/webapp-nikto
Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. Use when: (1) Conducting authorized web server security assessments, (2) Identifying common web vulnerabilities and misconfigurations, (3) Detecting outdated
$ npx -y skills add AgentSecOps/SecOpsAgentKit --skill webapp-nikto --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/webapp-nikto
Context preview
The summary Claude sees to decide when to auto-load this skill.
Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. Use when: (1) Conducting authorized web server security assessments, (2) Identifying common web vulnerabilities and misconfigurations, (3) Detecting outdated
SKILL.md
webapp-nikto.SKILL.mdname: webapp-nikto
description: >
Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated
software versions. Use when: (1) Conducting authorized web server security assessments, (2)
Identifying common web vulnerabilities and misconfigurations, (3) Detecting outdated server
software and known vulnerabilities, (4) Performing compliance scans for web server hardening,
(5) Enumerating web server information and enabled features, (6) Validating security controls
and patch levels.
version: 0.1.0
maintainer: sirappsec@gmail.com
category: offsec
tags: [web-security, vulnerability-scanner, nikto, server-security, web-assessment]
frameworks: [OWASP, CWE, NIST]
dependencies:
packages: [nikto]
tools: [perl]
references:
- https://cirt.net/Nikto2
- https://github.com/sullo/nikto
- https://owasp.org/www-project-web-security-testing-guide/
Nikto Web Server Scanner
Overview
Nikto is an open-source web server scanner that performs comprehensive tests against web servers for multiple security issues including dangerous files, outdated software versions, and server misconfigurations. This skill covers authorized security assessments of web servers and applications.
**IMPORTANT**: Nikto generates significant traffic and is easily detected. Only use with proper written authorization on systems you own or have explicit permission to test.
Quick Start
Basic web server scanning:
# Scan single host
nikto -h http://example.com
# Scan with SSL
nikto -h https://example.com
# Scan specific port
nikto -h example.com -p 8080
# Scan multiple ports
nikto -h example.com -p 80,443,8080
Core Workflow
Web Server Assessment Workflow
Progress: [ ] 1. Verify authorization for web server testing [ ] 2. Identify target web servers and ports [ ] 3. Perform initial reconnaissance scan [ ] 4. Run comprehensive vulnerability assessment [ ] 5. Analyze and categorize findings [ ] 6. Document vulnerabilities with remediation [ ] 7. Generate and deliver security report [ ] 8. Verify no testing artifacts remain
Work through each step systematically. Check off completed items.
1. Authorization Verification
**CRITICAL**: Before any web server scanning:
- Confirm written authorization from web server owner
- Verify scope includes web server vulnerability assessment
- Understand acceptable scanning windows
- Document emergency contact procedures
- Confirm no production impact restrictions
2. Basic Scanning
Perform basic web server scans:
# Standard scan
nikto -h http://example.com
# Scan with specific User-Agent
nikto -h http://example.com -useragent "Mozilla/5.0..."
# Scan through proxy
nikto -h http://example.com -useproxy http://proxy:8080
# Scan with authentication
nikto -h http://example.com -id username:password
# SSL/TLS scan
nikto -h https://example.com -ssl
# Force SSL even on non-standard ports
nikto -h example.com -p 8443 -ssl
3. Advanced Scanning Options
Customize scan behavior:
# Specify tuning options
nikto -h http://example.com -Tuning 123bde
# Enable all checks (very comprehensive)
nikto -h http://example.com -Tuning x
# Scan multiple hosts from file
nikto -h hosts.txt
# Limit to specific checks
nikto -h http://example.com -Plugins "apache_expect_xss"
# Update plugin database
nikto -update
# Display available plugins
nikto -list-plugins
**Tuning Options**:
- **0**: File Upload
- **1**: Interesting File/Seen in logs
- **2**: Misconfiguration/Default File
- **3**: Information Disclosure
- **4**: Injection (XSS/Script/HTML)
- **5**: Remote File Retrieval (Inside Web Root)
- **6**: Denial of Service
- **7**: Remote File Retrieval (Server Wide)
- **8**: Command Execution/Remote Shell
