Web security auditor
Skill 0x-Professor/Agent-Skills-Hub/skills/web-security-auditor
Public skill pack for AI coding/automation/penetration-testing agents.
npx -y skills add 0x-Professor/Agent-Skills-Hub --skill web-security-auditorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 10 stars10 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Aggregate SAST, SCA, DAST, secrets, API, frontend, and backend security checks into one report.
The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
2.3 KB, as published. Nobody here has run it
Web Security Auditor
Objective
Perform a comprehensive web application security review aligned to OWASP Top 10 and practical production hardening controls.
Required Workflow
A. Static Analysis (SAST)
- Run Semgrep for injection, secrets, crypto misuse, and prototype pollution.
- Run ESLint security plugins (
eslint-plugin-security,eslint-plugin-no-unsanitized). - Run Bandit for Python codebases.
B. Dependency Scanning (SCA)
- Run
npm audit,pip-audit, orcargo auditby stack. - Include Aikido Security or Snyk where available.
- Include Vulert for no-install open-source dependency checks.
C. Dynamic Analysis (DAST)
- Run OWASP ZAP automation/headless scans.
- Optionally run StackHawk.
- Optionally run Nuclei templates for quick vulnerability sweeps.
D. Secret Detection
- Run Gitleaks across repository and history.
- Run TruffleHog scan.
E. Frontend Security Checks
- Verify CSP (no unsafe inline/eval in production policy).
- Verify clickjacking protection (
X-Frame-Optionsorframe-ancestors). - Verify HSTS.
- Verify
X-Content-Type-Options: nosniff. - Verify no sensitive data in
localStorageand no exposed production source maps. - Check for XSS hazards (
dangerouslySetInnerHTML,innerHTML,eval).
F. Backend Security Checks
- Verify parameterized DB access / ORM usage.
- Verify strong JWT secret management and token expiry.
- Verify rate limiting on auth/sensitive routes.
- Verify strict CORS origins.
- Verify input validation on all endpoints.
- Verify secure password hashing (bcrypt/argon2).
- Check IDOR controls on user-owned resources.
G. API Security
- Include Akto or Escape.tech checks for business-logic and GraphQL/REST API risks.
Output
security-report.jsonwith findings grouped byCritical,High,Medium,Low
Execution
python skills/web-security-auditor/scripts/security_auditor.py --input <workspace> --output <out.json> --format json
References
references/tools.md