Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CodySwannGT/lisa --skill lisa-security-zap-scan명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
This skill should be used for any non-trivial request — features, bugs, stories, epics, spikes, or multi-step tasks. It accepts a ticket URL (Jira, Linear, GitHub), a file path containing a spec, or a plain-text prompt. It assembles an agent team, breaks the work into structured tasks, and manages the full lifecycle from research through implementation, code review, deploy, and empirical verification.
any non-trivial request —…
This skill should be used for any non-trivial request — features, bugs, stories, epics, spikes, or multi-step tasks. It accepts a ticket URL (Jira, Linear, GitHub), a file path containing a spec, or a plain-text prompt. It assembles an agent team, breaks the work into structured tasks, and manages the full lifecycle from research through implementation, code review, deploy, and empirical verification.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | lisa-security-zap-scan |
| description | Run an OWASP ZAP baseline… |
| allowed-tools | ["Bash","Read"] |
Run a ZAP baseline security scan against the local application.
Check prerequisites:
docker infoscripts/zap-baseline.sh exists in the projectExecute scan:
bash scripts/zap-baseline.shAnalyze results:
zap-report.html (or zap-report.md for text)reason, even when compressed to one line each.Apply the impact-or-exploitability bar -- the same bar the lisa-security-review skill
defines; follow that skill, do not restate it. A ZAP alert is not a reproducer by itself: the
alert names a pattern, not an exercised impact path.
claim-evidence-mapping contract (BCE-1, #1835): a ZAP request/response transcript is an
http-transcript and reaches the http-api boundary only. An alert whose claim is about
rendered UI (browser) or persisted state (data) needs evidence at that boundary -- a
transcript never proves it.reason (typically
"alert only, no reproducer / no bounded impact", or "transcript does not reach the claim's
boundary"). Unproven alerts are not dropped and not demoted out of the security summary --
they render in the unproven bucket so a reader still sees them.security.review.unprovenBucket is set to something other
than security-unproven; no other classification changes.Handle failures:
Run the scan now.