#
ENJA

brokencrystals

NeuraLegion/brokencrystals

Broken Crystals is a benchmark web application designed to evaluate security scanners and penetration testing tools against a wide range of common vulnerabilities.

199 339MITUpdated 2026-08-12

Overview

Broken Crystals is an intentionally vulnerable benchmark application built with a React frontend and a Node.js/PostgreSQL backend. It implements numerous common security flaws including broken JWT authentication, XSS, CSRF, insecure cookies, directory listing, and weak password brute-forcing, making it an ideal target for testing automated security scanners like SecTester.

Capabilities

  • Implements broken JWT authentication vulnerabilities (none algorithm, RSA-to-HMAC, invalid signature, KID manipulation, brute forcing, rogue keys)
  • Provides endpoints vulnerable to reflective, persistent, and DOM-based XSS
  • Demonstrates CSRF and misconfigured CORS policies
  • Exposes common sensitive files and directory listings
  • Supports automated testing via SecTester and Jest

Best for

Benchmarking web application security scanners, Testing automated penetration testing tools, Learning and demonstrating web application vulnerabilities, Practicing security exploitation and mitigation techniques

Evoa Score breakdown= Σ (score × weight)
64
Task usefulness20%88 → +17.6

実タスクにどれだけ役立つか(機能の豊富さ・用途の明確さ)。 AIによるcapabilities/use-cases解析

Code quality15%80 → +12.0

実装・指示の品質。 AIによるSKILL.md/README解析

Maintenance15%100 → +15.0

リポジトリがどれだけ活発に保守されているか。 GitHub 最終push日時の新しさ

Documentation12%28 → +3.4

ドキュメントの充実度・分かりやすさ。 README/独自要約の情報量

Security15%15 → +2.3

危険・不審な挙動が無いか。 AIによるセキュリティレビュー

Originality10%75 → +7.5

ありふれたラッパーではない独自性。 AIによる独自性判定

Popularity8%74 → +5.9

コミュニティの採用度。 GitHub Stars/Forks(対数スケール)

Compatibility5%0 → +0.0

対応AIエージェントの広さ。 AIによる対応エージェント判定

Weighted total63.6 / 100

ライセンス不明/制限あり(Red)のSkillは総合スコアに0.85倍の補正を適用します。 ランキングはこのScoreのみで決まり、広告で変わりません。 算出方法の詳細 →

Security considerations

This skill references a benchmark application containing intentional and severe security vulnerabilities. It should never be deployed to a public or production environment without strict isolation.

Categories

Summary and analysis are original content generated by AI Skills Rank. The skill's source text is not reproduced here — view it on the linked repository.