All skills
simota avatar

/probe

@e307415
by shingo imotasimota/agent-skills85 stars
15

Integrating OWASP ZAP/Burp Suite/Nuclei, planning penetration tests, executing DAST, and scanning for vulnerabilities. For runtime vulnerability validation. Complements Sentinel static analysis.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/probe

This session only. Nothing lands on disk.

referencevulnerability-testing-patterns.md

≈1.8k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Vulnerability Testing Patterns

Purpose: Use this file when testing runtime exploitability for web apps, REST APIs, GraphQL, OAuth, SQLi, XSS, or session-aware flows.

Contents

  • Payload families
  • REST API checks
  • GraphQL checks
  • OAuth 2.0 checks
  • Proof-safe validation notes

Proof-Safe Payload Families

Use harmless markers first. Escalate only when scope and environment allow it.

Class Example payloads Notes
SQL injection ' OR '1'='1, ' UNION SELECT NULL--, SLEEP(5) Prefer timing or harmless marker queries over destructive statements
XSS <script>alert(1)</script>, "><svg/onload=alert(1)> Prefer inert custom markers in controlled environments
Command injection ; echo probe-marker Avoid system-changing commands
SSRF http://127.0.0.1, http://169.254.169.254, controlled collaborator endpoint Verify safely and avoid persistence
Path traversal ../../../../etc/hostname Read-only checks only

REST API Checklist

Always consider these areas:

Area What to test
Authentication JWT signature, expiration, revocation, MFA gaps, reset flow
Authorization BOLA, BFLA, object ownership, role escalation
Input validation SQLi, XSS, command injection, path traversal, schema abuse
Data exposure Excess fields, secret leakage, internal identifiers
Abuse controls Rate limiting, pagination limits, bulk operations

GraphQL Testing

Priority Scenarios

Scenario Severity What to verify
Introspection exposure MEDIUM Disabled or protected in production
Query depth abuse HIGH Depth and complexity limits
Batch or alias overload MEDIUM Resource protection and throttling
Field suggestion leak LOW Error hygiene and schema leakage
Variable injection CRITICAL Server-side validation and resolver safety
Authorization bypass HIGH Field-level authorization

GraphQL Checklist

  • Introspection disabled or restricted in production
  • Query depth limit is enforced
  • Complexity limit or equivalent exists
  • Field-level authorization exists for sensitive objects
  • Error messages do not leak schema details

OAuth 2.0 Testing

Priority Scenarios

Scenario Severity What to verify
Redirect URI validation CRITICAL Strict allowlist matching
PKCE enforcement HIGH Required for public clients
Authorization code replay HIGH One-time use and short lifetime
State parameter CSRF HIGH Required and validated
Scope manipulation HIGH No unauthorized privilege expansion
Token replay HIGH Revocation, rotation, audience binding

OAuth Checklist

  • Redirect URIs are exact-match or strict-match validated
  • PKCE is mandatory for public clients
  • Authorization code lifetime is <10 min
  • state is required and verified
  • Refresh and access token handling respects audience and scope boundaries

Authorization-Focused Defaults

When scope includes authenticated APIs, prioritize:

  1. BOLA
  2. BFLA
  3. Mass assignment / BOPLA-style property abuse
  4. Session and token misuse
  5. Rate-limit bypass on auth-sensitive endpoints

LLM / Agent Surface Defaults (2026)

When the target embeds an LLM endpoint, RAG retrieval, or an agentic / MCP server, add these dynamic checks alongside the API Top 10 pass — see reference/llm-agent-security-2026.md for the catalogue and tooling.

Surface Primary dynamic check
Direct prompt injection (LLM01) Send Ignore prior instructions... style payloads; observe whether system prompt or downstream tool is influenced
Indirect prompt injection / Agent Goal Hijacking (ASI01) Plant marker instructions in RAG-ingestable content / tool output; observe whether the agent executes them
Sensitive Information Disclosure (LLM02) Ask the model to reveal system prompt, training-data secrets, vector-DB content; verify no PII / API key leak
Excessive Agency (LLM06) Trigger tool calls outside the documented scope; confirm allow-list enforcement
Vector / Embedding Weaknesses (LLM08) Inject poisoned documents into RAG index; verify retrieval grounding and authz
Unbounded Consumption (LLM10) Long-context, recursion, and token-bomb payloads; verify quotas
MCP server enumeration tools/list without auth, tool-name shadowing, tool-description injection (315 MCP CVEs in 2025 per Wallarm)

Output Requirements

For each tested pattern, record:

  • Endpoint or flow
  • Identity or role used
  • Payload or mutation attempted
  • Expected behavior
  • Actual behavior
  • Safe proof or reason it remains unconfirmed

Per-Recipe Behavior (SKILL.md excerpt)

Behavior notes per Recipe:

  • zap: Default Recipe. Authenticated ZAP baseline (PR) or full active (staging/nightly). Use Zest scripts for multi-step login, TOTP, Client Script Auth. PTK add-on for combined DAST+IAST+SAST+SCA in one browser session.
  • burp: Burp Suite Professional / Enterprise with Intruder, Repeater, Autorize (BOLA). Preferred for manual exploit chaining and multi-identity authz testing. Pair with Collaborator for OOB checks.
  • nuclei: Template-based targeted scanning (12,000+ templates, incl. GCP/Azure/K8s). Pin template versions, verify sources (CVE-2024-43405). Default rate 150 req/s; reduce to 30-50 on prod-adjacent. Review AI-generated templates manually.
  • pentest: Full PLAN→REPORT engagement. Scope, authorization, threat model, attack-path chaining. Output is a complete assessment report with CVSS v4.0, SLAs, and agent handoffs.
  • api: REST / GraphQL / WebSocket DAST. Requires written scope AND 2+ identities at different privilege tiers (single-identity scans cannot detect BOLA/BFLA). Run schemathesis + restler for stateful fuzz; Autorize for BOLA sweep; graphql-cop for GraphQL audit. Cross-link to Sentinel for static-first findings and Gateway when the flaw is spec-level (missing security:, CORS wildcard). BOLA alone is ~40% of API attacks — always include.
  • mobile: Dynamic testing of built iOS/Android binaries against OWASP MASVS 2.0 / MASTG. Requires written scope explicitly authorizing Frida instrumentation and SSL pinning bypass before use. MobSF for static+dynamic orchestration, Frida/Objection for runtime hooks, Burp for MITM post-pinning-bypass, Drozer for Android IPC. Cross-link to Sentinel for source-level audit and Native for remediation/rebuild. Test release builds, not debug.
  • recon: Passive-by-default external attack-surface mapping. Output is an inventory, NOT a pentest — no exploitation, no auth attempts, no active vuln scans without separate written scope. Subfinder + amass passive + assetfinder + crt.sh for subdomains; dnsx passive resolve; httpx single-GET fingerprint; trufflehog on public repos; HIBP for leaked-credential counts (never log in to verify). Feeds prioritized targets to zap/nuclei/api/mobile/pentest. Cross-link to Breach for full red-team engagement — recon is the recon-only slice, Breach owns the adversary scenario.

Source: SKILL.md on GitHub

2 warnings12d5 checks · Risk SAFE
  • Gen Agent Trust Hub12d

    The skill is a comprehensive dynamic security testing specialist designed for vulnerability scanning and penetration testing. No malicious patterns were detected. The flagged prompt injection text consists of industry-standard security test payloads intended for evaluating other systems and does not target the agent's own behavior.

  • Socket12d

    1 alert: gptSecurity

  • Snyk12d

    Risk: LOW · No issues

  • Runlayer6mo

    4/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e307415. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/probe