webapp-security

Map OWASP Top 10 2025 and ASVS v5 controls to per-route web application risk.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill webapp-security-blamejs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: webapp-security
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/webapp-security
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill webapp-security-blamejs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Legacy web application security frameworks and compliance controls are outdated for mid-2026 threat realities, failing to account for AI-generated code weakness drift, LLM prompt injection, and agentic exploit acceleration that outpace traditional testing and review cycles. Organizations relying on stale OWASP, NIST, and ISO controls risk shipping exploitable vulnerabilities and passing compliance audits that do not reflect actual attack surface.

Core Features & Use Cases

  • Comprehensive Risk Mapping: Maps OWASP Top 10 2025, ASVS v5, CWE root causes, and MITRE ATT&CK/ATLAS TTPs to per-route web application risk and global compliance framework gaps across 12+ international standards.
  • AI-Codegen Audit: Explicitly audits AI-suggested code for weakness drift, provenance tracking gaps, and unreviewed handlers that reintroduce SQLi, XSS, and other Top-10 vulnerabilities.
  • Compliance Theater Validation: Includes built-in checks to distinguish paper compliance from real security posture, covering SAST fix SLAs, auth test coverage, AI-codegen provenance, and critical bug bounty time-to-fix metrics.
  • Use Case: A team shipping AI-assisted web applications can use this skill to identify unreviewed Copilot-suggested file upload handlers that reintroduce path traversal vulnerabilities, map gaps to NIS2 and ISO 27001 requirements, and generate an auditable ASVS coverage report for auditors.

Quick Start

Use the webapp-security skill to run a full mid-2026 web application security assessment on your project, including AI-generated code weakness drift analysis, OWASP ASVS v5 coverage reporting, and compliance framework gap identification.

Frequently Asked Questions about webapp-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess web application security for AI-generated code weakness drift?

Assess AI-generated code weakness drift by auditing AI-suggested code for provenance tracking gaps and unreviewed handlers that reintroduce SQLi, XSS, and path traversal vulnerabilities, mapping them to CWE root causes and OWASP Top 10 2025.

How do I map OWASP ASVS v5 coverage to per-route web application risk?

Map OWASP ASVS v5 coverage to per-route risk by evaluating server-rendered and SPA architectures against global compliance framework gaps, generating auditable coverage reports that align with D3FEND defensive countermeasures.

Does this webapp security assessment track LLM prompt injection and MITRE ATT&CK TTPs?

This webapp security assessment tracks LLM prompt injection and agentic exploit acceleration by mapping MITRE ATT&CK and ATLAS TTPs to your application's threat realities, ensuring controls address mid-2026 attack vectors.

What is compliance theater validation in web application security audits?

Compliance theater validation distinguishes paper compliance from real security posture by checking SAST fix SLAs, authentication test coverage, AI-codegen provenance, and critical bug bounty time-to-fix metrics against actual attack surface.

Can I use this skill to identify NIS2 and ISO 27001 compliance gaps in my web app?

You can identify NIS2 and ISO 27001 compliance gaps by mapping your application's per-route risks and unreviewed AI-generated handlers against 12+ international standards, producing a prioritized remediation roadmap.

What are the limitations of using legacy OWASP frameworks for mid-2026 threat realities?

Legacy OWASP frameworks fail to account for AI-generated code weakness drift, LLM prompt injection, and agentic exploit acceleration, causing organizations to pass outdated compliance audits while shipping exploitable vulnerabilities.