02 - OS command injection through an argument | shell |
critical | cli |
file |
cli-baseline-b03-path-traversal |
CLI Baseline B03 - path traversal in a file-naming argument | shell |
high | cli |
file |
cli-baseline-b04-archive-traversal |
CLI Baseline B04 - zip-slip / archive extraction traversal | shell |
high | cli |
file |
cli-baseline-b05-argv-secrets |
CLI Baseline B05 - credentials exposed in the process table | shell |
high | cli |
file |
cli-baseline-b06-insecure-temp-files |
CLI Baseline B06 - insecure temporary file creation | shell |
medium | cli |
file |
cli-baseline-b07-path-hijack |
CLI Baseline B07 - untrusted search path / PATH hijack | shell |
high | cli |
file |
cli-baseline-b08-terminal-escape |
CLI Baseline B08 - terminal escape sequence injection | shell |
medium | cli |
file |
cli-baseline-b09-environment-trust |
CLI Baseline B09 - unvalidated trust in environment variables | shell |
medium | cli |
file |
cli-baseline-b10-config-credential-handling |
CLI Baseline B10 - insecure config and credential file handling | shell |
high | cli |
file |
cli-baseline-b11-memory-safety |
CLI Baseline B11 - memory-safety defect (instrumentation-dependent) | shell |
critical | cli |
file |
cli-baseline-b12-crash-hang |
CLI Baseline B12 - crash or hang on malformed input | shell |
medium | cli |
file |
cli-baseline-b13-toctou-symlink-race |
CLI Baseline B13 - TOCTOU / symlink race | shell |
high | cli |
file |
cli-baseline-b14-format-string |
CLI Baseline B14 - format-string defect | shell |
high | cli |
file |
databases
Section titled “databases”| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
clickhouse-auth-bypass |
ClickHouse Authentication Bypass | python |
high | file | |
cockroachdb-unauthenticated-access |
CockroachDB Unauthenticated Access Detection | yaml |
critical | file | |
couchdb-default-credentials |
CouchDB Default Credentials Detection | rust |
critical | file | |
elasticsearch-data-exposure |
Elasticsearch Cluster Data Exposure | python |
critical | file | |
elasticsearch-query-injection |
Elasticsearch Query DSL Injection Detector | python |
high | file | |
elasticsearch-unauthenticated |
Elasticsearch Unauthenticated Access Detection | rust |
critical | file | |
influxdb-health-exposed |
InfluxDB Health Endpoint Exposed | yaml |
medium | file | |
memcached-unauthenticated-access |
Memcached Unauthenticated Access Detection | yaml |
critical | file | |
mongodb-injection-deep |
MongoDB NoSQL Injection Deep Analysis | python |
high | file | |
mongodb-unauthenticated |
MongoDB Unauthenticated Access Detection | python |
critical | file | |
mysql-default-credentials |
MySQL Default/Weak Credentials Detection | python |
critical | file | |
postgresql-default-credentials |
PostgreSQL Default Credentials Detection | go |
critical | file | |
postgresql-extension-rce |
postgresql extension rce | python |
medium | file | |
redis-cluster-takeover |
Redis Cluster Takeover Detection | go |
critical | file | |
redis-unauthenticated-access |
Redis Unauthenticated Access Detection | yaml |
critical | file | |
redis-unauthenticated-c |
Redis Unauthenticated Access Detection (C) | c |
critical | file | |
redis-unauthenticated-cpp |
Redis Unauthenticated Access Detection (C++) | cpp |
critical | file | |
redis-unauthenticated-go |
Redis Unauthenticated Access Detection (Go) | go |
critical | file | |
redis-unauthenticated-java |
Redis Unauthenticated Access Detection (Java) | java |
critical | file | |
redis-unauthenticated-javascript |
Redis Unauthenticated Access Detection (JavaScript) | javascript |
critical | file | |
redis-unauthenticated-perl |
Redis Unauthenticated Access Detection (Perl) | perl |
critical | file | |
redis-unauthenticated-php |
Redis Unauthenticated Access Detection (PHP) | php |
