web-security-auditor
Aggregate SAST, SCA, DAST, secrets, API, frontend, and backend security checks into one report.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
메뉴
Aggregate SAST, SCA, DAST, secrets, API, frontend, and backend security checks into one report.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
SOC 직업 분류 기준
Plan and orchestrate authorized Nmap host discovery, port and service enumeration, NSE profiling, and reporting artifacts for in-scope targets.
Assess Active Directory identity attack paths including roasting, relay, and delegation abuse.
Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.
Test authentication and session management controls for bypass and account takeover scenarios.
Set up authorized C2 simulation workflows and measure defensive detection outcomes.
Assess AWS, Azure, and GCP controls for IAM escalation and cloud service exposure.
| name | web-security-auditor |
| description | Aggregate SAST, SCA, DAST, secrets, API, frontend, and backend security checks into one report. |
| compatibility | codex, claude-code, claude-ai, agent-skills |
| license | Apache-2.0 |
| allowed-tools | ["read_file","write_file","run_terminal_cmd","web_search"] |
| metadata | {"category":"web-builder","stage":"9-security","pipeline":"web-builder"} |
Perform a comprehensive web application security review aligned to OWASP Top 10 and practical production hardening controls.
eslint-plugin-security, eslint-plugin-no-unsanitized).npm audit, pip-audit, or cargo audit by stack.X-Frame-Options or frame-ancestors).X-Content-Type-Options: nosniff.localStorage and no exposed production source maps.dangerouslySetInnerHTML, innerHTML, eval).security-report.json with findings grouped by Critical, High, Medium, Lowpython skills/web-security-auditor/scripts/security_auditor.py --input <workspace> --output <out.json> --format json
references/tools.md