webapp-pentesting

Guide authorized web application penetration testing from reconnaissance to reporting.

6|1|Updated Mar 1, 2026
One-click install
npx skills add https://github.com/narlyseorg/superhackers --skill webapp-pentesting
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: webapp-pentesting
Source: https://github.com/narlyseorg/superhackers/tree/main/skills/webapp-pentesting
Command: npx skills add https://github.com/narlyseorg/superhackers --skill webapp-pentesting

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a structured, phase-driven approach to web application security testing, guiding you from reconnaissance through exploitation to reporting to uncover vulnerabilities efficiently.

Core Features & Use Cases

  • Phase-aligned workflow covering Recon, Scan, Enumerate, Exploit, Post-Exploit, and Report.
  • SPA-aware discovery and client-side route analysis to uncover hidden attack surfaces.
  • Integrated toolchain support (rustscan, nmap, httpx, nuclei, nikto, ffuf, BurpSuite, Metasploit, Playwright) with stealth testing guidance.
  • Automated output suitable for verification and documentation workflows, aligned with vulnerability-verification and reporting skills.
  • Real-world use cases include OWASP Top 10 testing on web apps, APIs, and SPA-centric architectures.

Quick Start

Follow the guided flow to perform recon, scanning, and enumeration on a target URL within scope.

Frequently Asked Questions about webapp-pentesting

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I systematically test web apps for OWASP Top 10 vulnerabilities like XSS and SQLi?

Web application penetration testing systematically uncovers vulnerabilities by guiding you through a structured workflow from reconnaissance to reporting. This phase-driven approach covers OWASP Top 10 risks including XSS, SQLi, CSRF, SSRF, and IDOR.

What is the best way to perform penetration testing on single page applications and APIs?

Penetration testing for SPAs and APIs requires SPA-aware discovery and client-side route analysis to uncover hidden attack surfaces. This structured workflow covers reconnaissance, scanning, enumeration, exploitation, and reporting for these architectures.

How do I integrate scanning and recon tools like nmap, nuclei, and BurpSuite into a pentesting workflow?

Toolchain integration in web app pentesting connects rustscan, nmap, httpx, nuclei, nikto, ffuf, BurpSuite, Metasploit, and Playwright into a structured pipeline. This aligns tool execution with specific testing phases and stealth testing practices.

Can I use this structured pentesting workflow for authorized security engagements?

This structured web application penetration testing workflow is designed specifically for authorized engagements. It guides security professionals through reconnaissance, exploitation, and post-exploitation while maintaining stealth testing practices.

How does SPA bundle analysis fit into a web application security testing workflow?

SPA bundle analysis extracts hidden attack surfaces by discovering client-side routes within the web application security testing workflow. It operates during the reconnaissance and scanning phases to ensure complete coverage of single page applications.

Does web app pentesting generate output suitable for security reporting and verification?

Web app pentesting generates automated output specifically structured for verification and documentation workflows. This output aligns with vulnerability-verification and security reporting skills to finalize the penetration testing lifecycle.