top-web-vulnerabilities
Assess Common Web Vulnerabilities
Web teams need a consistent way to recognize common application risks. This skill provides a structured vulnerability reference with causes, impacts, and mitigations.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "top-web-vulnerabilities" from https://skillstore.io/skills/sickn33-top-web-vulnerabilities.md and its manifest at https://skillstore.io/api/skills/sickn33-top-web-vulnerabilities/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "top-web-vulnerabilities". Explain the risk from missing object-level authorization in a customer portal.
Expected outcome:
The skill identifies this as an access control issue related to IDOR. It explains that missing object checks can expose other users' records and recommends server-side authorization on every object request.
Using "top-web-vulnerabilities". Create a checklist for reviewing API security before launch.
Expected outcome:
The skill produces a checklist covering authentication, authorization, input validation, rate limiting, API key storage, HTTPS, and logging. Each item links to likely impacts and mitigation themes.
Using "top-web-vulnerabilities". Map common scanner findings to OWASP Top 10 themes.
Expected outcome:
The skill groups findings such as injection, broken access control, cryptographic failures, security misconfiguration, and SSRF into the matching OWASP categories with remediation priorities.
Security Audit
SafeAll static findings were false positives from defensive reference text, markdown tables, or HTTP header examples. The reviewed skill does not execute commands, make network requests, access local secrets, or include prompt-injection text. No semantic security findings were identified.
Risk Factors
⚙️ External commands (1)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-top-web-vulnerabilities/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-top-web-vulnerabilities?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-top-web-vulnerabilities?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-top-web-vulnerabilities/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-top-web-vulnerabilities.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
sickn33. (2026). top-web-vulnerabilities security audit report (audit version 5) [Author version 1.1]. Skillstore. https://skillstore.io/skills/sickn33-top-web-vulnerabilities/audits/5BibTeX citation
@techreport{sickn33-sickn33-top-web-vulnerabilities-2026,
author = {sickn33},
title = {top-web-vulnerabilities security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/sickn33-top-web-vulnerabilities/audits/5},
note = {Author version 1.1}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "top-web-vulnerabilities security audit report (audit version 5)"
version: "1.1"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-07"
url: "https://skillstore.io/skills/sickn33-top-web-vulnerabilities/audits/5"
identifiers:
- type: other
value: "skillstore:sickn33-top-web-vulnerabilities:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Plan Web App Assessments
Build a structured review plan that covers injection, authentication, access control, API, and configuration risks.
Review Secure Coding Risks
Compare application features against common root causes and select practical mitigation options.
Create Risk Checklists
Turn the vulnerability catalog into review questions for releases, audits, or internal security standards.
Try These Prompts
Use this skill to explain injection vulnerabilities, including common root causes, user impact, and practical mitigations.
Use this skill to create a web security checklist for an application with login, file upload, API access, and admin functions.
Use this skill to map these findings to OWASP Top 10 categories and summarize the main remediation themes.
Use this skill to prioritize remediation for authentication, access control, SSRF, and API issues based on impact and likely exploitability.
Best Practices
- Use the catalog to frame questions before testing a live application.
- Confirm every suspected issue with authorized, environment-appropriate validation.
- Adapt mitigation guidance to the application's framework, data sensitivity, and deployment model.
Avoid
- Treating the catalog as proof that a vulnerability exists without verification.
- Running intrusive tests against systems without explicit authorization.
- Applying generic mitigations without reviewing architecture and business logic.
Frequently Asked Questions
Does this skill scan an application automatically?
Can developers use it during code review?
Does it replace a penetration test?
Does it include OWASP Top 10 mapping?
Can it help with remediation planning?
What authorization is needed before using it?
Developer Details
Author
sickn33License
MIT
Author version
v1.1
Skillstore revision
r1
Version notice
The author-declared version is not valid SemVer.
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/top-web-vulnerabilitiesRef
9f814fc6a43fd99946f2da5e0df231c65a38bc76
Maintenance freshness
7/18/2026
Usage
8 downloads · 98 views
File structure
📄 SKILL.md