Cyber Neo
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…
$ npx skills add petrkindlmann/qa-skills --skill security-testing -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install petrkindlmann/qa-skills security-testing --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-testing .claude/skills/security-testing && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/security-testing into .claude/skills/security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-testing", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/petrkindlmann/qa-skills/tree/main/skills/security-testingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add petrkindlmann/qa-skills --skill security-testing -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install petrkindlmann/qa-skills security-testing --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-testing .agents/skills/security-testing && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/security-testing into .agents/skills/security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-testing", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add petrkindlmann/qa-skills --skill security-testing -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install petrkindlmann/qa-skills security-testing --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-testing .cursor/skills/security-testing && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/security-testing into .cursor/skills/security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-testing", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/petrkindlmann/qa-skills.git --path skills/security-testing--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add petrkindlmann/qa-skills --skill security-testing -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install petrkindlmann/qa-skills security-testing --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-testing .gemini/skills/security-testing && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/security-testing into .gemini/skills/security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-testing", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install petrkindlmann/qa-skills security-testingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add petrkindlmann/qa-skills --skill security-testing -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-testing .github/skills/security-testing && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/security-testing into .github/skills/security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-testing", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add petrkindlmann/qa-skills --skill security-testing -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install petrkindlmann/qa-skills security-testing --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/petrkindlmann/qa-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-testing .opencode/skills/security-testing && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-testing" agent skill from https://github.com/petrkindlmann/qa-skills/tree/main/skills/security-testing into .opencode/skills/security-testing/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-testing", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-testingTest application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…
Security Testing is an agent skill from petrkindlmann/qa-skills. Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests (JWT, OAuth, RBAC), and XSS/CSRF/SQLi/SSRF Playwright patterns. Use when: "security test," "OWASP," "vulnerability," "ZAP," "XSS," "SSRF," "dependency scan," "auth testing," "OWASP LLM Top 10." Scope is automated scanning + negative-path security tests in CI, not manual penetration testing. Not for: mapping security…
Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/auth-tests.md`, `references/owasp-tests.md` and `references/scanning-and-ci.md`).
It sits in Security, covering Web application vulnerabilities, Supply chain security and Static analysis and SAST. It works with Playwright and Semgrep. The repository describes itself as: 50 QA and test-automation skills for Claude Code, Codex, Cursor, and any Agent Skills Standard runtime. The licence is MIT.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit b3bb61b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmnpxdockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, npx and docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Testing loads about 4.9k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 258 tokens; SKILL.md has 2,410 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from petrkindlmann/qa-skills at commit b3bb61b, republished under its MIT licence (© petrkindlmann). 2,410 words, ~4,866 tokens.
.claude/skills/security-testing/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.<objective>
A login test that only checks the happy path passes while an expired JWT still grants admin, an
IDOR lets user A read user B's orders, and a webhook field reaches `169.254.169.254`. This skill
forces the negative-path checks — broken access control, injection, SSRF, auth bypass, supply-chain
drift — into CI on every PR, layered across DAST, SCA, SAST, and custom Playwright tests so no single
tool's blind spot ships. It produces runnable tests mapped to the OWASP Top 10 (2025) plus the CI
gates that fail the build when a category regresses.
</objective>
Check .agents/qa-project-context.md first — if it exists, use it and skip anything already answered there (auth mechanism, compliance requirements, infrastructure). Then:
compliance-testing; this skill only proves the controls behave.Security is continuous, not a phase. Scans run in CI on every PR, not as a quarterly penetration test. A vulnerability caught on the PR that introduced it costs minutes; the same vulnerability found in prod costs an incident.
OWASP Top 10 is the floor, not the ceiling. It covers the most common impactful classes. Domain-specific threats (healthcare data, financial transactions, multi-tenant isolation) need their own analysis on top.
Defense in depth — no single tool catches everything. ZAP misses auth-logic bugs, SCA misses your custom code, Semgrep misses runtime issues. Layer DAST + SCA + SAST + auth tests + secret scanning. When one layer's blind spot is another layer's coverage, a regression has to beat all of them. SCA earns its layer because most of the shipped code is third-party — known CVEs in dependencies are the lowest-effort attack vector, so scan on every build.
Shift-left. Catch each class at the earliest stage: SAST and secret scanning on commit, dependency/supply-chain checks on the PR, DAST in staging, custom auth tests on every run. See shift-left-testing for the dev-QA workflow this rides on.
Test the attacker, not the user. Happy-path auth proves login works. Security tests prove logout invalidates the session, an expired token is rejected, role escalation fails, and a malformed payload fails closed. The negative path IS the test.
