All skills
hardw00t avatar

/dast-automation

@f9bb3b2

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/dast-automation

This session only. Nothing lands on disk.

workflowsblackbox_single_domain.md

≈824 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Blackbox single-domain DAST

Trigger: "Scan https://target.com for vulnerabilities" / "blackbox DAST on <domain>".

Duration: 15–60 min depending on surface size.

Precondition: Written scope authorization.

Step plan

┌────────────────────────────────┐
│ 1. Confirm scope w/ operator   │  (ask for out-of-scope paths)
├────────────────────────────────┤
│ 2. Phase 0 — Recon (parallel)  │  methodology/recon.md
│    nmap + whatweb + ffuf       │
│    + nuclei (root) + subfinder │
├────────────────────────────────┤
│ 3. Phase 1 — Crawl             │  methodology/crawling.md
│    Playwright MCP → BFS click  │
│    + form probe                │
├────────────────────────────────┤
│ 4. Phase 2 — Vuln testing      │  methodology/vuln_testing.md
│    XSS, SQLi, SSRF, traversal, │
│    CRLF, open redirect, CSRF   │
│    (can parallelize by class)  │
├────────────────────────────────┤
│ 5. Nuclei overlay on endpoints │
├────────────────────────────────┤
│ 6. Manual re-verify Crit/High  │
├────────────────────────────────┤
│ 7. Emit schemas/finding.json + │  methodology/reporting.md
│    output.html + output.md     │
└────────────────────────────────┘

Commands you'll actually run

# Step 2 — parallel recon
mkdir -p results/target/{crawl,evidence,screenshots}
subfinder -d target.com -silent -o results/target/subs.txt &
nmap -sV -sC -T4 target.com -oN results/target/nmap.txt &
whatweb -a 3 https://target.com --log-json results/target/whatweb.json &
ffuf -u https://target.com/FUZZ -w /usr/share/wordlists/dirb/common.txt \
     -o results/target/ffuf.json -of json &
nuclei -u https://target.com -severity critical,high,medium \
       -jsonl -o results/target/nuclei-root.jsonl &
wait

# Step 3 — Playwright crawl (via MCP; pseudo-code, invoke via tool)
# playwright_mcp.launch(url=https://target.com, mode=blackbox, depth=3)

# Step 5 — nuclei over discovered endpoints
nuclei -l results/target/crawl/endpoints.txt \
       -severity critical,high,medium \
       -jsonl -o results/target/nuclei-endpoints.jsonl

Decision gates

  • No endpoints discovered: check for SPA blocking Playwright; fall back to wget --spider + katana.
  • WAF blocking: reduce rate; switch to --tamper set when running sqlmap; do not bypass without authorization.
  • Rate-limit errors (429): pause scan, coordinate with operator, do not auto-retry from new IPs.

Output

results/target.com/output.json conforming to schemas/finding.json.

Related

  • Greybox auth: workflows/greybox_authenticated.md
  • Many targets: workflows/multi_domain_parallel.md
  • Scheduled re-runs: workflows/continuous_scanning.md

Source: SKILL.md on GitHub

1 alert3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill provides a comprehensive framework for automated dynamic application security testing (DAST). It utilizes Playwright for browser automation and integrates various security tools like Nuclei and SQLMap. While the skill includes numerous attack patterns and destructive payloads, these are documented as reference material and test cases to be applied against target systems. The skill follows security best practices for credential management and scoping.

  • Socket3mo

    2 alerts: gptSecurity

  • Snyk3mo

    Risk: CRITICAL · 2 issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/dast-automation