critical | file | |
redis-unauthenticated-python |
Redis Unauthenticated Access Detection (Python) | python |
critical | file | |
redis-unauthenticated-ruby |
Redis Unauthenticated Access Detection (Ruby) | ruby |
critical | file | |
redis-unauthenticated-rust |
Redis Unauthenticated Access Detection (Rust) | rust |
critical | file | |
redis-unauthenticated-shell |
Redis Unauthenticated Access Detection (Shell) | shell |
critical | file |
devops
Section titled “devops”| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
actions-injection-scanner |
GitHub Actions Injection Scanner | python |
high | file | |
ci-variable-exposure |
CI/CD Variable Exposure Detection | python |
critical | file | |
docker-api-unauth |
Docker API Unauthenticated Access | go |
critical | file | |
docker-registry-unauthenticated |
Docker Registry Unauthenticated Access Detection | shell |
high | file | |
etcd-auth-check |
Etcd Authentication Check | yaml |
info | file | |
etcd-instead-http-request |
Etcd Member List Security Check | yaml |
medium | file | |
etcd-running-unauthenticated-port |
Unauthenticated etcd Service Detection | shell |
critical | file | |
etcd-think-path-wrong |
Etcd Unauthenticated Access | yaml |
medium | file | |
etcd-unauth |
Etcd Unauthenticated Access - Members List | yaml |
high | file | |
etcd-unauthenticated |
Etcd Unauthenticated Member List Detection | shell |
high | file | |
etcd-unauthenticated-access |
Etcd Unauthenticated Access - Version Endpoint | yaml |
medium | file | |
ghes-version-fingerprint |
GitHub Enterprise Server Version Fingerprint | python |
info | file | |
git-history-secret-scan |
Git History Secret Scan | go |
critical | file | |
gitlab-version-fingerprint |
GitLab Version Fingerprint | python |
info | file | |
helm-chart-secrets-leak |
Helm Chart Secrets Leak Detection | python |
high | file | |
istio-pilot-misconfiguration |
Istio Pilot Misconfiguration Detection | go |
high | file | |
jenkins-unauth-rce |
Jenkins Unauthenticated Script Console RCE | go |
critical | file | |
jupyter-unauth-rce |
Jupyter Notebook Unauthenticated RCE | python |
critical | file | |
k8s-etcd-exposed |
Kubernetes etcd Secrets Exposure | go |
critical | file | |
k8s-rbac-misconfiguration |
Kubernetes RBAC Misconfiguration Detection | go |
critical | file | |
kubelet-api-exposure |
Kubelet API Exposure Detection | go |
critical | file | |
kubernetes-api-unauthenticated |
Kubernetes API Unauthenticated Access | yaml |
critical | file | |
pwn-request-scanner |
GitHub Actions Pwn Request Scanner | python |
critical | file | |
runner-token-detection |
runner token detection | go |
medium | file | |
saml-sso-bypass-gitlab |
saml sso bypass gitlab | python |
medium | file | |
service-account-token-abuse |
Kubernetes Service Account Token Abuse | go |
critical | file |
messaging
Section titled “messaging”| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
kafka-unauthenticated |
Apache Kafka Unauthenticated Access Detection | shell |
high | file | |
kafka-unauthenticated-access |
Kafka Unauthenticated Access Detection | python |
critical | file | |
mqtt-unauthenticated |
MQTT Unauthenticated Access (CONNACK Accepted) | yaml |
high | file | |
nats-unauthenticated-banner |
NATS Banner Indicates No Authentication | yaml |
medium | file | |
rabbitmq-default-credentials |
RabbitMQ Default Credentials Detection | python |
critical | file | |
rabbitmq-management-exposed |
RabbitMQ Management UI Exposed | yaml |
medium | file | |
zookeeper-unauthenticated-access |
Apache Zookeeper Unauthenticated Access | yaml |
critical | file |
monitoring
Section titled “monitoring”| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
cadvisor-exposed-javascript |
cAdvisor Exposed Without Authentication | javascript |