The 2025 list (final, owasp.org/Top10/2025/) re-orders categories and introduces two new ones. Changes from 2021:
For runnable test code per category, see references/owasp-tests.md.
The #1 vulnerability. Users act outside intended permissions. SSRF is now an access-control failure when the server is induced to reach internal resources for an attacker.
What to test: IDOR (change resource IDs to reach other users' data), missing function-level access control (admin endpoints as a regular user), path traversal (../../etc/passwd), CORS misconfiguration, SSRF (user URLs reaching internal networks, cloud-metadata endpoints, file://).
Default credentials, unnecessary features, verbose errors. Promoted from A05 — still the easiest way in.
What to test: stack traces disabled in prod, default credentials changed, unnecessary HTTP methods (e.g. TRACE) disabled, directory listing off, admin panels not public, cloud buckets not public.
New in 2025. Beyond "outdated dependencies" — provenance, build-pipeline integrity, the supply chain end-to-end.
What to test: lockfile committed and CI installs from it (npm ci, never npm install); SBOM generated and stored as a build artifact (Syft / anchore/sbom-action); provenance attestation for built artifacts (SLSA v1.0 L2/3, signed via cosign / actions/attest-build-provenance); dependency review on every PR; CI secrets not exposed to forks; self-hosted runners isolated from untrusted PR code.
See references/owasp-tests.md for the dependency-review / SBOM / provenance workflow and the lockfile-drift check.
Sensitive data exposed via weak or missing encryption.
What to test: TLS version / cipher suites / HSTS; passwords hashed with bcrypt/argon2 (not MD5/SHA1); no sensitive data in URLs, logs, or errors; cookies carry Secure, HttpOnly, SameSite; security headers present (HSTS, X-Content-Type-Options: nosniff, X-Frame-Options).
Untrusted data sent to an interpreter.
What to test: SQL injection in params/fields/headers; XSS (reflected, stored, DOM) in user content; CSRF on state-changing operations; command injection in filenames, search queries, webhook URLs.
Flawed architecture implementation alone can't fix. Includes design-level SSRF (URL-accepting features without an allow-list), credential stuffing without rate limits, business-logic abuse.
What to test: rate limiting on auth endpoints (fire 15 concurrent login attempts, expect a 429 in the responses); business-logic abuse (negative quantities, coupon stacking); account lockout after failed attempts; allow-list architecture for any feature that fetches a user-supplied URL.
Broken authentication, weak passwords, credential stuffing. Session rotation after login, expired/alg:none JWT rejection, RBAC matrix, OAuth state tampering. See references/auth-tests.md.
Unsigned updates, insecure deserialization, untrusted CI/CD.
What to test: Subresource Integrity (SRI) on CDN scripts; Content-Security-Policy header present and free of 'unsafe-inline' / 'unsafe-eval'.
Insufficient logging and missing alerts on what is logged. Renamed in 2025 to stress that logs without alerts are after-the-fact evidence, not detection.
What to test: failed logins logged AND alerting above threshold; admin actions audit-logged AND alerting on out-of-hours events; logs free of secrets/PII; the alert pipeline itself monitored.
New in 2025. Errors and unexpected states are an attack surface — fail-open defaults, uncaught exceptions leaking internals, race conditions in error paths, security checks skipped when "something went wrong."
What to test: error responses leak no stack traces / framework names / DB schema; auth fails closed (deny by default); timeouts and partial failures never bypass authorization; resource cleanup on every error path; fuzz every endpoint and verify responses stay within the documented error contract.
If your app embeds an LLM (chatbot, RAG, agent, copilot), the classic Top 10 above does not cover its failure modes — use the OWASP Gen AI Security Project's separate list (genai.owasp.org/llm-top-10/). This is the security/CI-gate view: one-line "what to test" per category. For the DEEP behavioral coverage of LLM01 and LLM02 — indirect injection via tool/RAG data, defend-the-tester technique, jailbreak red-teaming, and the runnable injection detector — hand off to ai-system-testing; do not duplicate it here.
