Agent skill

Dast Automation

by hardw00t in hardw00t/ai-security-arsenal

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

No licenceAuto-check passedSecurity

Install Dast Automation

skills CLI
$ npx skills add hardw00t/ai-security-arsenal --skill dast-automation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hardw00t/ai-security-arsenal dast-automation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hardw00t/ai-security-arsenal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dast-automation .claude/skills/dast-automation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dast-automation
GitHub stars
105
Token cost
~2.2k tokens
SKILL.md length
773 words
Files
49 (incl. scripts, references, assets)
Skills in repo
7
Repo updated
First seen
Licence
None found

At a glance

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

  • Requests like scan this domain
  • SKILL.md covers When to Use, Trigger Phrases, When NOT to Use This Skill and Decision Tree, plus 12 more sections
  • Calls apt, go and pip
  • Run DAST on these URLs

What it does

Dast Automation is an agent skill from hardw00t/ai-security-arsenal. Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Performs blackbox or greybox scans on single or multiple domains with orchestrated crawling, vulnerability detection, and structured output. Trigger on requests like "scan this domain", "run DAST on these URLs", "automated pentest", or "security-test the staging app".

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 53 other files, including scripts, reference files and assets (for example `README.md`, `assets/config/scanning.yaml` and `assets/config/scope.yaml`).

It sits in Security, covering Penetration testing, Structured output and tool calling and Browser testing. It works with Playwright and Model Context Protocol. The repository describes itself as: A collection of skills, agents, commands, and workflows for security researchers. Compatible with Claude Code, Claude Desktop, OpenCode, and other AI coding tools.

When your agent uses it

  • Requests like scan this domain
  • Run DAST on these URLs
  • Automated pentest
  • Security-test the staging app

Example prompts

  • “scan this domain”
  • “run DAST on these URLs”
  • “automated pentest”
  • “/dast-automation”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit a1a68f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • apt
    • go
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dast Automation loads about 2.2k tokens when it runs, and up to ~40k if it reads all its reference files. Until then it costs about 98 tokens; SKILL.md has 773 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~40k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 773 words (~2,194 tokens).

“Thin router. Specific guidance lives in workflows/, methodology/, payloads/, and examples/. Read this file first, then lazy-load only the files you need for the task.”

— opening of SKILL.md by hardw00t
name
dast-automation

Read the full SKILL.md on GitHub

Files

SKILL.md and 48 other files (scripts, references, assets) in skills/dast-automation of hardw00t/ai-security-arsenal.

  • SKILL.md
  • .DS_Store
  • README.md
  • assets/config/scanning.yaml
  • assets/config/scope.yaml
  • assets/payloads/sqli_payloads.txt
  • assets/payloads/xss_payloads.txt
  • examples/blackbox_basic.md
  • examples/continuous_setup.md
  • examples/github_actions_dast.yml
  • examples/greybox_multi_domain.md
  • methodology/crawling.md
  • methodology/recon.md
  • methodology/reporting.md
  • methodology/vuln_testing.md
  • payloads
  • … and 33 more

Open the folder on GitHubat commit a1a68f7

Compare with similar skills

Dast Automation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dast Automation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dast Automation this skillhardw00t/ai-security-arsenal105—~2.2kAutomated safety check: PassNone
Visible Browser for Manual Login CaptureEncod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT
Invisible Playwrightfeder-cr/invisible_dots32k—~989Automated safety check: PassMIT
Playwright E2E Testsonyx-dot-app/onyx32k1 repos~2.8kAutomated safety check: NotesCustom licence
Shogun Screenshotyohey-w/multi-agent-shogun1.4k—~901Automated safety check: NotesMIT
Playwright Debugvoicetreelab/voicetree924—~1.2kAutomated safety check: PassCustom licence

Similar skills

  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Invisible Playwright

    feder-cr/invisible_dots

    Use the Dot's browser (invisibleplaywright) for any task on a website: logging in, reading pages, filling forms, clicking through a site as a person would.

    32k GitHub stars~989 tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Playwright E2E Tests

    onyx-dot-app/onyx

    Write and maintain Playwright end-to-end tests for the Onyx application.

