All skills
hardw00t avatar

/dast-automation

@f9bb3b2

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/dast-automation

This session only. Nothing lands on disk.

examplesblackbox_basic.md

≈269 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Example: Blackbox scan, one domain

User: "Scan https://example.com for vulnerabilities."

Tool-call blueprint

  1. Ask operator for scope confirmation and out-of-scope paths (if ambiguous).
  2. Bash → parallel recon (see workflows/blackbox_single_domain.md step 2).
  3. Playwright MCP → launch context, navigate, BFS-crawl, emit crawl/endpoints.jsonl.
  4. For each injection class (XSS, SQLi, SSRF, path traversal, CRLF), iterate payloads/*.txt against discovered inputs.
  5. Bash → nuclei -l endpoints.txt ... for CVE/misconfig overlay.
  6. Manually re-verify Critical/High.
  7. Write → results/example.com/output.json conforming to schemas/finding.json.

Minimal state-tracking

results/example.com/
  crawl/endpoints.jsonl   # from Playwright
  crawl/forms.jsonl
  recon/nmap.txt
  recon/nuclei-root.jsonl
  output.json             # final

Report back to operator

  • Count by severity.
  • Top 3 risks with one-line description each.
  • Path to output.html.

Do not paste every finding inline; link to the structured output.

Source: SKILL.md on GitHub

1 alert3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill provides a comprehensive framework for automated dynamic application security testing (DAST). It utilizes Playwright for browser automation and integrates various security tools like Nuclei and SQLMap. While the skill includes numerous attack patterns and destructive payloads, these are documented as reference material and test cases to be applied against target systems. The skill follows security best practices for credential management and scoping.

  • Socket3mo

    2 alerts: gptSecurity

  • Snyk3mo

    Risk: CRITICAL · 2 issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/dast-automation