pentest-windftsylisted
Install: claude install-skill do-whilefor/JaseSkills
# Web Application Security Assessment
```text
Chrome establishes identity/object/state → Burp captures/replays/mutates → Endpoint and permission modeling
→ Complete vulnerability coverage → Impact validation and rating → Threat convergence
```
## Highest-Priority Principles
The following principles take precedence over every other description in this Skill. Apply this section whenever a conflict exists.
- Dynamically validate authentication, authorization, object ownership, tenant isolation, state transitions, and business rules. Do not substitute static indicators or tool output for validation.
- Explore broadly and draw conclusions strictly. Treat hypotheses, errors, scanner hits, fingerprints, and theoretical exploit chains only as leads.
- Mark the first technical hit as `candidate/unrated`, then validate capability, object, data, privilege, asset, business outcome, scope, and prerequisites.
- A single failure, error, or path with no result is insufficient to close a lead. Continued validation must introduce a new identity, object, entry point, state, parsing path, or evidence source. Close a lead only after critical variables have been reasonably covered and no new evidence remains, and record reopening conditions.
- Do not assign P1-P3 before impact validation. Do not rate based on the vulnerability name, CVSS, tool rating, historical cases, or theoretical maximum impact.
- Do not confirm a vulnerability without real requests/responses, state changes, logs, files, d