Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection. Use when: (1) Performing runtime security testing of web applications and APIs, (2) Detecting vulnerabilities like XSS, SQL injection, and authentication flaws in deployed applications, (3) Automating security scans in CI/CD pipelines with Docker containers, (4) Conducting authenticated testing with session management, (5) Generating security reports with OWASP and CWE mappings for compliance.
Inherits all available tools
Additional assets for this skill
This skill inherits all available tools. When active, it can use any tool Claude has access to.
assets/github_action.ymlassets/gitlab_ci.ymlassets/zap_automation.yamlassets/zap_context.xmlreferences/EXAMPLE.mdreferences/api_testing_guide.mdreferences/authentication_guide.mdreferences/false_positive_handling.mdreferences/owasp_mapping.md