- **9**: SQL Injection
- **a**: Authentication Bypass
- **b**: Software Identification
- **c**: Remote Source Inclusion
- **d**: WebService
- **e**: Administrative Console
- **x**: Reverse Tuning (exclude specified)
4. Output and Reporting
Generate scan reports:
# Output to text file
nikto -h http://example.com -o results.txt
# Output to HTML report
nikto -h http://example.com -o results.html -Format html
# Output to CSV
nikto -h http://example.com -o results.csv -Format csv
# Output to XML
nikto -h http://example.com -o results.xml -Format xml
# Multiple output formats
nikto -h http://example.com -o results.txt -Format txt -o results.html -Format html
5. Performance Tuning
Optimize scan performance:
# Increase timeout (default 10 seconds)
nikto -h http://example.com -timeout 20
# Limit maximum execution time
nikto -h http://example.com -maxtime 30m
# Use specific HTTP version
nikto -h http://example.com -vhost example.com
# Follow redirects
nikto -h http://example.com -followredirects
# Disable 404 guessing
nikto -h http://example.com -no404
# Pause between tests
nikto -h http://example.com -Pause 2
6. Evasion and Stealth
Evade detection (authorized testing only):
# Use random User-Agent strings
nikto -h http://example.com -useragent random
# Inject random data in requests
nikto -h http://example.com -evasion 1
# Use IDS evasion techniques
nikto -h http://example.com -evasion 12345678
# Pause between requests
nikto -h http://example.com -Pause 5
# Use session cookies
nikto -h http://example.com -cookies "session=abc123"
**Evasion Techniques**:
- **1**: Random URI encoding
- **2**: Directory self-reference (/./)
- **3**: Premature URL ending
- **4**: Prepend long random string
- **5**: Fake parameter
- **6**: TAB as request spacer
- **7**: Change case of URL
- **8**: Use Windows directory separator (\)
Security Considerations
Authorization & Legal Compliance
- **Written Permission**: Obtain explicit authorization for web server scanning
- **Scope Verification**: Only scan explicitly authorized hosts and ports
- **Detection Risk**: Nikto is noisy and will trigger IDS/IPS alerts
- **Production Impact**: Scans
Read more
name: webapp-nikto description: > Web server vulnerability scanner for identifying security issues, misconfigurations, and outdated software versions. Use when: (1) Conducting authorized web server security assessments, (2) Identifying common web vulnerabilities and misconfigurations, (3) Detecting outdated server software and known vulnerabilities, (4) Performing compliance scans for web server hardening, (5) Enumerating web server information and enabled features, (6) Validating security controls and patch levels. version: 0.1.0 maintainer: sirappsec@gmail.com category: offsec tags: [web-security, vulnerability-scanner, nikto, server-security, web-assessment] frameworks: [OWASP, CWE, NIST] dependencies: packages: [nikto] tools: [perl] references: - https://cirt.net/Nikto2 - https://github.com/sullo/nikto - https://owasp.org/www-project-web-security-testing-guide/
Nikto Web Server Scanner
Overview
Nikto is an open-source web server scanner that performs comprehensive tests against web servers for multiple security issues including dangerous files, outdated software versions, and server misconfigurations. This skill covers authorized security assessments of web servers and applications.
**IMPORTANT**: Nikto generates significant traffic and is easily detected. Only use with proper written authorization on systems you own or have explicit permission to test.
Quick Start
Basic web server scanning:
# Scan single host nikto -h http://example.com # Scan with SSL nikto -h https://example.com # Scan specific port nikto -h example.com -p 8080 # Scan multiple ports nikto -h example.com -p 80,443,8080
Core Workflow
Web Server Assessment Workflow
Progress: [ ] 1. Verify authorization for web server testing [ ] 2. Identify target web servers and ports [ ] 3. Perform initial reconnaissance scan [ ] 4. Run comprehensive vulnerability assessment [ ] 5. Analyze and categorize findings [ ] 6. Document vulnerabilities with remediation [ ] 7. Generate and deliver security report [ ] 8. Verify no testing artifacts remain
Work through each step systematically. Check off completed items.
