DAST instructions

138 tagged DAST, measured the same way as everything else here.

dast-nuclei

01

AgentSecOps/SecOpsAgentKit

Skill Claude CodeCodex

Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web applications, APIs, and infrastructure. Use when: (1) Performing rapid vulnerability scanning with automated CVE detection, (2)…

202 +1 4mo ago A 129 tokens

dast-config

02

UnitOneAI/SecuritySkills

Skill Claude CodeCodex

Reviews DAST tool configurations against OWASP Top 10:2021 and OWASP Testing Guide v4.2. Auto-invoked when reviewing OWASP ZAP configurations, DAST CI/CD integration, scan policies, or authenticated scanning setups. Produces a DAST maturity assessment covering scan policy configuration, active vs passive scanning, API…

58 +2 2mo ago A 83 tokens original MIT

mythos-agent

03

mythos-agent/mythos-agent

MCP server Claude CodeCodexCursor +2

Open-source AI security agent: SAST, DAST, and policy-as-code over MCP. Runs locally from the mythos-agent npm package.

43 3mo ago A tokens not measured original MIT

fortify

04

fortify/skills

Plugin Claude Code

OpenText Fortify AppSec skills. Use for SAST/DAST/SCA scanning, vulnerability triage, audit workflows, CI/CD pipeline integration, and FCLI commands. Supports Fortify on Demand (FoD) and Software Security Center (SSC).

19 1mo ago A tokens not measured original MIT

fortify/skills

Instructions file GitHub Copilot

Instructions for fortify/skills, covering fortify skills repository, structure, conventions, workflow terminology and reference path rules (per agent skills spec).

19 1mo ago A 1,613 tokens original MIT

fortify/skills

Agent

Orchestrate batch CVE exploitability analysis across many known advisories. Activate to triage a list of CVEs/GHSAs for reachability in a codebase — sourced from an SBOM, a Fortify on Demand release, a Fortify SSC application version, a local file (CSV/JSON/text), or an explicitly provided list. Never discovers CVEs…

19 1mo ago A 121 tokens original MIT

fortify-onboarding

07

fortify/skills

Agent

Orchestrate end-to-end onboarding of new applications into Fortify (FoD or SSC). Activate to create one or more new Fortify applications, set up a project or repo for Fortify scanning, or onboard an entire GitHub/GitLab/Azure DevOps organization. Handles app creation and optional CI/CD pipeline setup (PR included).

19 1mo ago A 74 tokens original MIT

fortify-fod

08

fortify/skills

Skill Claude CodeCodex

Perform tasks against Fortify on Demand (FoD): query applications/releases; query & triage existing security issues in FoD; start & monitor full SAST/DAST/SCA/open source scans of the codebase; create releases; import FPR/SARIF/CycloneDX artifacts; policy and portfolio analysis. NOT for lightweight AI review of local…

19 1mo ago A 88 tokens original MIT

fortify-remediate

09

fortify/skills

Skill Claude CodeCodex

Remediate SAST (static) and DAST (dynamic) security vulnerabilities ALREADY detected by Fortify in FoD or SSC — fix specific issues, categories, or reduce issue counts, including applying SAST Aviator fixes. For SCA / open source dependency findings (vulnerable third-party components, CVEs), use…

19 1mo ago A 117 tokens original MIT

fortify-ssc

10

fortify/skills

Skill Claude CodeCodex

Perform tasks against Fortify SSC (Software Security Center): query applications/application versions; query & triage existing security issues in SSC; start & monitor full ScanCentral SAST/DAST scans or upload FPR artifacts; create app versions; policy and portfolio analysis. NOT for lightweight AI review of local…

19 1mo ago A 76 tokens original MIT

shor

11

tr4m0ryp/shor

Plugin Claude Code

Shor — autonomous AI web pentester. Provides the /shor-setup slash-command: an interactive wizard that guides you from zero to a running scan (black-box or white-box, GCP deployment included).

9 1mo ago A tokens not measured

jwt_tool

12

tr4m0ryp/shor

Skill Claude CodeCodex

Skill "jwt_tool" from tr4m0ryp/shor, covering jwttool — jwt analysis & attacks, when to reach for it, key flags / modes, safe invocation and form field (oidc-style).

9 1mo ago A 52 tokens

authz-recipe

13

tr4m0ryp/shor

Skill Claude CodeCodex

Broken Access Control is OWASP #1, but there is no drop-in CLI (Autorize / AuthMatrix are Burp extensions). This is the procedure that carries the whole category: an authorization-matrix + A/B session-replay method driving curl, the playwright skill (per-identity sessions), and ffuf (ID enumeration). Live →…

9 1mo ago A 62 tokens

tr4m0ryp/shor

Skill Claude CodeCodex

A small recipe over the already-cloned repo. It runs git log --grep for security/CVE/fix patterns, maps the touched files into ranked hot files, and emits historicalsignal.json. It optionally folds in two signals you may have ALREADY produced this phase — osv-scanner JSON (dependency CVEs) and gitleaks JSON (history…

9 1mo ago A 86 tokens

vigolium-scanner

15

vigolium/skills

Skill Claude CodeCodex

Use when operating the vigolium CLI for web vulnerability scanning, security testing, or traffic analysis. Covers scanning a URL/spec/raw request, running AI agent scans (autopilot, swarm, audit, query), triaging findings, confirming them with replay/fuzz, handing off to Burp, browsing stored traffic, writing…

9 20d ago A 85 tokens

draugr CLAUDE.md

16

draugr-dev/draugr

Instructions file

Instructions for draugr-dev/draugr, covering working on draugr, what draugr is, layout, before you open a pr and design principles.

4 2d ago A 2,807 tokens original Apache-2.0

draugr

17

draugr-dev/draugr

MCP server Claude CodeCodexCursor +2

MCP server "draugr" as configured in draugr-dev/draugr. Launched with https://github.com/draugr-dev/draugr/releases/download/v0.99.1/draugr-0.99.1.mcp.

4 2d ago A tokens not measured original Apache-2.0

auth-flow-auditor

18

HermeticOrmus/LibreSecOps-Claude-Code

Agent

You are Auth Flow Auditor, an authentication and authorization specialist who has reviewed enterprise identity systems, OAuth implementations, and custom auth flows across every major framework. You know that authentication bugs are rarely in the crypto -- they're in the logic. Redirect URI validation that allows open…

4 3mo ago A 0 tokens original MIT

detection-engineer

20

HermeticOrmus/LibreSecOps-Claude-Code

Agent

You are the Detection Engineer, a specialist in translating adversary behavior into automated detection rules that trigger reliably on malicious activity while minimizing false positives. You think in terms of data sources, telemetry coverage, and detection logic. For every ATT&CK technique, you know what telemetry is…

4 3mo ago A 0 tokens original MIT

HermeticOrmus/LibreSecOps-Claude-Code

Skill Claude CodeCodex

Threat hunting is the proactive, analyst-driven search for threats that have evaded automated detection. Unlike detection engineering (which builds rules that fire automatically), hunting is a human-led investigation that uses hypotheses, data analysis, and domain expertise to find adversary activity that does not…

4 3mo ago A 0 tokens original MIT

crypto-algorithms

24

HermeticOrmus/LibreSecOps-Claude-Code

Skill Claude CodeCodex

Skill "crypto-algorithms" from HermeticOrmus/LibreSecOps-Claude-Code, covering crypto algorithms, knowledge base, the algorithm decision tree, key size guidelines (2025+) and modes of operation (symmetric encryption).

4 3mo ago A 0 tokens original MIT