[Skill Request]: Automated Web Application Security Assessment with OWASP ZAP
Proposed Skill Name
performing-web-application-security-assessment-with-owasp-zap
Category
Application Security
Skill Description
Teach an AI agent to perform authorized security assessments of web applications using OWASP ZAP. The skill should guide the agent through defining the authorized target, configuring passive and active scanning safely, identifying common web vulnerabilities, reviewing HTTP requests and responses, analyzing security headers, detecting issues such as XSS, SQL injection indicators, insecure cookies, authentication weaknesses, and exposed sensitive information, and mapping findings to appropriate remediation steps.
The agent should prioritize non-destructive testing, clearly distinguish confirmed findings from potential false positives, explain the evidence supporting each finding, assign severity and risk, and produce a structured security assessment report containing the vulnerability, affected endpoint, evidence, impact, severity, remediation, and verification steps.
The skill must only be used against systems for which the user has explicit authorization.
MITRE ATT&CK Technique(s)
T1190
Key Tools
OWASP ZAP ZAP Spider ZAP Passive Scanner ZAP Active Scanner ZAP API curl Burp Suite Community Edition Nmap
Source: mukul975/Anthropic-Cybersecurity-Skills