security-dast

Identify and validate DAST security findings in authorized runtime targets.

Updated May 8, 2026
One-click install
npx skills add https://github.com/ace3/skills --skill security-dast
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-dast
Source: https://github.com/ace3/skills/tree/main/skills/security-dast
Command: npx skills add https://github.com/ace3/skills --skill security-dast

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Blackbox/dynamic application security testing for authorized runtime targets, active surface scans, API/web probing, TLS checks, fuzzing, pentest-style validation, finding normalization, enterprise security reports, and retest evidence. It enables teams to perform secure, scope-limited security testing while producing actionable findings and remediation plans.

Core Features & Use Cases

  • Load and apply a base operating layer to enforce planning gates, surgical changes, and non-destructive verification.
  • Classify targets, evidence sources, and tool outputs into structured findings aligned with enterprise security reporting.
  • Leverage a curated set of references for standardized taxonomy, quality gates, benchmarking, and prompt-injection defense.
  • Produce enterprise-ready outputs including findings, remediation roadmaps, and retest evidence for iterative security assurance.
  • Compatible with DAST toolchains like ZAP, Nuclei, SSLyze, Naabu, and modern JavaScript/web apps.

Quick Start

Load the base layer and begin an authorized DAST workflow against your scoped targets.

Frequently Asked Questions about security-dast

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform dynamic application security testing on deployed web APIs?

Dynamic application security testing on deployed web APIs is performed by identifying in-scope runtime targets and probing them actively to collect evidence, severity ratings, and structured remediation guidance.

How does evidence-driven remediation work for runtime security findings?

Evidence-driven remediation validates active security findings by capturing runtime proof, classifying the evidence into structured findings, and generating actionable remediation steps alongside retest verification status.

Can I use this DAST workflow with tools like ZAP and Nuclei?

This DAST workflow is compatible with toolchains like ZAP, Nuclei, SSLyze, and Naabu, leveraging their outputs to normalize findings into enterprise-ready security reports.

What is the best way to structure enterprise security reports from pentest validation?

Structuring enterprise security reports from pentest validation involves classifying target evidence and tool outputs into normalized findings that include remediation roadmaps and iterative retest evidence.

Does this dynamic testing approach support scope-limited and non-destructive scans?

This dynamic testing approach supports scope-limited scans by loading a base operating layer that enforces planning gates, surgical changes, and non-destructive verification against authorized targets.

When do I need fuzzing and TLS checks for web application security testing?

Fuzzing and TLS checks are needed during web application security testing when probing active runtime surfaces to validate vulnerabilities and capture structured evidence for enterprise reporting.