Proposed Skill Name
performing-web-application-security-assessment-with-owasp-zap
Category
Application Security
Skill Description
Teach an AI agent to perform authorized security assessments of web applications using OWASP ZAP. The skill should guide the agent through defining the authorized target, configuring passive and active scanning safely, identifying common web vulnerabilities, reviewing HTTP requests and responses, analyzing security headers, detecting issues such as XSS, SQL injection indicators, insecure cookies, authentication weaknesses, and exposed sensitive information, and mapping findings to appropriate remediation steps.
The agent should prioritize non-destructive testing, clearly distinguish confirmed findings from potential false positives, explain the evidence supporting each finding, assign severity and risk, and produce a structured security assessment report containing the vulnerability, affected endpoint, evidence, impact, severity, remediation, and verification steps.
The skill must only be used against systems for which the user has explicit authorization.
MITRE ATT&CK Technique(s)
T1190
Key Tools
OWASP ZAP
ZAP Spider
ZAP Passive Scanner
ZAP Active Scanner
ZAP API
curl
Burp Suite Community Edition
Nmap
Proposed Skill Name
performing-web-application-security-assessment-with-owasp-zap
Category
Application Security
Skill Description
Teach an AI agent to perform authorized security assessments of web applications using OWASP ZAP. The skill should guide the agent through defining the authorized target, configuring passive and active scanning safely, identifying common web vulnerabilities, reviewing HTTP requests and responses, analyzing security headers, detecting issues such as XSS, SQL injection indicators, insecure cookies, authentication weaknesses, and exposed sensitive information, and mapping findings to appropriate remediation steps.
The agent should prioritize non-destructive testing, clearly distinguish confirmed findings from potential false positives, explain the evidence supporting each finding, assign severity and risk, and produce a structured security assessment report containing the vulnerability, affected endpoint, evidence, impact, severity, remediation, and verification steps.
The skill must only be used against systems for which the user has explicit authorization.
MITRE ATT&CK Technique(s)
T1190
Key Tools
OWASP ZAP
ZAP Spider
ZAP Passive Scanner
ZAP Active Scanner
ZAP API
curl
Burp Suite Community Edition
Nmap