| ID | Category | What to test |
|---|---|---|
| LLM01 | Prompt Injection | Direct + indirect injection (instructions hidden in retrieved docs, tool output, file content) override system intent. → DEEP coverage in ai-system-testing. |
| LLM02 | Sensitive Information Disclosure | Model leaks PII, secrets, other tenants' data, or training data via crafted prompts. → DEEP coverage (detector, scoped tests) in ai-system-testing. |
| LLM03 | Supply Chain | Provenance of models, adapters, datasets, and plugins; pinned/verified weights; poisoned third-party model or LoRA. |
| LLM04 | Data and Model Poisoning | Training/fine-tune/RAG-ingest data integrity; backdoors and bias injected via tainted sources. |
| LLM05 | Improper Output Handling | LLM output reaching a downstream interpreter unsanitized — XSS, SSRF, SQLi, command injection from generated text. |
| LLM06 | Excessive Agency | Agent has more tools/permissions/autonomy than the task needs; can delete, pay, or email without a human gate. |
| LLM07 | System Prompt Leakage | System prompt extractable, and — worse — relied on to hold secrets or enforce authz that belongs server-side. |
| LLM08 | Vector and Embedding Weaknesses | RAG retrieval crosses tenant/permission boundaries; embedding inversion; poisoned vectors returned as context. |
| LLM09 | Misinformation | Confident fabrication (hallucinated facts, fake citations/URLs, unsafe code) accepted as authoritative. |
| LLM10 | Unbounded Consumption | No token/rate/cost ceilings — prompt-driven resource exhaustion, denial-of-wallet, model extraction by query volume. |
LLM05 (Improper Output Handling) is where the classic Top 10 reconnects: treat LLM output as untrusted input and re-run the A05 Injection checks on anything it produces.
A complete pipeline layers DAST, dependency/supply-chain scanning, SAST, and secret scanning. Config and CI workflows are in references/scanning-and-ci.md.
zap-api-scan.py for APIs. ZAP 2.17.0 is current (weekly w2026-MM-DD Docker tags). The ZAP MCP Server (April 2026) lets coding agents drive spider/active-scan/alert-analysis for "scan the diff" workflows.cosign / attest-build-provenance) for A03. npm audit --audit-level=high is a noisy semver-only quick check, not the gate (it won't flag non-strict-semver versions and doesn't reliably exit non-zero).p/owasp-top-ten is the SAST gate. eslint-plugin-security is a weak secondary signal — see the note below; keep it as a lint-time nudge, not coverage.--only-verified in CI; git-secrets pre-commit.Avoid relying on eslint-plugin-security as your SAST gate — as of mid-2026 it ships ~13 rules, has had no meaningful rule growth since 2020, and benchmarks put its miss rate near 90% of detectable vulnerabilities. Its 4.0.0 release is flat-config-compatible so the config runs, but layer it under Semgrep, never instead of it.
ESLint 10 (Feb 2026) removed .eslintrc entirely — only flat config (eslint.config.js) works. Any .eslintrc.* security config is dead on ESLint 10; use it only for repos pinned to ESLint 8. See references/scanning-and-ci.md for both blocks.
Session management, JWT (expiry, alg: none confusion, wrong-key signing), and RBAC matrix tests. Full code in references/auth-tests.md. Also test session rotation after login (session fixation) and OAuth state-parameter tampering.
A complete security pipeline has five layers, each a CI step:
--only-verifiedp/owasp-top-ten as the gate; ESLint security plugins as a weak secondarynpx playwright test --project=securitySecurity as PR gate: OSV-Scanner exits non-zero on any vulnerability and gates the merge directly. If you gate on npm audit instead, parse npm audit --json and exit 1 when high/critical count > 0 — npm audit does not reliably exit non-zero on its own. See references/scanning-and-ci.md for the runnable gate.
Security testing only before release. Late findings are expensive. Scan every PR, not quarterly.
Relying on a single tool. ZAP misses auth-logic bugs; SCA misses custom code; ESLint misses runtime issues. Layer multiple tools.
Treating a near-dead linter as SAST coverage. eslint-plugin-security alone catches almost nothing (~13 rules, 2020-era detection). Gate on Semgrep p/owasp-top-ten; keep the linter as a nudge.
Ignoring dependency warnings. "Fix it later" becomes a backlog of known CVEs. Fail the build on high/critical via OSV-Scanner.
Testing only happy-path auth. Login works — fine. Does logout invalidate the session? Can an expired token still access resources? Does role escalation work?
Hardcoding secrets in test files. Tests holding real keys are themselves a vulnerability. Use env vars and CI secrets.
Skipping SSRF testing. Any URL-accepting feature (webhooks, image uploads, imports) is an SSRF vector. Test internal addresses and cloud-metadata endpoints.
Asserting a single status where several are valid. SSRF/CSRF/exceptional-condition tests have a set of acceptable codes. Use expect([400, 403, 422]).toContain(response.status()) — toBeOneOf is not a built-in matcher and throws at runtime.
Testing only known payloads. The XSS/SQLi payloads in the references are examples, not exhaustive. Use ZAP's maintained payload database for breadth.