critical | file | |
cadvisor-exposed-python |
cAdvisor Metrics Exposed | python |
medium | file | |
check-metrics-endpoint |
Check /metrics Endpoint Exposure | yaml |
medium | file | |
kibana-api-status-exposed |
Kibana /api/status Exposed | yaml |
medium | file | |
mysql-exporter-exposed |
MySQL Exporter Metrics Exposed | python |
medium | file | |
node-exporter-exposed-javascript |
Node Exporter Exposed Without Authentication | javascript |
high | file | |
node-exporter-exposed-python |
Node Exporter Metrics Exposed | python |
medium | file | |
postgresql-exporter-exposed |
PostgreSQL Exporter Metrics Exposed | python |
medium | file | |
prometheus-node-exporter-exposed |
Prometheus Node Exporter Exposed Without Authentication | yaml |
high | file | |
prometheus-server-exposed-https |
Prometheus Server Exposed (HTTPS) | python |
high | file | |
prometheus-server-exposed-javascript |
Prometheus Server Exposed Without Authentication | javascript |
high | file | |
prometheus-server-exposed-python |
Prometheus Server Exposed | python |
high | file | |
redis-exporter-exposed |
Redis Exporter Exposed Detection | yaml |
medium | file | |
redis-exporter-exposed-python |
Redis Exporter Metrics Exposed | python |
high | file | |
splunk-web-login-exposed |
Splunk Web Login Exposed | yaml |
medium | file | |
splunkd-server-info-exposed |
Splunkd Server Info Exposed | yaml |
high | file |
network
Section titled “network”| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
adb-exposed |
ADB Over TCP Exposed | yaml |
high | file | |
dhcpv6-solicit-response |
DHCPv6 Solicit Response Probe | python |
info | file | |
dns-rebinding-attack |
DNS Rebinding Attack Detection | go |
critical | file | |
dns-udp-service-probe |
DNS UDP Service Probe | python |
info | file | |
dns-zone-transfer |
DNS Zone Transfer (AXFR) Detection | python |
high | file | |
echo-service-exposed |
Echo Service Exposed | yaml |
low | file | |
epmd-node-list-exposed |
EPMD Node List Exposed | yaml |
medium | file | |
finger-service-exposed |
Finger Service Exposed | yaml |
low | file | |
ftp-anonymous-access |
FTP Anonymous Access Detection | python |
high | file | |
grpc-reflection-abuse |
gRPC Reflection API Exposure Detection | go |
high | file | |
http-service-responding |
HTTP Service Responding | yaml |
info | file | |
icmp-echo-reachable |
ICMP Echo Reachability | python |
info | file | |
ident-exposed |
Ident Service Exposed | yaml |
low | file | |
mdns-service-discovery-probe |
mDNS Service Discovery Probe | python |
info | file | |
nbns-name-query-probe |
NBNS Name Query Probe | python |
info | file | |
ndmp-service-exposed |
NDMP Service Exposed | yaml |
medium | file | |
ntp-udp-service-probe |
NTP UDP Service Probe | python |
info | file | |
port-scanner-async |
High-Speed Async TCP Port Scanner | rust |
info | file | |
rmi-service-enumeration |
RMI Service Enumeration | java |
high | file | |
rsync-banner-exposed |
Rsync Daemon Banner Exposed | yaml |
medium | file | |
smart-install-exposed |
Cisco Smart Install Exposed | yaml |
high | file | |
smtp-open-relay |
SMTP Open Relay Detection | python |
high | file | |
snmp-default-community |
SNMP Default Community String Detection | shell |
high | file | |
socks5-no-auth |
SOCKS5 No-Authentication Proxy | yaml |
high | file | |
ssdp-msearch-response |
SSDP M-SEARCH Response Probe | python |
info | file | |
tacacs-service-exposed |
TACACS+ Service Exposed | yaml |
medium | file | |
tcp-banner-probe |
TCP Banner Probe | python |
info | file | |
tcp-port-reachability |
TCP Port Reachability | python |
info | file | |
tftp-service-exposed |
TFTP Service Exposed | yaml |
medium | file | |
tls-certificate-deep-analysis |
TLS Certificate Deep Analysis | rust |
high | file | |
vnc-no-auth |
