Web App Penetration Testing

by usestrix469529068290Apache-2.067K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Pentest a web app or website end to end — black-box testing of a live URL, staging environment, or local dev server that finds and exploits real vulnerabilities (auth bypass, broken access control, IDOR, injection, XSS, SSRF, business logic) and proves each one with a working proof-of-concept instead of a signature match. Runs with Strix, either the self-hosted open-source CLI or the managed app.strix.ai cloud. Use when the user asks to pentest, hack, security-test, or audit their web app, website, web application, or staging site.

Instructions onlySecurity

Only the file list is public. File contents are available once the skill is installed in a workspace.

PathSizeType
SKILL.md4.2 KBtext/markdown

Source and attribution

Source:usestrix/strixinskills/web-app-penetration-testingat commit4695290

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal