Skip to content

[Skill Request]: Automated Web Application Security Assessment with OWASP ZAP #121

Description

@kartiklunagariya3-bit

Proposed Skill Name

performing-web-application-security-assessment-with-owasp-zap

Category

Application Security

Skill Description

Teach an AI agent to perform authorized security assessments of web applications using OWASP ZAP. The skill should guide the agent through defining the authorized target, configuring passive and active scanning safely, identifying common web vulnerabilities, reviewing HTTP requests and responses, analyzing security headers, detecting issues such as XSS, SQL injection indicators, insecure cookies, authentication weaknesses, and exposed sensitive information, and mapping findings to appropriate remediation steps.

The agent should prioritize non-destructive testing, clearly distinguish confirmed findings from potential false positives, explain the evidence supporting each finding, assign severity and risk, and produce a structured security assessment report containing the vulnerability, affected endpoint, evidence, impact, severity, remediation, and verification steps.

The skill must only be used against systems for which the user has explicit authorization.

MITRE ATT&CK Technique(s)

T1190

Key Tools

OWASP ZAP
ZAP Spider
ZAP Passive Scanner
ZAP Active Scanner
ZAP API
curl
Burp Suite Community Edition
Nmap

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requesthelp wantedExtra attention is needednew-skillNew skill contribution

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions