integrating-dast-with-owasp-zap-in-pipeline

mukul975/integrating-dast-with-owasp-zap-in-pipeline · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Integrates OWASP ZAP for Dynamic Application Security Testing in CI/CD pipelines, configuring baseline, full, and API scans, interpreting findings, tuning policies, and establishing quality gates in GitHub Actions and GitLab CI.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. implementing-devsecops-security-scanning · mukul975 bundle
    Integrates SAST, DAST, and SCA security scanning into CI/CD pipelines using open-source tools like Semgrep, Trivy, OWASP ZAP, and Gitleaks.
    24.6k
    repo stars
  2. building-devsecops-pipeline-with-gitlab-ci · mukul975 bundle
    Design and implement a comprehensive DevSecOps pipeline in GitLab CI/CD integrating SAST, DAST, container scanning, dependency scanning, and secret detection.
    24.6k
    repo stars
  3. scanning-docker-images-with-trivy · mukul975 bundle
    Scan Docker images for vulnerabilities, misconfigurations, secrets, and license violations using Trivy, with CI/CD integration and policy enforcement.
    24.6k
    repo stars
  4. scanning-containers-with-trivy-in-cicd · mukul975 bundle
    Integrate Trivy vulnerability scanning into CI/CD pipelines to detect container image CVEs, Dockerfile misconfigurations, and enforce severity-based quality gates.
    24.6k
    repo stars
  5. implementing-aqua-security-for-container-scanning · mukul975 bundle
    Deploy Aqua Security's Trivy scanner to detect vulnerabilities, misconfigurations, secrets, and license issues in container images across CI/CD pipelines and registries.
    24.6k
    repo stars
  6. implementing-secrets-scanning-in-ci-cd · mukul975 bundle
    Integrate gitleaks and trufflehog into CI/CD pipelines to detect leaked secrets before deployment.
    24.6k
    repo stars

Frequently asked questions

How do I install the integrating-dast-with-owasp-zap-in-pipeline skill?

Run npx skillmds add mukul975/integrating-dast-with-owasp-zap-in-pipeline in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the integrating-dast-with-owasp-zap-in-pipeline skill do?

Integrates OWASP ZAP for Dynamic Application Security Testing in CI/CD pipelines, configuring baseline, full, and API scans, interpreting findings, tuning policies, and establishing quality gates in GitHub Actions and GitLab CI. It is listed under DevOps & Infra, Security, CI/CD, Vulnerability Scanning on SkillMD.

Is integrating-dast-with-owasp-zap-in-pipeline safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with integrating-dast-with-owasp-zap-in-pipeline?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is integrating-dast-with-owasp-zap-in-pipeline free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published integrating-dast-with-owasp-zap-in-pipeline?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.