Web App Penetration Testing, OWASP Methodology & Report

    1

    A structured, OWASP-aligned methodology for authorized web app penetration tests, from recon to a client-ready findings report.

    $9

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Web App Penetration Testing, OWASP Methodology & Report

    Example session with this skill installed

    I have written permission to test dev.example.com. I found a reflected XSS on the search parameter. Help me document this finding for the final report.

    • Read your context and instructions
    • Compiled the web app penetration

    I have recorded that dev.example.com is in scope and you have written authorization. I will now format the reflected Cross-Site Scripting (XSS) finding using the standard reporting structure.

    Vulnerability Finding: Reflected Cross-Site Scripting (XSS)

    FieldDetail
    TitleReflected Cross-Site Scripting (XSS) in Search Component
    SeverityMedium (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
    Affected Assethttps://dev.example.com/search
    Vulnerable Parameterq (GET)

    Description

    The search functionality fails to properly sanitize or encode user-supplied input before rendering it in the HTML response. This allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session.

    Reproduction Steps

    1. Navigate to the following URL: https://dev.example.com/search?q=<script>alert(document.domain)</script>
    2. Observe the JavaScript alert box displaying the domain name.
    3. Review the page source to confirm the payload is rendered unencoded within the <div> tags.

    Impact

    An attacker could perform session hijacking, redirect users to malicious websites, or capture sensitive user information by injecting malicious scripts into the application.

    Remediation

    Implement context-aware output encoding. For HTML contexts, convert characters such as <, >, &, ", and ' into their corresponding HTML entities (e.g., &lt;, &gt;). Use established libraries like OWASP ESAPI or built-in framework encoding functions.

    Next steps

    • Test other parameters on the /search endpoint for similar injection flaws.
    • Verify if a Content Security Policy (CSP) is active and if it can be bypassed.
    • Check for persistent XSS by searching for the same payload and viewing the results page from a different session.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Structure a professional web app pentest following OWASP standards.Document vulnerabilities with CVSS scores and remediation steps.Draft authorization and scope agreements for security engagements.Ensure full coverage of the OWASP Top 10 during manual testing.

    About this skill

    web-pentest turns an ad-hoc security assessment into a disciplined, OWASP-aligned engagement. It is built for penetration testers, security consultants, and red teamers who already have written authorization to assess a web target and want their work to stay organized, evidence-backed, and repeatable, the discipline layer that most improvised testing lacks.

    It covers the full arc, from confirming scope and rules of engagement through to a client-ready findings report, keeping evidence captured and findings organized along the way. Each finding comes out structured for a client: title, OWASP category, severity with a CVSS vector, affected asset, reproduction steps, business impact, and remediation, so what you hand over reads like a real assessment instead of a pile of raw scanner output.

    Honest about what it is: a methodology and reporting aid, not a scanner or an exploit toolkit. It guides the engagement while you run your own tools and make the calls. It enforces a scope and authorization gate and will not help against targets you have no permission to test, and it defaults to non-destructive testing unless your rules of engagement explicitly allow more. Coverage depends on the testing you actually perform.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 9 days ago

    • Passed all security checks, Safe to install

    Listed9 days ago

    What's inside

    Frequently Asked Questions