Prove the assertions actually fire — a security suite that passes vacuously (wrong URL, matcher never reached) is worse than none.
docker run --rm -p 3000:3000 bkimminich/juice-shop
BASE_URL=http://localhost:3000 npx playwright test --project=securitygrep -r "toBeOneOf" tests/ must return nothing — every acceptable-set assertion uses expect([...]).toContain(...).owasp-coverage.md (or a CI job asserting it) maps every OWASP 2025 category to at least one tagged test, or to a recorded "mitigated / accepted risk" entry with justification — no category is silently absent.p/owasp-top-ten runs in CI and reports zero unresolved findings on the main branch (ESLint security plugins may run as a secondary, non-gating signal).if: always()).--project=security) exits 0 against staging AND produces failures when pointed at OWASP Juice Shop (proves assertions fire).alg:none rejection, session invalidation on logout, RBAC role-escalation prevention.grep / TruffleHog clean).references/)alg:none, expiry), and RBAC matrix tests for A07.© petrkindlmann, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/security-testing of petrkindlmann/qa-skills.
Open the folder on GitHubat commit b3bb61b
Security Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Testing this skillpetrkindlmann/qa-skills | 163 | — | ~4.9k | Automated safety check: Pass | MIT | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Semgrep Rule Creatorskrun-dev/skrun | 210 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Implementing Devsecops Security Scanningmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Sast Patternsvibeeval/vibecosystem | 531 | — | ~4.6k | Automated safety check: Pass | MIT | |
| Security Scanning Security Sastaiskillstore/marketplace | 430 | 6 repos | ~3.7k | Automated safety check: Pass | None |
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
skrun-dev/skrun
Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.
mukul975/Anthropic-Cybersecurity-Skills
Integrates SAST, DAST, and SCA into CI/CD pipelines using Semgrep for SAST, Trivy for SCA and container scanning, OWASP ZAP for DAST, and Gitleaks for secrets detection.
vibeeval/vibecosystem
Static Application Security Testing patterns, OWASP Top 10 checklist, language-specific vulnerability patterns, Semgrep rule writing guide, and CI/CD integration.
aiskillstore/marketplace
Static Application Security Testing (SAST) for code vulnerability analysis across multiple languages and frameworks
modu-ai/moai-adk
DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…
petrkindlmann/qa-skills
Test for WCAG 2.2 AA compliance with axe-core + Playwright, keyboard navigation audits, screen reader testing, ARIA pattern validation, and legal compliance mapping (ADA, EAA, Section 508).
petrkindlmann/qa-skills
Goal-driven E2E testing where a browser agent (Playwright MCP / computer-use) reads a natural-language goal and explores the app via the accessibility tree to assert outcomes — no pre-written script.
petrkindlmann/qa-skills
Use AI to write NEW test code from specs, PRDs, user stories, code diffs, bug reports, or OpenAPI specs.
petrkindlmann/qa-skills
Test REST and GraphQL APIs with Playwright APIRequestContext, Supertest, or standalone HTTP clients.
petrkindlmann/qa-skills
Design CI/CD pipelines that run test suites. An agent skill from petrkindlmann/qa-skills.
petrkindlmann/qa-skills
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…
Works with
Categories
Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests…. Security Testing is an agent skill from petrkindlmann/qa-skills. Test application security against OWASP Top 10 (2025) with automated CI tooling: OWASP ZAP (DAST), dependency/supply-chain scanning (OSV-Scanner, SBOM, provenance), Semgrep SAST, auth/session tests (JWT, OAuth, RBAC), and XSS/CSRF/SQLi/SSRF Playwright patterns.
Security Testing fits situations like: : security test; dependency scan; OWASP LLM Top 10. Scope is automated scanning + negative-path security tests in CI; not manual penetration testing.
Run `npx skills add petrkindlmann/qa-skills --skill security-testing -a claude-code`. Or copy the skill folder (skills/security-testing in petrkindlmann/qa-skills) into .claude/skills/security-testing in your project. Claude Code loads it when a task matches its description.
Run `npx skills add petrkindlmann/qa-skills --skill security-testing -a codex`. Or copy the skill folder (skills/security-testing in petrkindlmann/qa-skills) into .agents/skills/security-testing in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add petrkindlmann/qa-skills --skill security-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-testing, .gemini/skills/security-testing, .github/skills/security-testing and .opencode/skills/security-testing in your project.
Going by SKILL.md and its folder, Security Testing needs the command-line tools its instructions call (npm, npx and docker). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm, npx and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Security Testing is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.9k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Testing: Cyber Neo (Hainrixz/cyber-neo, 281 stars), Semgrep Rule Creator (skrun-dev/skrun, 210 stars), Implementing Devsecops Security Scanning (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Sast Patterns (vibeeval/vibecosystem, 531 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
petrkindlmann (a GitHub user) maintains it in petrkindlmann/qa-skills, which has 163 GitHub stars. The repository holds 45 skills in this directory. The repository was last updated on June 10, 2026.
Source: petrkindlmann/qa-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.