Security Testing

aj-geddes/useful-ai-prompts/skills/security-testing

作者 aj-geddes3f5182cfd739無授權條款355 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 個月前更新

Identify security vulnerabilities through SAST, DAST, penetration testing, and dependency scanning. Use for security test, vulnerability scanning, OWASP, SQL injection, XSS, CSRF, and penetration testing.

包含腳本Security
AI 產生的概覽

指導應用程式安全測試:SAST、DAST、滲透測試與相依性掃描。

功能
此技能提供辨識應用程式安全弱點的指引,結合自動化掃描(SAST、DAST)與人工滲透測試及程式碼審查。內容涵蓋 OWASP Top 10 相關主題,例如 SQL 注入、XSS、CSRF、身分驗證與授權、安全標頭、機密偵測以及相依性弱點掃描。它包含一個使用 OWASP ZAP 的快速入門範例、references 目錄中的參考指南,以及一支安全檢查清單指令碼。
適用情境
適用於測試應用程式的 OWASP Top 10 弱點、掃描相依套件的已知問題,或驗證身分驗證、授權、輸入清理、API 安全、工作階段管理與安全標頭。它面向安全測試與滲透測試工作。
執行需求
需要能閱讀參考指南並執行隨附 shell 指令碼的代理。快速入門範例使用 Python 與 zapv2 套件,並需要執行中的 OWASP ZAP 代理;掃描目標需要連線至目標應用程式的網路。

Security Testing

Table of Contents

Overview

Security testing identifies vulnerabilities, weaknesses, and threats in applications to ensure data protection, prevent unauthorized access, and maintain system integrity. It combines automated scanning (SAST, DAST) with manual penetration testing and code review.

When to Use

  • Testing for OWASP Top 10 vulnerabilities
  • Scanning dependencies for known vulnerabilities
  • Testing authentication and authorization
  • Validating input sanitization
  • Testing API security
  • Checking for sensitive data exposure
  • Validating security headers
  • Testing session management

Quick Start

Minimal working example:

python
# security_scan.pyfrom zapv2 import ZAPv2import time
class SecurityScanner:    def __init__(self, target_url, api_key=None):        self.zap = ZAPv2(apikey=api_key, proxies={            'http': 'http://localhost:8080',            'https': 'http://localhost:8080'        })        self.target = target_url
    def scan(self):        """Run full security scan."""        print(f"Scanning {self.target}...")
        # Spider the application        print("Spidering...")        scan_id = self.zap.spider.scan(self.target)        while int(self.zap.spider.status(scan_id)) < 100:            time.sleep(2)            print(f"Spider progress: {self.zap.spider.status(scan_id)}%")
        # Active scan        print("Running active scan...")// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
OWASP ZAP (DAST) [blocked]OWASP ZAP (DAST)
SQL Injection Testing [blocked]SQL Injection Testing
XSS Testing [blocked]XSS Testing
Authentication & Authorization Testing [blocked]Authentication & Authorization Testing
CSRF Protection Testing [blocked]CSRF Protection Testing
Dependency Vulnerability Scanning [blocked]Dependency Vulnerability Scanning
Security Headers Testing [blocked]Security Headers Testing
Secrets Detection [blocked]Secrets Detection

Best Practices

✅ DO

  • Run security scans in CI/CD
  • Test with real attack vectors
  • Scan dependencies regularly
  • Use security headers
  • Implement rate limiting
  • Validate and sanitize all input
  • Use parameterized queries
  • Test authentication/authorization thoroughly

❌ DON'T

  • Store secrets in code
  • Trust user input
  • Expose detailed error messages
  • Skip dependency updates
  • Use default credentials
  • Ignore security warnings
  • Test only happy paths
  • Commit sensitive data

來源與署名

來源:aj-geddes/useful-ai-prompts位於skills/security-testing提交3f5182c

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架