All skills
hardw00t avatar

/dast-automation

@f9bb3b2

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/dast-automation

This session only. Nothing lands on disk.

methodologyreporting.md

≈677 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Phase 3: Output Artifacts

Every DAST result written to disk follows schemas/finding.json. Human-readable outputs are generated from the JSON set, not hand-written.

Output hierarchy

results/<target>/
├── output.json             # array of finding objects (schemas/finding.json)
├── output.html             # rendered for humans
├── output.md               # for issue trackers
├── output.pdf              # executive handout (optional)
├── crawl/                  # raw crawl artifacts
├── evidence/               # per-entry request/response bodies
└── screenshots/            # per-entry Playwright screenshots

Entry skeleton

Driven by schemas/finding.json. Required per entry:

  • id — deterministic (<target>-<cwe>-<hash(url+param+payload)>)
  • title — less than 80 chars
  • severity — one of critical|high|medium|low|info
  • confidence — confirmed|likely|suspected
  • affected.url, affected.http_method, affected.parameter
  • evidence.request (curl command)
  • evidence.response (truncated to 1 KB)
  • evidence.playwright_screenshot_path (when available)
  • reproduction — ordered step array
  • remediation — concise, actionable

Severity rubric (calibrate with CVSS)

Severity Criteria
Critical RCE, SQLi-to-DB dump, IDOR exposing PII of other tenants, auth bypass, SSRF-to-cloud-creds
High Stored XSS w/ session context, privilege escalation, SSRF-to-internal-no-creds, SSO replay
Medium Reflected XSS, CSRF on non-critical action, info leak (versions, stacktraces), open redirect
Low Missing cookie flags, verbose errors, unsanitized headers, weak TLS config
Info Tech fingerprint, defense-in-depth suggestions

Executive summary template

# DAST Assessment — <target> — <date>

**Scope:** <hosts>
**Mode:** blackbox|greybox
**Duration:** <hh:mm>

| Severity | Count |
|----------|-------|
| Critical | N     |
| High     | N     |
| Medium   | N     |
| Low      | N     |

**Top 3 risks:**
1. ...
2. ...
3. ...

**Recommended immediate actions:** ...

Validation gate

Before delivery:

  • Every Critical/High re-verified manually (one operator, fresh session).
  • All screenshots redact PII.
  • Credentials scrubbed from logs (grep -r <password> results/ returns empty).
  • JSON validates against schemas/finding.json.

CI/CD integration

See examples/github_actions_dast.yml — fail the pipeline on new Critical/High vs baseline.

Do not share

  • Raw cookies, full JWTs, or customer PII.
  • Sample payloads with working exploit code for unpatched Critical issues on public trackers.

Source: SKILL.md on GitHub

1 alert3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill provides a comprehensive framework for automated dynamic application security testing (DAST). It utilizes Playwright for browser automation and integrates various security tools like Nuclei and SQLMap. While the skill includes numerous attack patterns and destructive payloads, these are documented as reference material and test cases to be applied against target systems. The skill follows security best practices for credential management and scoping.

  • Socket3mo

    2 alerts: gptSecurity

  • Snyk3mo

    Risk: CRITICAL · 2 issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/dast-automation