Skip to main content
Run any Skill in Manus
with one click

web-app-security

Stars3
Forks1
UpdatedJune 25, 2026 at 18:14

Web application security testing following OWASP methodology, including injection testing, authentication bypass, XSS, CSRF, SSRF, IDOR, file upload attacks, API security testing, and web application firewalling. Use this skill whenever the user mentions web app testing, OWASP top 10, SQL injection, XSS, cross-site scripting, CSRF, SSRF, IDOR, insecure deserialization, file upload vulnerability, API security, JWT testing, session management testing, authentication bypass, authorization testing, Burp Suite, ZAP, OWASP testing guide, web app pentest, application security assessment, or any web-focused security testing task. Also trigger for: ffuf, gobuster, wfuzz, sqlmap, XSStrike, commix, directory brute force, parameter fuzzing, web fuzzing, cookie testing, header injection, HTTP verb tampering, CORS misconfiguration, clickjacking, content security policy, or "test this web application for vulnerabilities". Expert tools: sqlmap (SQLi), Burp Suite (intercepting proxy), ZAP (open-source proxy), ffuf (web fuzzer

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly