All skills
hardw00t avatar

/dast-automation

@f9bb3b2

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/dast-automation

This session only. Nothing lands on disk.

examplesgreybox_multi_domain.md

≈355 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Example: Greybox scan, multiple domains

User: "Test app.corp.com, api.corp.com, admin.corp.com as admin@corp.com / <pw>."

Tool-call blueprint

  1. Confirm scope + tier of account; ask for second (low-priv) account for IDOR.
  2. Spawn 3 sub-agents via the Task tool, one per domain. Each executes workflows/greybox_authenticated.md.
  3. Each sub-agent:
    • Runs Phase 0 recon (parallel inside itself).
    • Logs in via Playwright, persists storageState.json in its own directory.
    • Runs authed crawl and vuln tests.
    • Writes results/<domain>/output.json.
  4. Parent agent waits on all sub-agents.
  5. Bash → merge per-domain outputs into results/aggregate.json.
  6. Re-verify all Critical/High across all domains.
  7. Return executive summary + path to aggregate output.

Concurrency

  • Max 5 parallel sub-agents; here we use 3 (domain count).
  • Each sub-agent caps at 5 req/s.
  • Auth is sequential inside each sub-agent; crawl is parallel across sub-agents.

Multi-account pattern

If the operator supplies both admin@corp.com and user@corp.com:

  • Run two sub-agents per target (one per account).
  • The IDOR comparator then diffs object-ID reachability between the two storage states.

Secrets handling

  • Read credentials from env (DAST_USER, DAST_PASS) — never inline in tool calls.
  • Scrub logs: grep -r "$DAST_PASS" results/ must return nothing before delivery.

Source: SKILL.md on GitHub

1 alert3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill provides a comprehensive framework for automated dynamic application security testing (DAST). It utilizes Playwright for browser automation and integrates various security tools like Nuclei and SQLMap. While the skill includes numerous attack patterns and destructive payloads, these are documented as reference material and test cases to be applied against target systems. The skill follows security best practices for credential management and scoping.

  • Socket3mo

    2 alerts: gptSecurity

  • Snyk3mo

    Risk: CRITICAL · 2 issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/dast-automation