What problem does it solve?
WebAssessment reduces the time and guesswork of doing a full, repeatable web app security assessment by coordinating understanding, threat modeling, and testing into a single workflow.
Core Features & Use Cases
- Application understanding: Produces a structured narrative of what the app does, who uses it, its user flows, and its attack surface.
- Threat modeling and prioritization: Generates prioritized OWASP/CWE-mapped attack scenarios and a test plan to drive efficient coverage.
- Web testing orchestration: Guides recon, content discovery (including ffuf fuzzing), web app testing via browser automation (Playwright), and AI-assisted vulnerability analysis (Gemini).
- Integration-ready outputs: Produces artifacts that align with specialized skills (Recon, PromptInjection, OSINT) for broader coverage and better sequencing.
Quick Start
Run WebAssessment against a target app to understand the application, generate a prioritized threat model, and execute the relevant pentest workflows with actionable findings.