1. Authorization Verification
**CRITICAL**: Before any web server scanning:
- Confirm written authorization from web server owner
- Verify scope includes web server vulnerability assessment
- Understand acceptable scanning windows
- Document emergency contact procedures
- Confirm no production impact restrictions
2. Basic Scanning
Perform basic web server scans:
# Standard scan nikto -h http://example.com # Scan with specific User-Agent nikto -h http://example.com -useragent "Mozilla/5.0..." # Scan through proxy nikto -h http://example.com -useproxy http://proxy:8080 # Scan with authentication nikto -h http://example.com -id username:password # SSL/TLS scan nikto -h https://example.com -ssl # Force SSL even on non-standard ports nikto -h example.com -p 8443 -ssl
3. Advanced Scanning Options
Customize scan behavior:
# Specify tuning options nikto -h http://example.com -Tuning 123bde # Enable all checks (very comprehensive) nikto -h http://example.com -Tuning x # Scan multiple hosts from file nikto -h hosts.txt # Limit to specific checks nikto -h http://example.com -Plugins "apache_expect_xss" # Update plugin database nikto -update # Display available plugins nikto -list-plugins
**Tuning Options**:
- **0**: File Upload
- **1**: Interesting File/Seen in logs
- **2**: Misconfiguration/Default File
- **3**: Information Disclosure
- **4**: Injection (XSS/Script/HTML)
- **5**: Remote File Retrieval (Inside Web Root)
- **6**: Denial of Service
- **7**: Remote File Retrieval (Server Wide)
- **8**: Command Execution/Remote Shell
- **9**: SQL Injection
- **a**: Authentication Bypass
- **b**: Software Identification
- **c**: Remote Source Inclusion
- **d**: WebService
- **e**: Administrative Console
- **x**: Reverse Tuning (exclude specified)
4. Output and Reporting
Generate scan reports:
# Output to text file nikto -h http://example.com -o results.txt # Output to HTML report nikto -h http://example.com -o results.html -Format html # Output to CSV nikto -h http://example.com -o results.csv -Format csv # Output to XML nikto -h http://example.com -o results.xml -Format xml # Multiple output formats nikto -h http://example.com -o results.txt -Format txt -o results.html -Format html
5. Performance Tuning
Optimize scan performance:
# Increase timeout (default 10 seconds) nikto -h http://example.com -timeout 20 # Limit maximum execution time nikto -h http://example.com -maxtime 30m # Use specific HTTP version nikto -h http://example.com -vhost example.com # Follow redirects nikto -h http://example.com -followredirects # Disable 404 guessing nikto -h http://example.com -no404 # Pause between tests nikto -h http://example.com -Pause 2
6. Evasion and Stealth
Evade detection (authorized testing only):
# Use random User-Agent strings nikto -h http://example.com -useragent random # Inject random data in requests nikto -h http://example.com -evasion 1 # Use IDS evasion techniques nikto -h http://example.com -evasion 12345678 # Pause between requests nikto -h http://example.com -Pause 5 # Use session cookies nikto -h http://example.com -cookies "session=abc123"
**Evasion Techniques**:
- **1**: Random URI encoding
- **2**: Directory self-reference (/./)
- **3**: Premature URL ending
- **4**: Prepend long random string
- **5**: Fake parameter
- **6**: TAB as request spacer
- **7**: Change case of URL
- **8**: Use Windows directory separator (\)
Security Considerations
Authorization & Legal Compliance
- **Written Permission**: Obtain explicit authorization for web server scanning
- **Scope Verification**: Only scan explicitly authorized hosts and ports
- **Detection Risk**: Nikto is noisy and will trigger IDS/IPS alerts
- **Production Impact**: Scans
An assortment of security operations skills for AI coding agents. A collaborative approach to shift-left security using Claude Code skills.
Other skills on secopsagentkit.
- /api-mitmproxy
Interactive HTTPS proxy for API security testing with traffic interception, modification, and replay capabilities. Supports HTTP/1, HTTP/2, HTTP/3, WebSockets, and TLS-protected protocols. Includes Python scripting API for automation and multiple interfaces (console, web, CLI).
Open skill - /api-spectral
API specification linting and security validation using Stoplight's Spectral with support for OpenAPI, AsyncAPI, and Arazzo specifications. Validates API definitions against security best practices, OWASP API Security Top 10, and custom organizational standards. Use when: (1)
Open skill - /dast-ffuf
Fast web fuzzer for DAST testing with directory enumeration, parameter fuzzing, and virtual host discovery. Written in Go for high-performance HTTP fuzzing with extensive filtering capabilities. Supports multiple fuzzing modes (clusterbomb, pitchfork, sniper) and recursive
Open skill - /dast-nuclei
Fast, template-based vulnerability scanning using ProjectDiscovery's Nuclei with extensive community templates covering CVEs, OWASP Top 10, misconfigurations, and security issues across web applications, APIs, and infrastructure. Use when: (1) Performing rapid vulnerability
Open skill - /dast-zap
Dynamic application security testing (DAST) using OWASP ZAP (Zed Attack Proxy) with passive and active scanning, API testing, and OWASP Top 10 vulnerability detection. Use when: (1) Performing runtime security testing of web applications and APIs, (2) Detecting vulnerabilities
Open skill - /sast-bandit
Python security vulnerability detection using Bandit SAST with CWE and OWASP mapping. Use when: (1) Scanning Python code for security vulnerabilities and anti-patterns, (2) Identifying hardcoded secrets, SQL injection, command injection, and insecure APIs, (3) Generating
Open skill

