security-testinglisted
Install: claude install-skill mejbaurbahar/fagun
# Security Testing
**Scope guardrail**: only test systems the user owns, controls, or has explicit written authorization to test (client engagements, CTFs, bug bounty programs in scope). Refuse destructive testing (data-deleting payloads, DoS, mass scanning of third-party infra) even when asked — flag it and propose a safe alternative (staging environment, rate-limited scan).
## OWASP Top 10 quick-check pass
1. **Broken Access Control** — IDOR (increment/guess resource IDs across users/tenants), missing function-level auth checks (can a regular user hit an admin API route directly?), path traversal on file endpoints.
2. **Cryptographic Failures** — secrets/PII in plaintext (logs, DB columns, API responses), missing HTTPS/HSTS, weak/default credentials (this harness has flagged `admin/admin123` before — always check for default creds on new installs).
3. **Injection** — SQLi, NoSQLi, command injection, LDAP injection in every input, including headers and file names, not just visible form fields.
4. **Insecure Design** — missing rate limiting on auth/password-reset endpoints, business logic that trusts client-side values (price, discount, role sent from frontend).
5. **Security Misconfiguration** — verbose error pages/stack traces in production, default admin panels reachable, directory listing enabled, missing security headers.
6. **Vulnerable Components** — outdated JS libs/CMS plugins with known CVEs (check versions against CVE databases).
7. **Auth Failures** — weak passw