common-architecture-di…
Draw architecture diagrams as editable draw.io files with a fixed house style, C4 levels, and evidence-tagged shapes. Use when producing a system context,…
Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, and AI-driven curl probes. Use when advising on or running dynamic security scans on
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill common-dast-tooling --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/common-dast-toolingContext preview
The summary Claude sees to decide when to auto-load this skill.
Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, and AI-driven curl probes. Use when advising on or running dynamic security scans on
name: common-dast-tooling
description: Standardize dynamic application security testing for backend APIs, frontend web apps, and mobile clients. Covers ZAP, Nuclei, Nikto, sqlmap, ffuf, browser automation, mobile proxy interception, and AI-driven curl probes. Use when advising on or running dynamic security scans on local/staging environments.
metadata:
triggers:
keywords:
- DAST
- dynamic scan
- zap
- nuclei
- nikto
- curl probe
- pentest
- dynamic analysis
- sqlmap
- ffuf
- mobile proxySee [implementation guide](references/implementation.md) for setup commands.
When automated tools unavailable, generate targeted `curl` probes:
See [implementation guide](references/implementation.md) for all commands.
| Finding | Severity | Deduction | |---|---|---| | Unauthenticated access to private data | P0 | -25 | | Successful SQLi/RCE via probe | P0 | -20 | | Mobile API interception (no cert pin) | P1 | -15 | | DOM XSS confirmed via browser | P1 | -10 | | Info Leakage (Server versions/Env vars) | P1 | -10 | | Missing security headers (CSP/HSTS) | P2 | -5 |
The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.
Repo: hoangnguyen0403/agent-skills-standard
Draw architecture diagrams as editable draw.io files with a fixed house style, C4 levels, and evidence-tagged shapes. Use when producing a system context,…
Enforce SOLID principles, guard-clause style, function size limits, and intention-revealing naming across all languages. Use when refactoring for readability,…
Standardize BRD and BRD-lite discovery for business goals, stakeholder impact, current-to-future state, and measurable value outcomes. Use when creating BRD,…
Conduct high-quality, persona-driven code reviews. Use when reviewing PRs, critiquing code quality, or analyzing changes for team feedback.
Maximize context window efficiency, reduce latency, and prevent lost-in-middle issues through strategic masking and compaction. Use when token budgets are…
Troubleshoot systematically using the Scientific Method. Use when debugging crashes, tracing errors, diagnosing unexpected behavior, or investigating…