All skills
hardw00t avatar

/dast-automation

@f9bb3b2

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/dast-automation

This session only. Nothing lands on disk.

examplescontinuous_setup.md

≈366 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Example: Continuous weekly scan setup

User: "Set up automated weekly security scanning for production.example.com."

Tool-call blueprint

  1. Confirm authorization to run recurring scans in production (different from one-shot).
  2. Discuss blackbox-only vs greybox with service account; greybox in prod requires stable test tenant.
  3. Run one baseline scan now: invoke workflows/blackbox_single_domain.md and save output as baseline.json.
  4. Write → cron or GitHub Actions config. For GitHub, copy examples/github_actions_dast.yml into the target repo.
  5. Write → alerting config: where to page on new Critical/High (email, Slack webhook, PagerDuty integration key).
  6. Return to operator:
    • Baseline summary (severity counts).
    • Schedule configured.
    • Location of baseline artifact.
    • Who will receive alerts.

Baseline artifact

results/continuous/production.example.com/
  baseline.json           # schemas/finding.json array
  baseline.date.txt       # ISO-8601 timestamp
  baseline.commit.txt     # git SHA of scan config

Diff rules

See workflows/continuous_scanning.md → "Diff rules" table. Only new Critical/High page; new Medium is digested weekly.

Operator questions to ask up front

  • Production or staging?
  • Preferred alert channel and recipients?
  • Weekly, nightly, or post-deploy cadence?
  • Scope changes per release (new subdomains, new API versions)?
  • Who owns baseline-bump reviews?

Source: SKILL.md on GitHub

1 alert3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill provides a comprehensive framework for automated dynamic application security testing (DAST). It utilizes Playwright for browser automation and integrates various security tools like Nuclei and SQLMap. While the skill includes numerous attack patterns and destructive payloads, these are documented as reference material and test cases to be applied against target systems. The skill follows security best practices for credential management and scoping.

  • Socket3mo

    2 alerts: gptSecurity

  • Snyk3mo

    Risk: CRITICAL · 2 issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/dast-automation