Security Surface

Generate and run risk-based passive security-surface checks (CT-SEC - assets and threats identified first, then auth boundaries, IDOR, error handling, user enumeration prioritized by risk) against an authorized self-hosted app, plus optional OWASP ZAP baseline. Use for security coverage. Authorized self-hosted targets only.

QAIA-Project 5ce9509 2 files · 16.4 KB Updated

File contents

QAIA-Project/QAIA/tree/main/plugins/qaia-playwright/skills/security-surface commit 5ce9509d01

Frequently asked questions

npx skillmds@latest add qaia-project/security-surface