Web Vulnerability Analysis Skill

Route web vulnerability analysis through CAI agents and HexStrike.

316|42|Updated Apr 5, 2026
One-click install
npx skills add https://github.com/xwtro0tk1t-cloud/harness --skill web-vulnerability-analysis-skill
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Web Vulnerability Analysis Skill
Source: https://github.com/xwtro0tk1t-cloud/harness/tree/main/bundled-skills/web-vuln-analyzer
Command: npx skills add https://github.com/xwtro0tk1t-cloud/harness --skill web-vulnerability-analysis-skill

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Web security teams spend excessive time coordinating analysis across tools and reports. This Skill centralizes vulnerability analysis, enabling AI-driven routing, automated verification, and reproducible reporting.

Core Features & Use Cases

  • CAI-driven task routing to 11 agents for reconnaissance, testing, and reporting.
  • HexStrike integration to access Kali-based security tools for advanced testing.
  • Browser-based verification with Playwright for client-side vulnerabilities.
  • End-to-end workflows: from report parsing to verification, PoC generation, and final reports.
  • Use Case: security teams validating open redirects, XSS, SAST findings, and full pentests across multiple environments.

Quick Start

Describe your target and desired verification mode to initiate an automated capability.

Frequently Asked Questions about Web Vulnerability Analysis Skill

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate web vulnerability analysis and pentest reporting?

Automated web vulnerability analysis routes tasks through CAI agents and HexStrike to perform reconnaissance, testing, and report generation. It orchestrates end-to-end workflows from parsing to PoC generation.

Can I verify client-side vulnerabilities like XSS using Playwright?

Playwright browser-based verification validates client-side vulnerabilities like XSS and open redirects. It executes automated checks to confirm exploitability within web applications during dynamic testing.

How does HexStrike integration work for web security testing?

HexStrike integration provides Docker-based access to Kali security tools for advanced penetration testing. It enables non-browser mode testing to expand vulnerability scanning capabilities across environments.

Do I need Docker to run automated penetration testing across multiple agents?

Docker is required to run HexStrike integration for accessing Kali-based security tools. The environment orchestrates CAI agents through Docker to execute automated penetration testing and SAST verification.

What is the best way to verify SAST findings dynamically?

Dynamic verification of SAST findings uses CAI-driven task routing to 11 agents for automated testing. It parses static analysis reports and applies dynamic verification to generate PoC and final reports.

Are there limitations when testing web applications with CAI agents?

Web vulnerability analysis using CAI agents requires specifying a target and desired verification mode to initiate testing. Limitations depend on browser and non-browser modes available for the specific assessment scope.