performing-web-application-vulnerability-triage

mukul975/performing-web-application-vulnerability-triage · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation.

SKILL.md

Files

This skill is a package of 6 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.5 KB
  • 📄standards.md 1.3 KB
  • 📄workflows.md 1.3 KB
  • 📁scripts
  • ⚙️agent.py 3.9 KB
  • 📄LICENSE 11.0 KB

Related

  1. security-auditor · leandrobenjaminl
    Automated security auditing covering SAST, DAST, dependency scanning, secret detection, container hardening, and compliance checks before deployments or when integrating new dependencies.
    0
    repo stars
  2. implementing-devsecops-security-scanning · mukul975 bundle
    Integrates SAST, DAST, and SCA security scanning into CI/CD pipelines using open-source tools like Semgrep, Trivy, OWASP ZAP, and Gitleaks.
    24.6k
    repo stars
  3. bola-idor · shulkwisec
    Detect and exploit Broken Object Level Authorization (BOLA) and Insecure Direct Object Reference (IDOR) vulnerabilities in APIs and web applications.
    21
    repo stars
  4. testing-for-xss-vulnerabilities · mukul975 bundle
    Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation.
    24.6k
    repo stars
  5. conducting-api-security-testing · mukul975 bundle
    Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic using the OWASP API Security Top 10 framework.
    24.6k
    repo stars
  6. exploiting-api-injection-vulnerabilities · mukul975 bundle
    Tests APIs for injection vulnerabilities including SQL, NoSQL, OS command, LDAP, and SSRF through parameters, headers, and request bodies.
    24.6k
    repo stars

Frequently asked questions

How do I install the performing-web-application-vulnerability-triage skill?

Run npx skillmds add mukul975/performing-web-application-vulnerability-triage in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the performing-web-application-vulnerability-triage skill do?

Triage web application vulnerability findings from DAST/SAST scanners using OWASP risk rating methodology to separate true positives from false positives and prioritize remediation. It is listed under Security, Vulnerability Scanning on SkillMD.

Is performing-web-application-vulnerability-triage safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with performing-web-application-vulnerability-triage?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is performing-web-application-vulnerability-triage free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published performing-web-application-vulnerability-triage?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.