[Skill Request]: Automated Web Application Security Assessment with OWASP ZAP

Author: kartiklunagariya3-bitCreated Aug 15, 2026Updated Aug 17, 2026
Labelsenhancementhelp wantednew-skill

Proposed Skill Name

performing-web-application-security-assessment-with-owasp-zap

Category

Application Security

Skill Description

Teach an AI agent to perform authorized security assessments of web applications using OWASP ZAP. The skill should guide the agent through defining the authorized target, configuring passive and active scanning safely, identifying common web vulnerabilities, reviewing HTTP requests and responses, analyzing security headers, detecting issues such as XSS, SQL injection indicators, insecure cookies, authentication weaknesses, and exposed sensitive information, and mapping findings to appropriate remediation steps.

The agent should prioritize non-destructive testing, clearly distinguish confirmed findings from potential false positives, explain the evidence supporting each finding, assign severity and risk, and produce a structured security assessment report containing the vulnerability, affected endpoint, evidence, impact, severity, remediation, and verification steps.

The skill must only be used against systems for which the user has explicit authorization.

MITRE ATT&CK Technique(s)

T1190

Key Tools

OWASP ZAP ZAP Spider ZAP Passive Scanner ZAP Active Scanner ZAP API curl Burp Suite Community Edition Nmap

Source: mukul975/Anthropic-Cybersecurity-Skills