pentest-web-app-attacker
Assess web applications against OWASP WSTG and OWASP Top 10 with reproducible evidence capture.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Assess web applications against OWASP WSTG and OWASP Top 10 with reproducible evidence capture.
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
Plan and orchestrate authorized Nmap host discovery, port and service enumeration, NSE profiling, and reporting artifacts for in-scope targets.
Assess Active Directory identity attack paths including roasting, relay, and delegation abuse.
Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.
Test authentication and session management controls for bypass and account takeover scenarios.
Set up authorized C2 simulation workflows and measure defensive detection outcomes.
Assess AWS, Azure, and GCP controls for IAM escalation and cloud service exposure.
| name | pentest-web-app-attacker |
| description | Assess web applications against OWASP WSTG and OWASP Top 10 with reproducible evidence capture. |
Crawl and test in-scope web applications for high-impact weaknesses.
python skills/pentest-web-app-attacker/scripts/web_app_attacker.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run
web-findings.jsoncrawl-map.jsonweb-attack-report.jsonreferences/tools.mdskills/autonomous-pentester/shared/scope_schema.jsonskills/autonomous-pentester/shared/finding_schema.jsonWARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.