All skills
simota avatar

/probe

@e307415
by shingo imotasimota/agent-skills85 stars
15

Integrating OWASP ZAP/Burp Suite/Nuclei, planning penetration tests, executing DAST, and scanning for vulnerabilities. For runtime vulnerability validation. Complements Sentinel static analysis.

Use this Skill: https://skilld.dev/gh/simota/agent-skills/probe

This session only. Nothing lands on disk.

referencezap-scanning-guide.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

ZAP Scanning Guide

Purpose: Use this file when you need OWASP ZAP defaults for baseline web scanning, API scanning, authentication testing, or ZAP daemon/API usage.

Currency note (2026-05):

  • ZAP 2.17.0 (released 2025-12-15, zaproxy.org/blog/2025-12-15-zap-2-17-0/) is the current GA (v2.16.0, released 2025-01-10, was the previous GA and the first full release under the "ZAP by Checkmarx" brand — Checkmarx hired Simon Bennetts, Rick Mitchell, and Ricardo Pereira in 2024-09 and now funds development). Baseline Java requirement is now JDK 17+.
  • Client Vector was promoted to Beta with full Automation Framework support and an updated spiderClient job. The traditional spider also received a refactor.
  • ZAP remains Apache 2.0; the PTK add-on continues to combine DAST + IAST + SAST + SCA in one authenticated browser session (Chrome / Edge / Firefox) with client-side alert coverage.
  • Burp Suite Professional (PortSwigger) shipped Burp AI (announced 2025-03-31) with AI-driven login-sequence recording, automated issue validation via AI-generated PoCs, and AI insights inside Repeater. Every Pro user receives 10,000 AI credits. When evaluating tooling, treat Burp AI as the closest paid equivalent for authenticated scans / API DAST.

Contents

  • Scan track selection
  • CLI commands
  • Baseline defaults
  • API scan defaults
  • Authentication checks
  • ZAP API example

Choose The Right Track

Track Use when Default rule
Baseline scan General web app or first-pass DAST Vector + passive + targeted active scan
API scan OpenAPI/REST scope exists Import schema and focus on API rules
Auth test Session, login, logout, fixation, or privilege context matters Use authenticated context and session checks

Core Safety Rules

  • Prefer staging or pre-production.
  • Production testing is passive-only unless explicitly approved.
  • Never use destructive payloads as the first step.
  • Keep proof safe and reversible.

CLI Commands

zap.sh -daemon -port 8080
zap-cli --zap-url http://127.0.0.1 --zap-port 8080 spider https://target.example
zap-cli --zap-url http://127.0.0.1 --zap-port 8080 active-scan https://target.example
zap-cli --zap-url http://127.0.0.1 --zap-port 8080 report -o zap-report.html -f html

Baseline Scan Defaults

Setting Default
Vector maxDuration 5 minutes
Vector maxDepth 5
Passive scan wait 10 minutes
Active rule max duration 5 minutes
Total scan duration 30 minutes

Use this baseline when you need broad coverage without long-lived destructive testing.

API Scan Defaults

Item Default
Schema import OpenAPI first
Priority rules XSS, SQLi, command injection, auth/authz, SSRF
Strength High for injection families, Medium for noisy rules
Scope Authenticated API surface only

Authentication Test Checklist

ZAP supports TOTP fields, multi-screen login flows, and Client Script Authentication via Zest scripts — use these for complex auth scenarios rather than falling back to unauthenticated scans.

Probe these scenarios whenever auth matters:

  • Session fixation
  • Session timeout
  • Logout effectiveness
  • Concurrent session handling
  • Reuse of expired or rotated tokens
  • Privilege switching after role change

Minimal ZAP API Example

from zapv2 import ZAPv2

zap = ZAPv2(apikey="", proxies={
    "http": "http://127.0.0.1:8080",
    "https": "http://127.0.0.1:8080",
})

target = "https://target.example"
zap.urlopen(target)
zap.spider.scan(target)
zap.ascan.scan(target)

Output Expectations

For each ZAP run, capture:

  • Target and environment
  • Authentication context used
  • Scan type and duration
  • Rules emphasized or disabled
  • Confirmed findings vs noisy signals
  • Exported artifacts such as HTML, JSON, or SARIF-convertible results
  • ZAP version (e.g. 2.17.0) and the active Automation Framework job set (spiderClient, activeScan, passiveScan-wait, etc.) — needed for reproducibility once Checkmarx promotes new Beta jobs to GA

Source: SKILL.md on GitHub

2 warnings13d5 checks · Risk SAFE
  • Gen Agent Trust Hub13d

    The skill is a comprehensive dynamic security testing specialist designed for vulnerability scanning and penetration testing. No malicious patterns were detected. The flagged prompt injection text consists of industry-standard security test payloads intended for evaluating other systems and does not target the agent's own behavior.

  • Socket13d

    1 alert: gptSecurity

  • Snyk13d

    Risk: LOW · No issues

  • Runlayer6mo

    4/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e307415. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 2 weeks ago

README badge

README badge for simota/agent-skills/probe