dast skills

85 tagged dast, measured the same way as everything else here.

Browse within: devsecops 57appsec 47cybersecurity 35bug-bounty 34application-security 19libre-x-claude-code 19agentforce 14appexchange 14claude-code-plugins 14gemini-cli-extension 9github-copilot 9

dast-nuclei

01

AgentSecOps/SecOpsAgentKit

Skill Claude CodeCodex

Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web applications, APIs, and infrastructure. Use when: (1) Performing rapid vulnerability scanning with automated CVE detection, (2)…

201 4mo ago A 129 tokens

dast-config

02

UnitOneAI/SecuritySkills

Skill Claude CodeCodex

Reviews DAST tool configurations against OWASP Top 10:2021 and OWASP Testing Guide v4.2. Auto-invoked when reviewing OWASP ZAP configurations, DAST CI/CD integration, scan policies, or authenticated scanning setups. Produces a DAST maturity assessment covering scan policy configuration, active vs passive scanning, API…

56 2mo ago A 83 tokens original MIT

fortify-fod

03

fortify/skills

Skill Claude CodeCodex

Perform tasks against Fortify on Demand (FoD): query applications/releases; query & triage existing security issues in FoD; start & monitor full SAST/DAST/SCA/open source scans of the codebase; create releases; import FPR/SARIF/CycloneDX artifacts; policy and portfolio analysis. NOT for lightweight AI review of local…

19 1mo ago A 88 tokens original MIT

fortify-remediate

04

fortify/skills

Skill Claude CodeCodex

Remediate SAST (static) and DAST (dynamic) security vulnerabilities ALREADY detected by Fortify in FoD or SSC — fix specific issues, categories, or reduce issue counts, including applying SAST Aviator fixes. For SCA / open source dependency findings (vulnerable third-party components, CVEs), use…

19 1mo ago A 117 tokens original MIT

fortify-ssc

05

fortify/skills

Skill Claude CodeCodex

Perform tasks against Fortify SSC (Software Security Center): query applications/application versions; query & triage existing security issues in SSC; start & monitor full ScanCentral SAST/DAST scans or upload FPR artifacts; create app versions; policy and portfolio analysis. NOT for lightweight AI review of local…

19 1mo ago A 76 tokens original MIT

jwt_tool

06

tr4m0ryp/shor

Skill Claude CodeCodex

Skill "jwt_tool" from tr4m0ryp/shor, covering jwttool — jwt analysis & attacks, when to reach for it, key flags / modes, safe invocation and form field (oidc-style).

9 1mo ago A 52 tokens

authz-recipe

07

tr4m0ryp/shor

Skill Claude CodeCodex

Broken Access Control is OWASP #1, but there is no drop-in CLI (Autorize / AuthMatrix are Burp extensions). This is the procedure that carries the whole category: an authorization-matrix + A/B session-replay method driving curl, the playwright skill (per-identity sessions), and ffuf (ID enumeration). Live →…

9 1mo ago A 62 tokens

tr4m0ryp/shor

Skill Claude CodeCodex

A small recipe over the already-cloned repo. It runs git log --grep for security/CVE/fix patterns, maps the touched files into ranked hot files, and emits historicalsignal.json. It optionally folds in two signals you may have ALREADY produced this phase — osv-scanner JSON (dependency CVEs) and gitleaks JSON (history…

9 1mo ago A 86 tokens

vigolium-scanner

09

vigolium/skills

Skill Claude CodeCodex

Use when operating the vigolium CLI for web vulnerability scanning, security testing, or traffic analysis. Covers scanning a URL/spec/raw request, running AI agent scans (autopilot, swarm, audit, query), triaging findings, confirming them with replay/fuzz, handing off to Burp, browsing stored traffic, writing…

9 18d ago A 85 tokens

HermeticOrmus/LibreSecOps-Claude-Code

Skill Claude CodeCodex

Threat hunting is the proactive, analyst-driven search for threats that have evaded automated detection. Unlike detection engineering (which builds rules that fire automatically), hunting is a human-led investigation that uses hypotheses, data analysis, and domain expertise to find adversary activity that does not…

4 3mo ago A 0 tokens original MIT

audit-codebase

13

runverdict/sf-security-review-toolkit

Skill Claude CodeCodex

Phase 1 of security review prep. Runs the autonomous multi-agent white-box audit of the partner's own codebase across the applicable threat dimensions — find, adversarially verify, synthesize — maintaining a findings ledger that makes every re-run incremental. Use after scope-submission, after fixing findings, or…

2 27d ago A 76 tokens original Apache-2.0

run-scans

14

runverdict/sf-security-review-toolkit

Skill Claude CodeCodex

Phase 3 of security review prep. Orchestrates every scan family the review consumes — Code Analyzer (package SAST), the Partner Security Portal scanner check, authenticated DAST (+ Nuclei/Schemathesis) plan generation, TLS grading (SSL Labs or local testssl/sslyze), dependency audits, secret scan, and the…

2 27d ago A 177 tokens original Apache-2.0

runverdict/sf-security-review-toolkit

Skill Claude CodeCodex

Autonomous driver for AppExchange/AgentExchange security-review SUBMISSION readiness. Runs a seconds-long preflight (greps + architecture detection + sf CLI auto-resolve when authed), emits one 3-tier preflight report, then drives the whole journey end to end — scope, static scans, audit, artifacts, live scans…

2 27d ago A 183 tokens original Apache-2.0