Web Appsec Agent skills for AI agents
7 practitioner-grade web appsec agent skills, each a focused Markdown document your agent loads into context on demand. Search them from Claude Desktop, Cursor or any MCP client, or pull one with the CLI.
All 7 skills
- access-control
Authorization testing, privilege escalation, and IDOR detection for authorized security assessments
141 lines - api-security-testing
API auth flows, rate limiting, schema validation, and GraphQL security testing for authorized assessments
163 lines - auth-testing
Authentication review, credential handling, and session management testing for authorized assessments
145 lines - business-logic
Business logic flaw detection, race conditions, and workflow bypass testing for authorized assessments
166 lines - input-validation
XSS, SQLi, command injection, and template injection testing for authorized security assessments
147 lines - Next.js Security
Use this skill when securing or reviewing a Next.js application. Activate when users mention next.js typescript security, App Router security, server actions, server components, middleware auth, NEXT_PUBLIC env leaks, SSRF in image optimization, CVE-2025 middleware bypass, route handler validation, or hardening a Vercel/self-hosted Next deployment.
114 lines - web-config-review
Security headers, CORS, CSP, cookie flags, and TLS configuration review for authorized assessments
156 lines