web-security-testing
Run OWASP Web Security Testing
Web teams need a repeatable way to check common application risks before release. This skill organizes OWASP testing into phases, prompts, and reporting steps.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "web-security-testing" from https://skillstore.io/skills/sickn33-web-security-testing.md and its manifest at https://skillstore.io/api/skills/sickn33-web-security-testing/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "web-security-testing". Plan a security test for a customer portal before launch.
Expected outcome:
A phased checklist covering reconnaissance, injection, XSS, authentication, access control, headers, evidence collection, and final reporting.
Using "web-security-testing". Summarize validated access control issues for stakeholders.
Expected outcome:
A clear report section with affected roles, business impact, reproduction summary, severity rationale, and remediation steps.
Using "web-security-testing". Check whether OWASP Top 10 areas were covered.
Expected outcome:
A coverage review showing tested categories, missing evidence, unresolved questions, and next actions before signoff.
Security Audit
SafeAll static findings are false positives caused by Markdown backticks and code fences in SKILL.md. I found no prompt injection, hidden execution path, or data exfiltration intent in the reviewed skill file.
Risk Factors
⚙️ External commands (31)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-web-security-testing/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-web-security-testing?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-web-security-testing?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-web-security-testing/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-web-security-testing.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
sickn33. (2026). web-security-testing security audit report (audit version 4) [Author version 1.0.0]. Skillstore. https://skillstore.io/skills/sickn33-web-security-testing/audits/4BibTeX citation
@techreport{sickn33-sickn33-web-security-testing-2026,
author = {sickn33},
title = {web-security-testing security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/sickn33-web-security-testing/audits/4},
note = {Author version 1.0.0}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "web-security-testing security audit report (audit version 4)"
version: "1.0.0"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-07"
url: "https://skillstore.io/skills/sickn33-web-security-testing/audits/4"
identifiers:
- type: other
value: "skillstore:sickn33-web-security-testing:audit:4"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: HighWhat You Can Build
Prepare a Web App Assessment
Plan the testing phases, target areas, and expected evidence for an authorized web application review.
Check Release Readiness
Use the OWASP checklist to confirm key controls before a production release.
Coordinate Bug Bounty Triage
Organize valid reports by vulnerability class, risk level, proof, and remediation status.
Try These Prompts
Create an OWASP web security test plan for this application. Include phases, scope notes, evidence to collect, and reporting checkpoints.
Assess authentication and session management risks for this application. Focus on lockout, MFA, session expiry, password policy, and test evidence.
Build an access control test matrix for these roles and endpoints. Include vertical escalation, horizontal escalation, IDOR checks, and expected results.
Turn these validated web security findings into a concise report. Include impact, severity, proof summary, affected areas, remediation, and retest guidance.
Best Practices
- Define written authorization, scope, rate limits, and test windows before starting.
- Record evidence, affected assets, reproduction steps, and remediation owners for every confirmed issue.
- Retest fixes and update the report with verified outcomes.
Avoid
- Testing systems without permission or outside the approved scope.
- Reporting scanner output without manual validation and impact analysis.
- Skipping documentation of assumptions, test limits, and unresolved risks.
Frequently Asked Questions
Does this skill execute security tools?
Can I use it for production systems?
Which vulnerabilities does it cover?
Does it replace a penetration tester?
Can it help with reporting?
Does it work with Claude Code and Codex?
Developer Details
Author
sickn33License
MIT
Author version
v1.0.0
Skillstore revision
r1
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/web-security-testingRef
f93e9bb0daca99badb6a7e574b97737155d57cb3
Maintenance freshness
7/18/2026
Usage
7 downloads · 100 views
File structure
📄 SKILL.md