OWASP Security Review Protocol
- ❌ NO execution/dynamic analysis.
- ❌ NO false positives. Evidence required.
- ✅ MUST map to OWASP Top 10.
- ✅ MUST provide
Severity,Location,Remediation.
- Analyze: Identify language/framework. Trace Source → Sink.
- Scan:
- Injection/Broken Access.
- Hardcoded Secrets.
- Logging Failures.
- Report: Format findings (Markdown Table). If none, "No risks found".
- Remediate: Provide code fixes for Critical/High.
- A01 Broken Access: IDOR, traversal.
- A02 Crypto: Weak keys/algos.
- A03 Injection: SQLi, XSS, Cmd.
- A04 Design: No rate limiting.
- A05 Misconfig: Default creds.
- A06 Components: Old libs.
- A07 Auth: Weak pwd.
- A08 Integrity: Deserialization.
- A09 Logging: Missing/PII.
- A10 SSRF: Unvalidated URLs.
Security Audit
| Vuln | OWASP | Sev | Loc | Desc | Fix |
|---|---|---|---|---|---|
| Name | Cat | High | File:10 | Issue | Fix |
Summary
[Assessment]