Loading skill
Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | 47% | 0% |
| case-08 | ✗→✓ | ▲ Improved | -18% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 25% | 0% |
| case-10 | ✗→✓ | ▲ Improved | 22% | 0% |
| case-15 | ✗→✓ | ▲ Improved | -16% | 0% |
Specialized workflow for testing web applications against OWASP Top 10 vulnerabilities including injection attacks, XSS, broken authentication, and access control issues.
Use this workflow when:
scanning-tools - Security scanningtop-web-vulnerabilities - OWASP knowledgeUse @scanning-tools to perform web application reconnaissancesql-injection-testing - SQL injectionsqlmap-database-pentesting - SQLMapUse @sql-injection-testing to test for SQL injectionUse @sqlmap-database-pentesting to automate SQL injection testingxss-html-injection - XSS testinghtml-injection-testing - HTML injectionUse @xss-html-injection to test for cross-site scriptingbroken-authentication - Authentication testingUse @broken-authentication to test authentication securityidor-testing - IDOR testingfile-path-traversal - Path traversalUse @idor-testing to test for insecure direct object referencesUse @file-path-traversal to test for path traversalapi-security-best-practices - Security headersUse @api-security-best-practices to audit security headersreporting-standards - Security reportingUse @reporting-standards to create security reportsecurity-audit - Security auditingapi-security-testing - API securitywordpress-security - WordPress securityOther measured skills in the registry, with their headline benchmark lift.