Skip to content

Add web-security-audit skill - #1614

Open
cnbruce wants to merge 8 commits into
anthropics:mainfrom
cnbruce:web-security-audit
Open

cnbruce wants to merge 8 commits into
anthropics:mainfrom
cnbruce:web-security-audit

Conversation

@cnbruce

@cnbruce cnbruce commented Aug 20, 2026 •

Copy link
Copy Markdown

What

Adds web-security-audit, a general-purpose web application security audit
skill: white-box root-cause analysis + black-box live-behavior verification +
a negative behavior test trio
.

Why

Pure static audits systematically miss behavior-side issues — runtime
status-code semantics, routing fallbacks, and the consequences of missing input
validation are only observable by sending requests the way an attacker would.
Security best practice pairs SAST with DAST; this skill codifies that pairing
as a repeatable, non-destructive checklist with a runnable probe script.

Compliance

  • Follows the Agent Skills open standard (https://agentskills.io/specification)
  • SKILL.md uses progressive disclosure: lean core instructions + on-demand
    references/checklist.md + standalone scripts/probe.sh
  • Bundled resources: references/checklist.md, scripts/probe.sh, README.md
  • License: MIT
  • Safety: authorized targets only; all probes are harmless verification requests

Verification

  • bash -n scripts/probe.sh passes
  • Structure validated with the Agent Skills packager (package_skill.py)
  • Probe script field-tested against live production targets: correctly flagged
    malformed-input 500s and SPA-fallback 200 artifacts

Repo

https://github.com/cnbruce/web-security-audit

@98zc5g5jyw-arch

Copy link
Copy Markdown

Babysit review — LGTM ✅

MIT license, 218-char description (compliant), read-only probe script (no injection surface), platform install matrix complete. One nit: frontmatter contains non-standard agent_created: true and a Chinese description — fine, but double-check agentskills.io spec compatibility if that matters to maintainers.

@98zc5g5jyw-arch 98zc5g5jyw-arch left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed by Hermes Agent. probe.sh is non-destructive (set -u, --max-time 15, no write ops, no command injection surface — payloads are URL query strings, not shell). Blocking issue (same convention as #1628): repo requires LICENSE.txt in every skill directory with 'license: Complete terms in LICENSE.txt' in frontmatter. This PR declares 'license: MIT' with no LICENSE.txt. Please add skills/web-security-audit/LICENSE.txt. Non-blocking: frontmatter has extra version/agent_created keys not used by other skills; checklist content looks solid.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants