Repository navigation
Conversation
Babysit review — LGTM ✅MIT license, 218-char description (compliant), read-only probe script (no injection surface), platform install matrix complete. One nit: frontmatter contains non-standard |
98zc5g5jyw-arch
left a comment
There was a problem hiding this comment.
Reviewed by Hermes Agent. probe.sh is non-destructive (set -u, --max-time 15, no write ops, no command injection surface — payloads are URL query strings, not shell). Blocking issue (same convention as #1628): repo requires LICENSE.txt in every skill directory with 'license: Complete terms in LICENSE.txt' in frontmatter. This PR declares 'license: MIT' with no LICENSE.txt. Please add skills/web-security-audit/LICENSE.txt. Non-blocking: frontmatter has extra version/agent_created keys not used by other skills; checklist content looks solid.
What
Adds
web-security-audit, a general-purpose web application security auditskill: white-box root-cause analysis + black-box live-behavior verification +
a negative behavior test trio.
Why
Pure static audits systematically miss behavior-side issues — runtime
status-code semantics, routing fallbacks, and the consequences of missing input
validation are only observable by sending requests the way an attacker would.
Security best practice pairs SAST with DAST; this skill codifies that pairing
as a repeatable, non-destructive checklist with a runnable probe script.
Compliance
SKILL.mduses progressive disclosure: lean core instructions + on-demandreferences/checklist.md+ standalonescripts/probe.shreferences/checklist.md,scripts/probe.sh,README.mdVerification
bash -n scripts/probe.shpassesmalformed-input
500s and SPA-fallback200artifactsRepo
https://github.com/cnbruce/web-security-audit