Skip to main content Home Creators proffesor-for-testing agentic-qe security-testing
security-testing Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology. Use when conducting SAST/DAST scans, auditing authentication flows, testing authorization rules, or implementing security test automation.
Jump to install Skills Marketplace Discover and explore AI skills built by the community.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Copy promptShow prompt details A direct command skips the review prompt. Inspect the source before running it.
npx skills add https://github.com/proffesor-for-testing/agentic-qe --skill security-testingThe command stays on one line. Scroll horizontally to inspect it before copying.
Prefer a local copy? Download the files currently available to SkillsMP.
Download Zip Downloading... More from this repository Ruflo is a multi-agent orchestration platform for AI coding agents (Claude Code, Cursor, Codex, Copilot, Gemini, Amp, +12 more). Use this skill when the user wants to (1) install/init ruflo in a project, (2) run multi-agent swarms with hierarchical coordination, (3) use ruflo's 314+ MCP tools for memory, routing, hooks, sub-agents, or workflows, (4) check ruflo status/version/doctor health, or (5) discover which of ruflo's 30+ plugins fits their task.
Build dependency-aware execution plans for complex Agentic QE, Ruflo, integration, migration, or multi-stream engineering programs. Use when Codex must turn research or requirements into phased work, select a small AQE fleet, map critical paths and parallel streams, define acceptance gates, or sequence risky changes. Use aqe-plan-quality instead when the primary output is only a test or quality plan.
Conduct evidence-first technical research for Agentic QE, Ruflo, related ruvnet projects, or external tools. Use when Codex must investigate a repository, compare current upstream changes, trace dependencies and history, distinguish verified facts from inference, or synthesize findings into actionable engineering recommendations. Do not use for a simple known-answer lookup or an implementation-only task.
Related occupations SOC
Based on SOC occupation classification
name security-testing description Scans for security vulnerabilities including XSS, SQL injection, CSRF, and auth flaws using OWASP Top 10 methodology. Use when conducting SAST/DAST scans, auditing authentication flows, testing authorization rules, or implementing security test automation. category specialized-testing priority critical tokenEstimate 1200 agents ["qe-security-scanner","qe-api-contract-validator","qe-quality-analyzer"] implementation_status optimized optimization_version 1 last_optimized "2025-12-02T00:00:00.000Z" dependencies [] quick_reference_card true tags ["security","owasp","sast","dast","vulnerabilities","auth","injection"] trust_tier 3 validation {"schema_path":"schemas/output.json","validator_path":"scripts/validate-config.json","eval_path":"evals/security-testing.yaml"}
Security Testing
<default_to_action>
When testing security or conducting audits:
TEST OWASP Top 10 vulnerabilities systematically
VALIDATE authentication and authorization on every endpoint
SCAN dependencies for known vulnerabilities (npm audit)
CHECK for injection attacks (SQL, XSS, command)
VERIFY secrets aren't exposed in code/logs
Quick Security Checks:
Access control → Test horizontal/vertical privilege escalation
Crypto → Verify password hashing, HTTPS, no sensitive data exposed
Injection → Test SQL injection, XSS, command injection
Auth → Test weak passwords, session fixation, MFA enforcement
Config → Check error messages don't leak info
Critical Success Factors:
Think like an attacker, build like a defender
Security is built in, not added at the end
Test continuously in CI/CD, not just before release
</default_to_action>
Quick Reference Card
When to Use
Security audits and penetration testing
Testing authentication/authorization
Validating input sanitization
Reviewing security configuration
OWASP Top 10 (2021)
# Vulnerability Key Test 1 Broken Access Control User A accessing User B's data 2 Cryptographic Failures Plaintext passwords, HTTP 3 Injection SQL/XSS/command injection 4 Insecure Design Rate limiting, session timeout 5 Security Misconfiguration Verbose errors, exposed /admin 6 Vulnerable Components npm audit, outdated packages 7 Auth Failures Weak passwords, no MFA 8 Integrity Failures Unsigned updates, malware 9 Logging Failures No audit trail for breaches 10 SSRF Server fetching internal URLs
Tools
SAST SonarQube, Semgrep Static code analysis DAST OWASP ZAP, Burp Dynamic scanning Deps npm audit, Snyk Dependency vulnerabilities Secrets git-secrets, TruffleHog Secret scanning
Agent Coordination
qe-security-scanner: Multi-layer SAST/DAST scanning
qe-api-contract-validator: API security testing
qe-quality-analyzer: Security code review
Key Vulnerability Tests
1. Broken Access Control
test ('user cannot access another user\'s order' , async () => {
const userAToken = await login ('userA' );
const userBOrder = await createOrder ('userB' );
const response = await api.get (`/orders/${userBOrder.id} ` , {
headers : { Authorization : `Bearer ${userAToken} ` }
});
expect (response.status ).toBe (403 );
});
test ('regular user cannot access admin' , async () => {
const userToken = await login ('regularUser' );
expect ((await api.get ('/admin/users' , {
headers : { Authorization : `Bearer ${userToken} ` }
})).status ).toBe (403 );
});
2. Injection Attacks
test ('prevents SQL injection' , async () => {
const malicious = "' OR '1'='1" ;
const response = await api.get (`/products?search=${malicious} ` );
expect (response.body .length ).toBeLessThan (100 );
});
test ('sanitizes HTML output' , async () => {
const xss = '<script>alert("XSS")</script>' ;
await api.post ('/comments' , { text : xss });
const html = (await api.get ('/comments' )).body ;
expect (html).toContain ('<script>' );
expect (html).not .toContain ('<script>' );
});
3. Cryptographic Failures test ('passwords are hashed' , async () => {
await db.users .create ({ email : 'test@example.com' , password : 'MyPassword123' });
const user = await db.users .findByEmail ('test@example.com' );
expect (user.password ).not .toBe ('MyPassword123' );
expect (user.password ).toMatch (/^\$2[aby]\$\d{2}\$/ );
});
test ('no sensitive data in API response' , async () => {
const response = await api.get ('/users/me' );
expect (response.body ).not .toHaveProperty ('password' );
expect (response.body ).not .toHaveProperty ('ssn' );
});
4. Security Misconfiguration test ('errors don\'t leak sensitive info' , async () => {
const response = await api.post ('/login' , { email : 'nonexistent@test.com' , password : 'wrong' });
expect (response.body .error ).toBe ('Invalid credentials' );
});
test ('sensitive endpoints not exposed' , async () => {
const endpoints = ['/debug' , '/.env' , '/.git' , '/admin' ];
for (let ep of endpoints) {
expect ((await fetch (`https://example.com${ep} ` )).status ).not .toBe (200 );
}
});
5. Rate Limiting test ('rate limiting prevents brute force' , async () => {
const responses = [];
for (let i = 0 ; i < 20 ; i++) {
responses.push (await api.post ('/login' , { email : 'test@example.com' , password : 'wrong' }));
}
expect (responses.filter (r => r.status === 429 ).length ).toBeGreaterThan (0 );
});
Security Checklist
Authentication
Authorization
Data Protection
Input Validation
CI/CD Integration
security-checks:
steps:
- name: Dependency audit
run: npm audit --audit-level=high
- name: SAST scan
run: npm run sast
- name: Secret scan
uses: trufflesecurity/trufflehog@main
- name: DAST scan
if: github.ref == 'refs/heads/main'
run: docker run owasp/zap2docker-stable zap-baseline.py -t https://staging.example.com
#!/bin/sh
git-secrets --scan
npm run lint:security
Agent-Assisted Security Testing
await Task ("Security Scan" , {
target : 'src/' ,
layers : { sast : true , dast : true , dependencies : true , secrets : true },
severity : ['critical' , 'high' , 'medium' ]
}, "qe-security-scanner" );
await Task ("OWASP Scan" , {
categories : ['broken-access-control' , 'injection' , 'cryptographic-failures' ],
depth : 'comprehensive'
}, "qe-security-scanner" );
await Task ("Validate Fix" , {
vulnerability : 'CVE-2024-12345' ,
expectedResolution : 'upgrade package to v2.0.0' ,
retestAfterFix : true
}, "qe-security-scanner" );
Agent Coordination Hints
Memory Namespace aqe/security/
├── scans/* - Scan results
├── vulnerabilities/* - Found vulnerabilities
├── fixes/* - Remediation tracking
└── compliance/* - Compliance status
Fleet Coordination const securityFleet = await FleetManager .coordinate ({
strategy : 'security-testing' ,
agents : [
'qe-security-scanner' ,
'qe-api-contract-validator' ,
'qe-quality-analyzer' ,
'qe-deployment-readiness'
],
topology : 'parallel'
});
Common Mistakes
❌ Security by Obscurity Hiding admin at /super-secret-admin → Use proper auth
❌ Client-Side Validation Only JavaScript validation can be bypassed → Always validate server-side
❌ Trusting User Input Assuming input is safe → Sanitize, validate, escape all input
❌ Hardcoded Secrets API keys in code → Environment variables, secret management
Compliance & Agent CLI For v3 agent-specific commands (aqe security ...), SAST/DAST scanning code, compliance audits (SOC2/GDPR/HIPAA), secret detection, and security gates, see references/compliance-agent-commands.md .
Related Skills
Remember Think like an attacker: What would you try to break? Test that.
Build like a defender: Assume input is malicious until proven otherwise.
Test continuously: Security testing is ongoing, not one-time.
With Agents: Agents automate vulnerability scanning, track remediation, and validate fixes. Use agents to maintain security posture at scale.
Run History After each security scan, append results to run-history.json in this skill directory:
node -e "
const fs = require('fs');
const h = JSON.parse(fs.readFileSync('.claude/skills/security-testing/run-history.json'));
h.runs.push({date: new Date().toISOString().split('T')[0], scan_types: ['sast','deps'], findings: {critical: 0, high: 0, medium: 0, low: 0}});
fs.writeFileSync('.claude/skills/security-testing/run-history.json', JSON.stringify(h, null, 2));
"
Read run-history.json before each scan — track finding count by severity over time. Alert if critical findings increase.
Skill Composition
During code review → Use with /code-review-quality for combined quality + security review
Validate findings → Use /pentest-validation to prove exploitability
Compliance → Use /compliance-testing for regulatory requirements
Gotchas
npm audit may report false positives for dev dependencies — filter with --omit=dev for production-relevant results
Agent may skip DAST in favor of faster SAST-only scans — explicitly request both if needed
security-compliance domain has 100% success rate — use as model for other skill reliability
When scanning dependencies, check both direct and transitive — npm audit --all catches nested vulnerabilities