Security Testing

by aj-geddes3f5182cfd739No license355 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 7 months ago

Identify security vulnerabilities through SAST, DAST, penetration testing, and dependency scanning. Use for security test, vulnerability scanning, OWASP, SQL injection, XSS, CSRF, and penetration testing.

Includes scriptsSecurity
AI-generated overview

Guides security testing of applications: SAST, DAST, penetration testing, and dependency scanning.

What it does
This skill provides guidance for identifying security vulnerabilities in applications, combining automated scanning (SAST, DAST) with manual penetration testing and code review. It covers OWASP Top 10 topics such as SQL injection, XSS, CSRF, authentication and authorization, security headers, secrets detection, and dependency vulnerability scanning. It includes a quick-start example using OWASP ZAP and reference guides in the references directory, plus a security checklist script.
When to use it
Use it when testing applications for OWASP Top 10 vulnerabilities, scanning dependencies for known issues, or validating authentication, authorization, input sanitization, API security, session management, and security headers. It is intended for security test and penetration testing work.
Requirements
Requires an agent able to read the reference guides and run the bundled shell script. The quick-start example uses Python with the zapv2 package and a running OWASP ZAP proxy; scanning targets requires network access to the target application.

Security Testing

Table of Contents

Overview

Security testing identifies vulnerabilities, weaknesses, and threats in applications to ensure data protection, prevent unauthorized access, and maintain system integrity. It combines automated scanning (SAST, DAST) with manual penetration testing and code review.

When to Use

  • Testing for OWASP Top 10 vulnerabilities
  • Scanning dependencies for known vulnerabilities
  • Testing authentication and authorization
  • Validating input sanitization
  • Testing API security
  • Checking for sensitive data exposure
  • Validating security headers
  • Testing session management

Quick Start

Minimal working example:

python
# security_scan.pyfrom zapv2 import ZAPv2import time
class SecurityScanner:    def __init__(self, target_url, api_key=None):        self.zap = ZAPv2(apikey=api_key, proxies={            'http': 'http://localhost:8080',            'https': 'http://localhost:8080'        })        self.target = target_url
    def scan(self):        """Run full security scan."""        print(f"Scanning {self.target}...")
        # Spider the application        print("Spidering...")        scan_id = self.zap.spider.scan(self.target)        while int(self.zap.spider.status(scan_id)) < 100:            time.sleep(2)            print(f"Spider progress: {self.zap.spider.status(scan_id)}%")
        # Active scan        print("Running active scan...")// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
OWASP ZAP (DAST) [blocked]OWASP ZAP (DAST)
SQL Injection Testing [blocked]SQL Injection Testing
XSS Testing [blocked]XSS Testing
Authentication & Authorization Testing [blocked]Authentication & Authorization Testing
CSRF Protection Testing [blocked]CSRF Protection Testing
Dependency Vulnerability Scanning [blocked]Dependency Vulnerability Scanning
Security Headers Testing [blocked]Security Headers Testing
Secrets Detection [blocked]Secrets Detection

Best Practices

✅ DO

  • Run security scans in CI/CD
  • Test with real attack vectors
  • Scan dependencies regularly
  • Use security headers
  • Implement rate limiting
  • Validate and sanitize all input
  • Use parameterized queries
  • Test authentication/authorization thoroughly

❌ DON'T

  • Store secrets in code
  • Trust user input
  • Expose detailed error messages
  • Skip dependency updates
  • Use default credentials
  • Ignore security warnings
  • Test only happy paths
  • Commit sensitive data

Source and attribution

Source:aj-geddes/useful-ai-promptsinskills/security-testingat commit3f5182c

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal