Install
$ agentstack add skill-0x-professor-agent-skills-hub-web-security-auditor ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Web Security Auditor
Objective
Perform a comprehensive web application security review aligned to OWASP Top 10 and practical production hardening controls.
Required Workflow
A. Static Analysis (SAST)
- Run Semgrep for injection, secrets, crypto misuse, and prototype pollution.
- Run ESLint security plugins (
eslint-plugin-security,eslint-plugin-no-unsanitized). - Run Bandit for Python codebases.
B. Dependency Scanning (SCA)
- Run
npm audit,pip-audit, orcargo auditby stack. - Include Aikido Security or Snyk where available.
- Include Vulert for no-install open-source dependency checks.
C. Dynamic Analysis (DAST)
- Run OWASP ZAP automation/headless scans.
- Optionally run StackHawk.
- Optionally run Nuclei templates for quick vulnerability sweeps.
D. Secret Detection
- Run Gitleaks across repository and history.
- Run TruffleHog scan.
E. Frontend Security Checks
- Verify CSP (no unsafe inline/eval in production policy).
- Verify clickjacking protection (
X-Frame-Optionsorframe-ancestors). - Verify HSTS.
- Verify
X-Content-Type-Options: nosniff. - Verify no sensitive data in
localStorageand no exposed production source maps. - Check for XSS hazards (
dangerouslySetInnerHTML,innerHTML,eval).
F. Backend Security Checks
- Verify parameterized DB access / ORM usage.
- Verify strong JWT secret management and token expiry.
- Verify rate limiting on auth/sensitive routes.
- Verify strict CORS origins.
- Verify input validation on all endpoints.
- Verify secure password hashing (bcrypt/argon2).
- Check IDOR controls on user-owned resources.
G. API Security
- Include Akto or Escape.tech checks for business-logic and GraphQL/REST API risks.
Output
security-report.jsonwith findings grouped byCritical,High,Medium,Low
Execution
python skills/web-security-auditor/scripts/security_auditor.py --input --output --format json
References
references/tools.md
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: 0x-Professor
- Source: 0x-Professor/Agent-Skills-Hub
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.