Security Testing

aj-geddes/useful-ai-prompts/skills/security-testing

作者 aj-geddes3f5182cfd739无许可证355 个星标收录于 2026年10月8日更新于 2026年10月8日仓库7个月前更新

Identify security vulnerabilities through SAST, DAST, penetration testing, and dependency scanning. Use for security test, vulnerability scanning, OWASP, SQL injection, XSS, CSRF, and penetration testing.

包含脚本Security
AI 生成的概览

指导应用程序安全测试:SAST、DAST、渗透测试与依赖扫描。

功能
该技能提供识别应用程序安全漏洞的指导,将自动化扫描(SAST、DAST)与人工渗透测试和代码审查相结合。内容涵盖 OWASP Top 10 相关主题,如 SQL 注入、XSS、CSRF、身份验证与授权、安全响应头、密钥检测以及依赖漏洞扫描。它包含一个使用 OWASP ZAP 的快速入门示例、references 目录中的参考指南,以及一个安全检查清单脚本。
适用场景
适用于测试应用程序的 OWASP Top 10 漏洞、扫描依赖项的已知问题,或验证身份验证、授权、输入清理、API 安全、会话管理和安全响应头。它面向安全测试和渗透测试工作。
运行要求
需要能够阅读参考指南并运行所附 shell 脚本的智能体。快速入门示例使用 Python 及 zapv2 包,并需要运行中的 OWASP ZAP 代理;扫描目标需要访问目标应用程序的网络。

Security Testing

Table of Contents

Overview

Security testing identifies vulnerabilities, weaknesses, and threats in applications to ensure data protection, prevent unauthorized access, and maintain system integrity. It combines automated scanning (SAST, DAST) with manual penetration testing and code review.

When to Use

  • Testing for OWASP Top 10 vulnerabilities
  • Scanning dependencies for known vulnerabilities
  • Testing authentication and authorization
  • Validating input sanitization
  • Testing API security
  • Checking for sensitive data exposure
  • Validating security headers
  • Testing session management

Quick Start

Minimal working example:

python
# security_scan.pyfrom zapv2 import ZAPv2import time
class SecurityScanner:    def __init__(self, target_url, api_key=None):        self.zap = ZAPv2(apikey=api_key, proxies={            'http': 'http://localhost:8080',            'https': 'http://localhost:8080'        })        self.target = target_url
    def scan(self):        """Run full security scan."""        print(f"Scanning {self.target}...")
        # Spider the application        print("Spidering...")        scan_id = self.zap.spider.scan(self.target)        while int(self.zap.spider.status(scan_id)) < 100:            time.sleep(2)            print(f"Spider progress: {self.zap.spider.status(scan_id)}%")
        # Active scan        print("Running active scan...")// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
OWASP ZAP (DAST) [blocked]OWASP ZAP (DAST)
SQL Injection Testing [blocked]SQL Injection Testing
XSS Testing [blocked]XSS Testing
Authentication & Authorization Testing [blocked]Authentication & Authorization Testing
CSRF Protection Testing [blocked]CSRF Protection Testing
Dependency Vulnerability Scanning [blocked]Dependency Vulnerability Scanning
Security Headers Testing [blocked]Security Headers Testing
Secrets Detection [blocked]Secrets Detection

Best Practices

✅ DO

  • Run security scans in CI/CD
  • Test with real attack vectors
  • Scan dependencies regularly
  • Use security headers
  • Implement rate limiting
  • Validate and sanitize all input
  • Use parameterized queries
  • Test authentication/authorization thoroughly

❌ DON'T

  • Store secrets in code
  • Trust user input
  • Expose detailed error messages
  • Skip dependency updates
  • Use default credentials
  • Ignore security warnings
  • Test only happy paths
  • Commit sensitive data

来源与署名

来源:aj-geddes/useful-ai-prompts位于skills/security-testing提交3f5182c

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架