pytm
81Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Plan Authorized Web Fuzzing with ffuf
Web fuzzing creates noisy results and legal exposure when scope, filters, and rate limits are unclear. This skill produces authorized ffuf workflows with focused discovery, filtering, output, and CI guidance.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "dast-ffuf" from https://skillstore.io/skills/agentsecops-dast-ffuf.md and its manifest at https://skillstore.io/api/skills/agentsecops-dast-ffuf/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "dast-ffuf". Plan low-impact directory discovery for an authorized staging host.
Expected outcome:
Using "dast-ffuf". Reduce false positives after every path returns a successful response.
Expected outcome:
Using "dast-ffuf". Add ffuf to a staging security pipeline.
Expected outcome:
Most static hits are false positives from Markdown syntax, reference links, and labeled security examples. The CI template has a critical supply-chain risk because it pipes an unpinned remote script into Bash. The skill also provides high-impact credential fuzzing and reconnaissance workflows that require explicit authorization.
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/agentsecops-dast-ffuf/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/agentsecops-dast-ffuf?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/agentsecops-dast-ffuf?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/agentsecops-dast-ffuf/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/agentsecops-dast-ffuf.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>AgentSecOps. (2026). dast-ffuf security audit report (audit version 9) [Author version 0.1.0]. Skillstore. https://skillstore.io/skills/agentsecops-dast-ffuf/audits/9@techreport{agentsecops-agentsecops-dast-ffuf-2026,
author = {AgentSecOps},
title = {dast-ffuf security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/agentsecops-dast-ffuf/audits/9},
note = {Author version 0.1.0}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "dast-ffuf security audit report (audit version 9)"
version: "0.1.0"
type: report
authors:
- name: "AgentSecOps"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/agentsecops-dast-ffuf/audits/9"
identifiers:
- type: other
value: "skillstore:agentsecops-dast-ffuf:audit:9"
description: "Skillstore immutable audit report identifier"
Create a rate-limited directory and file discovery plan for an owned staging application.
Build focused GET or POST parameter tests with filters that reduce baseline noise.
Design a repeatable CI check that records ffuf results and flags exposed sensitive paths.
Create a basic ffuf plan for [authorized target] using [wordlist]. Use low concurrency, explain response filters, and save reviewable results.
Plan authorized fuzzing for [endpoint] and [parameter location]. Include a baseline request, payload category, matching rules, rate limits, and manual validation steps.
Design a scoped virtual host discovery workflow for [base domain]. Explain calibration, false-positive reduction, DNS validation, request limits, and evidence handling.
Design a CI ffuf check for [staging URL]. Pin dependencies, avoid remote pipe execution, set failure criteria, protect artifacts, and limit requests.
Author
AgentSecOpsLicense
MIT
Author version
v0.1.0
Skillstore revision
r2
Ref
9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2
Maintenance freshness
7/24/2026
Usage
5 downloads ยท 248 views
File structure
Build pytm Threat Models as Code
Threat modeling often becomes outdated and disconnected from architecture changes. This skill helps create pytm models, STRIDE analysis, and diagram workflows for security reviews and CI.
Secure Dockerfiles with Hadolint
Dockerfile mistakes can create insecure and unreliable container images. This skill provides Hadolint workflows, rule guidance, remediation examples, and reusable CI configurations.
Run Authorized Nuclei Security Scans
Known vulnerabilities and misconfigurations can escape manual review. This skill guides authorized Nuclei scans, template selection, validation, and reporting.
Audit Code with Semgrep
Security flaws can remain hidden across large, multilingual repositories. This skill guides focused Semgrep scans, triage, custom rules, CI gates, and standards-aligned remediation.
Scan Dependencies and Containers with Trivy
Security teams need consistent visibility into vulnerable components, images, and infrastructure configuration. This skill provides practical Trivy workflows for assessment, reporting, and remediation.
Automate OWASP ZAP DAST Scans
Security teams need repeatable runtime testing before releases. This skill guides authorized OWASP ZAP scans, authentication setup, API testing, and CI reporting.
Strengthen Application Security Reviews
by alirezarezvani
Security reviews often lack consistent checklists and reusable workflows. This skill provides security review scaffolds, reference guidance, and simple reporting scripts for Claude, Codex, and Claude Code.
Review Application Security Risks
by Bikach
Security reviews can miss issues across authentication, input handling, APIs, and secrets. This skill provides structured guidance, checklists, and remediation patterns for application-security work.
Build Security Blue Books for Sensitive Apps
by sickn33
Sensitive applications need clear security documentation before review. This skill helps Codex, Claude, and Claude Code draft structured Blue Book guidance.
Guide Web Fuzzing With ffuf
by sickn33
Web testers need focused ffuf guidance when planning directory, parameter, or virtual host fuzzing. This skill gives Claude, Codex, and Claude Code a simple workflow for web fuzzing discussions.
Assess Common Web Vulnerabilities
by sickn33
Web teams need a consistent way to recognize common application risks. This skill provides a structured vulnerability reference with causes, impacts, and mitigations.
Assess Web Vulnerabilities with a Top 100 Reference
by sickn33
Teams need consistent language for common web security flaws. This skill provides a structured OWASP-aligned reference with causes, impacts, and mitigations.