vuln-definitions-db
v0.1.2数据库领域漏洞定义:DBMS 通用形态(认证/RBAC/查询处理/存储引擎/外部访问/复制/云控制面/泄露/密钥/内存安全)与 Bugcrowd VRT P1–P5 → 四档映射;含 ClickHouse Bugcrowd 项目资产范围、合格条款、赏金资格(不定级)、历史漏洞模式库(定级校准 + 挖掘切入点)与 Langfuse Cloud 厂商文件(安全架构特征 + 挖掘候选)。
By DeepSonar0 GitHub starsUpdated 2 days ago
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 1 skill or MCP entry
- Source updated
- Sep 22, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install vuln-definitions-db for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install vuln-definitions-db@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/SummerSec/DeepSonar-SkillsClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is vuln-definitions-db/.
Plugin files
├── .claude-plugin/plugin.json└── SKILL.md
Included Skills1
数据库领域漏洞定义指南。定义 DBMS 通用漏洞形态(认证接入 / 权限模型 RBAC / 查询处理 / 存储引擎 / 外部访问 UDF·表函数 / 复制与集群 / 云控制面多租户 / 数据泄露 / 配置密钥 / 内存安全),并把 Bugcrowd VRT P1–P5 映射为 critical/high/medium/low 四档;含 ClickHouse Bugcrowd 项目资产范围、OSS 合格条款、云平台排除项与赏金资格(不定级),历史漏洞模式库(codec 解压、query cache 键、native 协议、library-bridge、UDF 沙箱逃逸、NoSQL 注入等),以及 Langfuse 厂商文件(Cloud 4.x 安全架构特征、认证模型、SSRF 防线、挖掘候选)。用户提到「ClickHouse 漏洞」「数据库漏洞」「DBMS」「SQL 注入定级」「RBAC 绕过」「row policy」「query cache」「Keeper」「clickhouse-server」「ClickHouse Cloud」「Bugcrowd」「VRT」「P1 P2 P3」「Langfuse」「cloud.langfuse.com」「ingestion API」「in-app agent」或要给数据库类审计目标定级时使用。This skill should be used when the user asks to rate a database / DBMS vulnerability, classify RBAC or row-policy bypasses, map Bugcrowd VRT priorities to severity tiers, check ClickHouse Bugcrowd scope and eligibility, or audits ClickHouse OSS, ClickHouse Cloud, Langfuse Cloud, or other database targets.
Plugin manifests1
{
"name": "vuln-definitions-db",
"version": "0.1.2",
"description": "数据库领域漏洞定义:DBMS 通用形态(认证/RBAC/查询处理/存储引擎/外部访问/复制/云控制面/泄露/密钥/内存安全)与 Bugcrowd VRT P1–P5 → 四档映射;含 ClickHouse Bugcrowd 项目资产范围、合格条款、赏金资格(不定级)、历史漏洞模式库(定级校准 + 挖掘切入点)与 Langfuse Cloud 厂商文件(安全架构特征 + 挖掘候选)。",
"author": {
"name": "DeepSonar"
}
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[vuln-definitions-db on Agent Plugins Marketplace](https://pluginsmp.com/plugins/vuln-definitions-db)