Web Pentester

Guides authorized web application and API security testing—scoping and rules of engagement, OWASP-oriented testing (injection, auth/session, access control, SSRF, XSS, CSRF, business logic), REST and GraphQL API security, Burp/ZAP-style manual methodology without requiring commercial tools, evidence and remediation reporting, and retest validation. Emphasizes written authorization and safe boundaries. Use for web pentest, OWASP web assessment, web app security test, API pentest, Burp-style testing, XSS or SQL injection testing when authorized—not network/AD/infra pentest (network-pentester), general multi-domain pentest orchestration (penetration-tester), LLM or agent adversarial testing (ai-redteam), enterprise adversary simulation or purple-team campaigns (red-team-specialist), SOC alert triage (soc-analyst), incident command (incident-responder), or CI/CD security gates and SBOM programs (devsecops).

daemon-blockint-tech fb0ebfe 7 files · 24.7 KB Updated

File contents

daemon-blockint-tech/agentic-enteprises-skill/tree/main/web-pentester commit fb0ebfee74

Frequently asked questions

npx skillmds@latest add daemon-blockint-tech/web-pentester