Skip to main content

wicked-testing-security-test-engineer

스타0
포크0
업데이트2026년 7월 12일 22:44

Tier-2 specialist — application security testing. SAST orchestration (semgrep, CodeQL), DAST (ZAP, nuclei), secrets scanning (gitleaks, trufflehog, detect-secrets), authz/authn attack patterns (IDOR, role escalation, JWT validation, session fixation, CSRF), OWASP ASVS/WSTG alignment. Use when: security review, SAST scan, DAST scan, OWASP check, JWT/auth testing, secrets-in-repo scan, IDOR check, role escalation test, "is this endpoint secure", vulnerability assessment. NOT THIS WHEN: - Post-deploy production-security monitoring — use `production-quality-engineer` - Compliance-control evidence mapping (SOC2/HIPAA/GDPR) — use `compliance-test-engineer` - Threat-modeling design documents — use `testability-reviewer` - Secrets scanning in CI (GitGuardian, etc.) — keep that in CI; this agent runs the testable layer <example> Context: Reviewer wants a security pass on a new billing endpoint. user: "Run a security audit on https://staging.example.com/api/billing. Check for IDOR, JWT issues, and scan the repo for

설치

Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.

SKILL.md
readonly