All skills
simota avatar

/probe

@e307415
by shingo imotasimota/agent-skills85 stars
15

Integrating OWASP ZAP/Burp Suite/Nuclei, planning penetration tests, executing DAST, and scanning for vulnerabilities. For runtime vulnerability validation. Complements Sentinel static analysis.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/probe

This session only. Nothing lands on disk.

referencesecurity-report-template.md

≈701 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Report Template

Purpose: Use this file when preparing the final Probe report. It defines the minimum structure, severity summary, and per-finding schema.

Contents

  • Report skeleton
  • Findings summary table
  • Finding entry template
  • Status labels

Minimum Report Structure

Use this structure unless the caller provides a stricter schema.

## Executive Summary
- Target
- Test period
- Environment
- Scope
- Out-of-scope items
- Methodology

## Findings Summary
| Severity | Count | Status |
| --- | --- | --- |
| Critical | 0 | Open / Mitigated / Accepted |
| High | 0 | Open / Mitigated / Accepted |
| Medium | 0 | Open / Mitigated / Accepted |
| Low | 0 | Open / Mitigated / Accepted |

## Confirmed Findings
### [FINDING-001] Vulnerability Title
- Severity:
- CVSS:
- Status:
- Affected target:
- Description:
- Impact:
- Steps to reproduce:
- Evidence:
- Remediation:
- References:

## Unconfirmed Or Needs Review
- Finding ID:
- Reason it is not yet confirmed:
- What would be needed to confirm it safely:

## False Positive Notes
- Rule or test:
- Why it was false positive:
- Suggested tuning:

## Next Actions
- Recommended owner:
- Recommended next agent:
- Required validation after fix:

Findings Summary Rules

  • Count only confirmed findings in the main severity summary.
  • Put unconfirmed issues in a separate section.
  • If no issue is confirmed, say so explicitly.
  • If the scan scope was partial, state the limitation in the executive summary.

Finding Entry Template

Use the following fields for each confirmed finding:

Field Requirement
Severity CRITICAL, HIGH, MEDIUM, or LOW
CVSS Numeric score and vector when available
Status Confirmed, Mitigated, Accepted Risk, or Needs Fix
Description What was tested and what failed
Impact Business or technical impact in plain language
Steps to reproduce Short, reproducible, safe sequence
Evidence Request/response pair, screenshot, log line, or marker
Remediation Specific fix guidance, not generic advice
References OWASP, vendor docs, or protocol references when useful

Status Labels

Label Use when
Confirmed Safe proof exists and the issue is reproducible
Needs Review Evidence is incomplete or risk of destructive confirmation is too high
False Positive The signal was reproduced and disproven
Mitigated The issue was fixed and re-validation confirms it

Report Quality Gate

Do not finalize the report if any of these are missing:

  • Scope and environment
  • Evidence for every confirmed finding
  • CVSS or a reason why CVSS is not applicable
  • Clear remediation guidance
  • Explicit labeling of false positives and unconfirmed items

Source: SKILL.md on GitHub

2 warnings12d5 checks · Risk SAFE
  • Gen Agent Trust Hub12d

    The skill is a comprehensive dynamic security testing specialist designed for vulnerability scanning and penetration testing. No malicious patterns were detected. The flagged prompt injection text consists of industry-standard security test payloads intended for evaluating other systems and does not target the agent's own behavior.

  • Socket12d

    1 alert: gptSecurity

  • Snyk12d

    Risk: LOW · No issues

  • Runlayer6mo

    4/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e307415. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/probe