Agent Skills

web-security-review

Review web applications against the OWASP Top 10 for Web Applications (2021). Use when auditing web apps, reviewing server-side code, or assessing web frameworks for the classic OWASP Top 10 risks including injection, broken auth, and XSS.

Install

npx skills add https://github.com/owasp/secure-agent-playbook --skill web-security-review
SKILL.md

Web Security Review (OWASP Top 10)

Review web applications against all 10 OWASP Top 10 risks by following the full procedure in plays/owasp-top10-web-review.md.

Steps

  1. Application Mapping — Identify framework/language, deployment model (monolith/microservices), trust boundaries (internet/internal/local), data sensitivity (PII, financial, health), and authentication mechanisms.

  2. Assess Each OWASP Top 10 Risk:

    • A01 Broken Access Control — Missing authz checks, IDOR, privilege escalation, path traversal, CORS misconfigurations
    • A02 Cryptographic Failures — Weak algorithms, missing TLS, hardcoded keys, improper key management, cleartext storage
    • A03 Injection — SQLi, NoSQLi, OS command injection, LDAP injection, XSS, SSTI, XPath injection
    • A04 Insecure Design — Missing security requirements, business logic flaws, insecure workflows, threat modeling gaps
    • A05 Security Misconfiguration — Default configs, verbose errors, missing headers, unnecessary features, outdated components
    • A06 Vulnerable Components — Unpatched libraries, unsupported dependencies, lack of inventory, missing SBOM
    • A07 Identification & Auth Failures — Weak passwords, session issues, MFA gaps, credential stuffing, brute force
    • A08 Software & Data Integrity Failures — Insecure deserialization, unsigned updates, CI/CD attacks, dependency confusion
    • A09 Security Logging & Monitoring Failures — Missing audit logs, insufficient monitoring, no incident response capability
    • A10 Server-Side Request Forgery (SSRF) — Unvalidated URL parameters, internal service access, cloud metadata endpoints
  3. Framework-Specific Analysis — Apply checks for detected framework (React, Angular, Vue, Express, Django, Flask, Rails, Spring, ASP.NET, Laravel).

  4. Configuration Review — Examine web server configs (nginx, Apache), application configs, and deployment manifests for security settings.

Output

Application overview, risk matrix for all 10 categories with severity/status, detailed findings using templates/finding.md, positive controls observed, and prioritized remediation roadmap.

OWASP References

  • OWASP Top 10 for Web Applications (2021)
  • OWASP ASVS v5.0 — Application Security Verification Standard
  • OWASP Testing Guide (WSTG)
  • OWASP Cheat Sheet Series

Related skills

azure-compliancemicrosoft606KRun Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.firebase-security-rules-auditorfirebase124KAudits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.browser-fingerprint-auditliarjsdev69KAudit a browser fingerprint for internal contradictions with the liarjs CLI - canvas, WebGL, WebGL2, WebGPU, audio, 220 fonts, WebRTC and timezone probes, scored against the TLS/HTTP/ASN view of the same request. Use when asked to run a browser fingerprint test, see what a fingerprint looks like, check canvas or WebGL fingerprint stability, compare a spoofed profile against a real browser, or find out whether a browser profile is self-consistent.cloudflare-onecloudflare66KDesign, configure, troubleshoot, or review Cloudflare One Zero Trust and SASE deployments. Use cloudflare-one-migrations for migration planning from other vendors.

Search skills and MCP servers

Fuzzy search across 23,137 skills and servers