All skills
hardw00t avatar

/dast-automation

@f9bb3b2

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".

Use this Skill: https://skilld.dev/gh/hardw00t/ai-security-arsenal/dast-automation

This session only. Nothing lands on disk.

workflowsgreybox_authenticated.md

≈875 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow: Greybox authenticated DAST

Trigger: "Perform greybox DAST on <domain> with credentials ..." / "test as logged-in user".

Precondition: Written scope authorization AND operator-supplied credentials (or session cookies). Confirm the account tier (low-priv / admin / dual) before starting.

Critical ordering

Authentication MUST complete before greybox crawl. Do not parallelize auth with crawl. Storage state is consumed by every downstream step.

┌────────────────────────────────┐
│ 1. Confirm creds + tier        │
├────────────────────────────────┤
│ 2. Phase 0 — Recon (parallel)  │  as blackbox
├────────────────────────────────┤
│ 3. Playwright LOGIN (single)   │  methodology/crawling.md (greybox)
│    - fill form                 │
│    - detect CAPTCHA/2FA → ABORT│
│    - persist storageState.json │
├────────────────────────────────┤
│ 4. Phase 1 — Authed crawl      │  BFS with storageState attached
│    - re-verify auth mid-crawl  │
├────────────────────────────────┤
│ 5. Phase 2 — Authed tests      │  methodology/vuln_testing.md
│    PLUS:                       │
│    - IDOR (2-account diff)     │
│    - Privilege escalation      │
│    - Session mgmt invariants   │
│    - Mass assignment           │
│    - Business logic (extended  │
│      thinking)                 │
├────────────────────────────────┤
│ 6. Re-verify + emit report     │
└────────────────────────────────┘

Multi-account pattern (strongly recommended for IDOR)

Request two accounts of the same tier plus one of a higher tier when possible:

contextA (low-priv)  → storageStateA.json
contextB (low-priv)  → storageStateB.json  # different tenant
contextC (admin)     → storageStateC.json  # optional

Run crawls in all three after each login completes. Then IDOR = B attempting A's object IDs; privilege escalation = A attempting C's endpoints.

Session invariants to verify

  • Cookie flags: HttpOnly, Secure, SameSite=Lax|Strict.
  • Logout invalidates server-side session (reuse cookie after logout ⇒ finding).
  • Concurrent-session policy if advertised.
  • Idle / absolute timeout behavior.
  • Session fixation: assigned session ID persists across login.

Auth failure playbook

Symptom Action
CAPTCHA on login Abort; ask operator for a bypass (backdoor form, API token).
2FA required Ask operator for TOTP seed / backup codes OR a pre-authenticated cookie.
Rate-limit on login Switch to stored cookie; do not brute the login endpoint.
CSRF token on login Playwright already fetches it via form — ensure submit uses the rendered DOM, not a raw POST.

Output

results/target.com/output.json with affected.authenticated_as populated per entry.

Related

  • Blackbox flow: workflows/blackbox_single_domain.md
  • Multi-domain: workflows/multi_domain_parallel.md
  • Business logic patterns: payloads/business_logic.txt

Source: SKILL.md on GitHub

1 alert3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    The skill provides a comprehensive framework for automated dynamic application security testing (DAST). It utilizes Playwright for browser automation and integrates various security tools like Nuclei and SQLMap. While the skill includes numerous attack patterns and destructive payloads, these are documented as reference material and test cases to be applied against target systems. The skill follows security best practices for credential management and scoping.

  • Socket3mo

    2 alerts: gptSecurity

  • Snyk3mo

    Risk: CRITICAL · 2 issues

Signed by skilld at f9bb3b2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 6 months ago

README badge

README badge for hardw00t/ai-security-arsenal/dast-automation