Agent skill
web-security-auditor
Aggregate SAST, SCA, DAST, secrets, API, frontend, and backend security checks into one report.
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/other/web-security-auditor
Metadata
Additional technical details for this skill
- stage
- 9-security
- category
- web-builder
- pipeline
- web-builder
SKILL.md
Web Security Auditor
Objective
Perform a comprehensive web application security review aligned to OWASP Top 10 and practical production hardening controls.
Required Workflow
A. Static Analysis (SAST)
- Run Semgrep for injection, secrets, crypto misuse, and prototype pollution.
- Run ESLint security plugins (
eslint-plugin-security,eslint-plugin-no-unsanitized). - Run Bandit for Python codebases.
B. Dependency Scanning (SCA)
- Run
npm audit,pip-audit, orcargo auditby stack. - Include Aikido Security or Snyk where available.
- Include Vulert for no-install open-source dependency checks.
C. Dynamic Analysis (DAST)
- Run OWASP ZAP automation/headless scans.
- Optionally run StackHawk.
- Optionally run Nuclei templates for quick vulnerability sweeps.
D. Secret Detection
- Run Gitleaks across repository and history.
- Run TruffleHog scan.
E. Frontend Security Checks
- Verify CSP (no unsafe inline/eval in production policy).
- Verify clickjacking protection (
X-Frame-Optionsorframe-ancestors). - Verify HSTS.
- Verify
X-Content-Type-Options: nosniff. - Verify no sensitive data in
localStorageand no exposed production source maps. - Check for XSS hazards (
dangerouslySetInnerHTML,innerHTML,eval).
F. Backend Security Checks
- Verify parameterized DB access / ORM usage.
- Verify strong JWT secret management and token expiry.
- Verify rate limiting on auth/sensitive routes.
- Verify strict CORS origins.
- Verify input validation on all endpoints.
- Verify secure password hashing (bcrypt/argon2).
- Check IDOR controls on user-owned resources.
G. API Security
- Include Akto or Escape.tech checks for business-logic and GraphQL/REST API risks.
Output
security-report.jsonwith findings grouped byCritical,High,Medium,Low
Execution
python skills/web-security-auditor/scripts/security_auditor.py --input <workspace> --output <out.json> --format json
References
references/tools.md
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
Didn't find tool you were looking for?