Web App Penetration Testing, OWASP Methodology & Report
A structured, OWASP-aligned methodology for authorized web app penetration tests, from recon to a client-ready findings report.
$9
Works with the AI tools you already use
Web App Penetration Testing, OWASP Methodology & Report
Example session with this skill installed
I have written permission to test dev.example.com. I found a reflected XSS on the search parameter. Help me document this finding for the final report.
- Read your context and instructions
- Compiled the web app penetration
I have recorded that dev.example.com is in scope and you have written authorization. I will now format the reflected Cross-Site Scripting (XSS) finding using the standard reporting structure.
Vulnerability Finding: Reflected Cross-Site Scripting (XSS)
| Field | Detail |
|---|---|
| Title | Reflected Cross-Site Scripting (XSS) in Search Component |
| Severity | Medium (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) |
| Affected Asset | https://dev.example.com/search |
| Vulnerable Parameter | q (GET) |
Description
The search functionality fails to properly sanitize or encode user-supplied input before rendering it in the HTML response. This allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session.
Reproduction Steps
- Navigate to the following URL:
https://dev.example.com/search?q=<script>alert(document.domain)</script> - Observe the JavaScript alert box displaying the domain name.
- Review the page source to confirm the payload is rendered unencoded within the
<div>tags.
Impact
An attacker could perform session hijacking, redirect users to malicious websites, or capture sensitive user information by injecting malicious scripts into the application.
Remediation
Implement context-aware output encoding. For HTML contexts, convert characters such as <, >, &, ", and ' into their corresponding HTML entities (e.g., <, >). Use established libraries like OWASP ESAPI or built-in framework encoding functions.
Next steps
- Test other parameters on the
/searchendpoint for similar injection flaws. - Verify if a Content Security Policy (CSP) is active and if it can be bypassed.
- Check for persistent XSS by searching for the same payload and viewing the results page from a different session.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
web-pentest turns an ad-hoc security assessment into a disciplined, OWASP-aligned engagement. It is built for penetration testers, security consultants, and red teamers who already have written authorization to assess a web target and want their work to stay organized, evidence-backed, and repeatable, the discipline layer that most improvised testing lacks.
It covers the full arc, from confirming scope and rules of engagement through to a client-ready findings report, keeping evidence captured and findings organized along the way. Each finding comes out structured for a client: title, OWASP category, severity with a CVSS vector, affected asset, reproduction steps, business impact, and remediation, so what you hand over reads like a real assessment instead of a pile of raw scanner output.
Honest about what it is: a methodology and reporting aid, not a scanner or an exploit toolkit. It guides the engagement while you run your own tools and make the calls. It enforces a scope and authorization gate and will not help against targets you have no permission to test, and it defaults to non-destructive testing unless your rules of engagement explicitly allow more. Coverage depends on the testing you actually perform.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 9 days ago
- Passed all security checks, Safe to install