All skills
hardw00t avatar

/dast-automation

@f9bb3b2

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/dast-automation

This session only. Nothing lands on disk.

workflowscontinuous_scanning.md

≈646 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Continuous DAST scanning

Trigger: "Schedule weekly DAST on <domain>" / "set up continuous security scanning".

Pattern

Baseline once; diff every subsequent run against the baseline; alert only on new Critical/High.

┌──────────────────────────────┐
│ Run 0 (baseline)             │
│  → results/baseline.json     │
└──────────────────────────────┘
        │
        ▼
┌──────────────────────────────┐
│ Run N (cron / CI scheduled)  │
│  → results/<YYYY-MM-DD>.json │
│  → diff vs baseline.json     │
│  → alert if Δ = new Crit/High│
│  → update rolling baseline   │
└──────────────────────────────┘

Scheduling options

cron

# /etc/cron.d/dast-target
0 2 * * 1 dast /opt/dast/run.sh target.com --mode blackbox --baseline /opt/dast/baseline.json --notify sec@corp.com

GitHub Actions

See examples/github_actions_dast.yml.

Kubernetes CronJob

apiVersion: batch/v1
kind: CronJob
metadata: { name: dast-weekly }
spec:
  schedule: "0 2 * * 1"
  jobTemplate:
    spec:
      template:
        spec:
          restartPolicy: OnFailure
          containers:
            - name: dast
              image: corp/dast-runner:latest
              args: ["--target", "https://target.com",
                     "--mode", "blackbox",
                     "--baseline", "/data/baseline.json"]

Baseline management

  • Commit baseline.json to a versioned store (git, S3 with object-lock).
  • Bump baseline only after human review of the diff.
  • Rotate baseline on major release of the target application.

Diff rules

A "new" entry = same (affected.url, affected.parameter, cwe) absent from baseline.

Δ severity Action
New Critical Page on-call immediately.
New High Ticket within 24h.
New Medium Weekly digest.
Fixed Critical/High Note in digest, auto-close linked ticket.
No change Silent success.

Drift alerts

  • Scan duration >2× baseline → infra anomaly or coverage regression.
  • Endpoint count <0.8× baseline → crawl regression (maybe auth broke).
  • Nuclei template count mismatch → update templates and re-baseline.

Related

  • Single scan: workflows/blackbox_single_domain.md
  • CI integration: examples/github_actions_dast.yml

Source: SKILL.md on GitHub

1 alert3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill provides a comprehensive framework for automated dynamic application security testing (DAST). It utilizes Playwright for browser automation and integrates various security tools like Nuclei and SQLMap. While the skill includes numerous attack patterns and destructive payloads, these are documented as reference material and test cases to be applied against target systems. The skill follows security best practices for credential management and scoping.

  • Socket3mo

    2 alerts: gptSecurity

  • Snyk3mo

    Risk: CRITICAL · 2 issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/dast-automation