Webapp Pentest Checklist

Authorized self-pentest checklist for web applications you own. Walks the OWASP Web/API Top 10 against a locally-running target, discovering the base URL via env or entrypoint files (never hardcoded). Use when the user asks to "pentest", "attack", "probe", or "test the security of" their own running web app and the framework is unknown or mixed. For framework-specific deeper checks, use express/django/spring-boot/nextjs/nestjs/fastapi attack-probe skills.

Dolphinllc b82d05f 4.7 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/offensive/web/webapp-pentest-checklist commit b82d05f04c

Frequently asked questions

npx skillmds@latest add dolphinllc/webapp-pentest-checklist