VNC No Authentication Detection | c |
critical | file | |
websocket-message-fuzzer |
websocket message fuzzer | javascript |
medium | file | |
whois-service-exposed |
WHOIS Service Exposed | yaml |
low | file | |
wsd-probe-response |
WSD Probe Response | python |
info | file |
| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
system-context-recon |
System Context Reconnaissance | shell |
info | file |
tooling
Section titled “tooling”| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
supply-chain-install-credential-access |
Supply chain - install-time credential access and workflow planting | shell |
critical | cli |
file |
supply-chain-install-hook-behavior |
Supply chain - install and import-time hook behaviour | shell |
critical | cli |
file |
| Template | What it checks | Language | Severity | Target | Source |
|---|---|---|---|---|---|
auth-bypass-flow |
Authentication Bypass with Session Flow | yaml |
critical | file | |
auth-token-logout-reuse |
Authentication Token Reuse After Logout | python |
high | file | |
deserialization-gadget-scan |
Deserialization Gadget Scan | java |
critical | file | |
directory-listing-common-paths |
Directory Listing Exposure (Common Paths) | yaml |
medium | file | |
directory-traversal |
Directory Traversal Detection | c |
high | file | |
example-http-check |
Example HTTP Security Check | yaml |
info | file | |
forced-browse-auth-bypass |
Forced Browse Auth Bypass — Protected Endpoints Without Auth | python |
high | file | |
graphql-user-enumeration |
GraphQL User Enumeration (CVE-2021-4191) | python |
medium | file | |
http-header-injection |
HTTP Header Injection Detection | python |
medium | file | |
http-service-detection |
HTTP Service Detection | yaml |
info | file | |
http2-rapid-reset |
HTTP/2 Rapid Reset Detection (CVE-2023-44487) | go |
critical | file | |
idor-bola-horizontal |
IDOR / BOLA Horizontal Privilege Escalation | python |
high | file | |
jwt-alg-confusion |
JWT Algorithm Confusion (RS256 → HS256 / none) | python |
critical | file | |
jwt-role-tampering |
JWT Role / Privilege Claim Tampering | python |
critical | file | |
log4shell-detection |
Log4Shell (CVE-2021-44228) Vulnerability Detection | shell |
critical | file | |
mass-assignment-update |
Mass Assignment via Profile / Object Update Endpoint | python |
high | file | |
password-reset-enum |
Password Reset User Enumeration via Response Differences | python |
medium | file | |
password-reset-takeover |
password reset takeover | python |
medium | file | |
prototype-pollution |
prototype pollution | javascript |
medium | file | |
race-condition-exploit |
Race Condition Detection (TOCTOU) | go |
critical | file | |
rate-limit-auth-bypass |
Missing or Bypassable Rate Limit on Authentication Endpoint | python |
high | file | |
response-integrity-audit |
Response Integrity Audit (Cache Poisoning & HPP) | yaml |
medium | file | |
sensitive-data-exposure |
Sensitive Data Exposure Detection | yaml |
medium | file | |
server-side-js-injection |
server side js injection | javascript |
medium | file | |
session-fixation-check |
Session Fixation — Token Unchanged After Login | python |
high | file | |
spring4shell-detection |
Spring4Shell Detection (CVE-2022-22965) | java |
critical | file | |
sql-injection-basic |
SQL Injection Detection (Basic) | yaml |
critical | file | |
sql-injection-detection-c |
SQL Injection Detection | c |
critical | file | |
ssti-engine-fingerprint |
Server-Side Template Injection Engine Fingerprint | python |
high | file | |
timing-attack-detection |
Blind SQL Injection (Time-Based) | yaml |
high | file | |
vertical-privesc-admin |
Vertical Privilege Escalation to Admin Endpoints | python |
critical | file | |
xss-detection-c |
Cross-Site Scripting (XSS) Detection | c |
high | file |

