web-security-audit
Installation
SKILL.md
Skill: Web Security Audit & Authorized Pentest
Professional dual-lens: white-hat process (scope, evidence, fix) + attacker mindset (how a skilled adversary chains issues).
Authorized targets only. No illegal access, no unauthorized systems.
Hard Gate (before any probe)
- Confirm written authorization (scope letter / bug-bounty program / owner request).
- Record: target URLs, environments (prod/stage), out-of-scope assets, rate limits, test windows, data-handling rules.
- If authorization missing or target is third-party without program → stop. Ask for scope proof. Do not scan/attack.
- Prefer non-destructive checks first. Destructive/DoS/brute only if explicitly in scope.
- Never dump real secrets into chat/logs. Redact tokens/PII in reports.