    32k GitHub starsUsed in 1 repo~2.8k tokens
    Testing & QAAuto-check: notes
  • Shogun Screenshot

    yohey-w/multi-agent-shogun

    スクリーンショットの取得・加工を行う。ローカルスクショから最新画像を取得、 PlaywrightでWebページをキャプチャ、画像のトリミング・リサイズ、機微情報を黒塗りマスキング。

    1.4k GitHub stars~901 tokensUpdated 2 mo ago
    Testing & QAAuto-check: notes
  • Playwright Debug

    voicetreelab/voicetree

    This skill should be used when the user asks to "debug the electron app", "connect playwright to VoiceTree", "take screenshots of the running app", "interact with the live UI", "inspect the running…

    924 GitHub stars~1.2k tokensUpdated 3 days ago
    Testing & QAAuto-check passed
  • Tool Design

    guanyang/open-agent-hub

    This skill should be used for the tool-interface layer of an agent system specifically: writing tool descriptions agents can route on, designing tool schemas and response formats, naming…

    977 GitHub starsUsed in 2 repos~5k tokens
    Agent WorkflowsAuto-check passed

More from hardw00t/ai-security-arsenal

  • Sast Orchestration

    hardw00t/ai-security-arsenal

    Static Application Security Testing orchestration — run and compose Semgrep, CodeQL, Bandit, gosec, Brakeman, SpotBugs, ESLint; author custom rules; ingest SARIF; triage and rank findings by…

    105 GitHub stars~2.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Iac Security

    hardw00t/ai-security-arsenal

    Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.

    105 GitHub stars~2.4k tokensUpdated 5 mo ago
    Auto-check passed
  • LLM Security

    hardw00t/ai-security-arsenal

    LLM and AI application security testing skill for prompt injection (direct, indirect, multimodal), system-prompt extraction, RAG poisoning, memory poisoning, MCP server injection, skill-file…

    105 GitHub stars~2.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Sca Security

    hardw00t/ai-security-arsenal

    Software Composition Analysis: find vulnerable dependencies, correlate CVE/GHSA/OSV across ecosystems, generate CycloneDX/SPDX SBOMs, assess license compliance, and run reachability-aware triage to…

    105 GitHub stars~3k tokensUpdated 5 mo ago
    Auto-check passed
  • Threat Modeling

    hardw00t/ai-security-arsenal

    Systematic threat modeling skill for applications, APIs, and systems using STRIDE, PASTA, Attack Trees, DREAD, LINDDUN, and OCTAVE.

    105 GitHub stars~2.6k tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Dast Automation

What does Dast Automation do?

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. Dast Automation is an agent skill from hardw00t/ai-security-arsenal. Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

When should I use Dast Automation?

Dast Automation fits situations like: requests like scan this domain; run DAST on these URLs; automated pentest; security-test the staging app.

How do I install Dast Automation in Claude Code?

Run `npx skills add hardw00t/ai-security-arsenal --skill dast-automation -a claude-code`. Or copy the skill folder (skills/dast-automation in hardw00t/ai-security-arsenal) into .claude/skills/dast-automation in your project. Claude Code loads it when a task matches its description.

How do I install Dast Automation in Codex?

Run `npx skills add hardw00t/ai-security-arsenal --skill dast-automation -a codex`. Or copy the skill folder (skills/dast-automation in hardw00t/ai-security-arsenal) into .agents/skills/dast-automation in your project. Codex loads it when a task matches its description.

Can I use Dast Automation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hardw00t/ai-security-arsenal --skill dast-automation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dast-automation, .gemini/skills/dast-automation, .github/skills/dast-automation and .opencode/skills/dast-automation in your project.

What does Dast Automation need to run?

Going by SKILL.md and its folder, Dast Automation needs the command-line tools its instructions call (apt, go and pip). Our summary lists: Python 3.

Does Dast Automation access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Dast Automation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Dast Automation use?

No licence was found for Dast Automation or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Dast Automation use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 38k tokens, read only when the agent opens those files.

What are the alternatives to Dast Automation?

Skills that share tags, products or a category with Dast Automation: Visible Browser for Manual Login Capture (Encod3d-Sec/TORCH, 329 stars), Invisible Playwright (feder-cr/invisible_dots, 32k stars), Playwright E2E Tests (onyx-dot-app/onyx, 32k stars) and Shogun Screenshot (yohey-w/multi-agent-shogun, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dast Automation?

hardw00t (a GitHub user) maintains it in hardw00t/ai-security-arsenal, which has 105 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on April 19, 2026.

Source: hardw00t/ai-security-arsenal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.