← ClaudeAtlas

pentestlisted

Authorised dynamic security testing of the project's OWN application (dev/staging or explicitly approved prod) — OWASP ZAP baseline/API scan (OpenAPI/GraphQL), Nuclei, Schemathesis fuzzing, testssl.sh, nmap on the project's own host, manual OWASP checks for auth/IDOR/GraphQL limits; report with CVSS and fixes in docs/security/pentest-<date>.md. Scope must be confirmed first.
gonimar/claude-web-studio · ★ 0 · Web & Frontend · score 76
Install: claude install-skill gonimar/claude-web-studio
# Pentest (the project's own application) Reply in the project conversation language (CLAUDE.md → Language); code, identifiers, paths and commit messages stay in English. Template `templates/pentest-report.md`; reference `stack-reference/security-standards.md`. **The scope is fixed before the first request**: only the project's own hosts/domains from technical-preferences/deployment docs; production only with an explicit "yes" and in an agreed window. Targets outside the project are refused. ## Phase 1: Scope and confirmation `AskUserQuestion`: target (URL), environment, window, accounts for authenticated checks, exclusions (payments, e-mails). Record the scope as the report's first section. ## Phase 2: Tools (whatever is installed; otherwise docker images with consent) ZAP baseline → full/API scan (OpenAPI or GraphQL introspection on dev); Nuclei (web/misconfig templates); Schemathesis on OpenAPI / GraphQL fuzzing; `testssl.sh`; `nmap -sV` on the project's own host; manual checks: IDOR (two accounts), GraphQL field permissions, depth/batching limits, login rate limit, password reset, uploads, CSRF/CORS, headers. `--quick` — ZAP baseline + headers + testssl only. ## Phase 3: Findings Severity/CVSS, steps, evidence (no secrets), fix (code/config), verification after the fix; "clean" areas listed. ## Phase 4: Write "May I write `docs/security/pentest-<date>.md`?" — one `AskUserQuestion`: write (Recommended) · show the draft/diff first · not now. Stories for High+. After t