dast-nuclei

Run template-driven Nuclei scans to detect CVEs and misconfigurations in web applications and APIs.

183|35|Updated Nov 19, 2025
One-click install
npx skills add https://github.com/AgentSecOps/SecOpsAgentKit --skill dast-nuclei
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dast-nuclei
Source: https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/appsec/dast-nuclei
Command: npx skills add https://github.com/AgentSecOps/SecOpsAgentKit --skill dast-nuclei

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires requests.

What problem does it solve?

Nuclei-based DAST scanning often requires manual setup, template selection, and interpretation of results. This Skill automates that process, enabling faster vulnerability discovery and more consistent security checks.

Core Features & Use Cases

  • Automated DAST using ProjectDiscovery's Nuclei with 7000+ community templates for CVEs, OWASP Top 10, misconfigurations, and API exposure.
  • Supports authenticated scans, severity filtering, targeted templates, and reporting workflows that feed into CI/CD pipelines.
  • Use Case: A security engineer integrates this Skill into CI to run nightly scans of a staging API and publish a security report to stakeholders.

Quick Start

Run a Nuclei-based DAST scan against your target to rapidly surface CVEs and security misconfigurations.

Frequently Asked Questions about dast-nuclei

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate Nuclei DAST scans in a CI/CD pipeline?

Nuclei DAST scanning automates template-driven dynamic analysis to identify security vulnerabilities like CVEs and OWASP Top 10 issues across web applications and APIs. It replaces manual template selection and setup with consistent, automated security checks.

Can I run authenticated Nuclei scans for API exposure and misconfigurations?

You can run Nuclei DAST scans using 7000+ community templates to detect CVEs, OWASP Top 10 vulnerabilities, security misconfigurations, and API exposure across your web applications and APIs.

Does this Nuclei automation support severity filtering and rate limits?

Automated Nuclei scanning generates remediation-ready output suites and security reports, which can be published directly to stakeholders when integrated into nightly CI workflows.

What is the best way to detect CVEs and OWASP Top 10 vulnerabilities in staging?

Yes, Nuclei DAST automation supports authenticated scanning. You can configure targeted templates, severity filtering, and rate limits to test authenticated web applications and APIs for misconfigurations and exposures.

Do I need to manually select Nuclei templates for security testing?

Automated Nuclei DAST scanning supports configurable rate limits and severity filtering, allowing you to control scan intensity and focus on critical vulnerabilities during dynamic analysis.