pentest-audit
Pentest and security-audit a running Spring Boot app — OWASP ZAP DAST scans, manual probes for auth, headers, CORS, actuator, and error leakage, and a findings report with fixes. Use when asked to pentest an app, run a DAST scan, or audit whether an app is secure end to end. Not for dependency/SBOM/image scanning — use security-hardening. Not for adding auth — use spring-security.
Pinned to revision b9857f69c5d3, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/pentest-audit/SKILL.md
- skills/pentest-audit/assets/templates/pentest-report.md
- skills/pentest-audit/references/pentest-checklist.md
Every link opens the file at its source, pinned to the revision this page describes.