What problem does it solve?
This Skill provides a structured, safety-first process to discover, validate, and document security vulnerabilities in web applications and APIs so teams can prioritize fixes, meet compliance requirements, and reduce risk.
Core Features & Use Cases
- Authorization-first workflow: Mandatory explicit authorization and non-destructive testing rules to avoid unauthorized or destructive actions.
- Reconnaissance & enumeration: Endpoint discovery, sitemap/robots checks, and technology fingerprinting to map attack surface.
- OWASP Top 10 & API testing: Guided checklist for common vulnerabilities (Broken Access Control, Injection, Cryptography, Authentication, etc.) with PoC and reproduction rules.
- Remediation, reporting & verification: Structured PoC format, concrete code fixes, TSV logging of results, and retest guidance for verification and compliance reporting.
Quick Start
Run an authorized OWASP Top 10 penetration test against target example.com and produce reproducible PoCs with prioritized remediation guidance.