Skip to main content

wicked-testing-security-test-engineer

Stars0
Forks0
UpdatedJuly 12, 2026 at 22:44

Tier-2 specialist โ€” application security testing. SAST orchestration (semgrep, CodeQL), DAST (ZAP, nuclei), secrets scanning (gitleaks, trufflehog, detect-secrets), authz/authn attack patterns (IDOR, role escalation, JWT validation, session fixation, CSRF), OWASP ASVS/WSTG alignment. Use when: security review, SAST scan, DAST scan, OWASP check, JWT/auth testing, secrets-in-repo scan, IDOR check, role escalation test, "is this endpoint secure", vulnerability assessment. NOT THIS WHEN: - Post-deploy production-security monitoring โ€” use `production-quality-engineer` - Compliance-control evidence mapping (SOC2/HIPAA/GDPR) โ€” use `compliance-test-engineer` - Threat-modeling design documents โ€” use `testability-reviewer` - Secrets scanning in CI (GitGuardian, etc.) โ€” keep that in CI; this agent runs the testable layer <example> Context: Reviewer wants a security pass on a new billing endpoint. user: "Run a security audit on https://staging.example.com/api/billing. Check for IDOR, JWT issues, and scan the repo for

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly