Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Skill Saas Dast Recon

ASecurity

Run defensive, explicitly authorized SaaS DAST and recon with scope controls. Use when asked to scan an owned local, staging, preview, or approved production URL, API endpoint, SaaS app, tenant boundary, public web surface, auth flow, exposed files, headers, TLS, or OWASP Top 10 behavior using tools such as ZAP, Nuclei, Katana, httpx, and Subfinder.

53 stars
0 votes
0 copies
0 views
Added 9/26/2026
ai-agentsgosqldockerapisecurity

Works with

api

Security Analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned 9/26/2026

$npx -y skills add IAPro-Community/Orquestrador-Maestro --skill skill-saas-dast-recon --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Skill Saas Dast Recon?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Skill Saas Dast Recon
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/iapro-community-skill-saas-dast-recon/badge)](https://www.skillsdirectory.com/skills/iapro-community-skill-saas-dast-recon)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: skill-saas-dast-recon
description: Run defensive, explicitly authorized SaaS DAST and recon with scope controls. Use when asked to scan an owned local, staging, preview, or approved production URL, API endpoint, SaaS app, tenant boundary, public web surface, auth flow, exposed files, headers, TLS, or OWASP Top 10 behavior using tools such as ZAP, Nuclei, Katana, httpx, and Subfinder.
category: security
risk: high
source: owasp-zap-projectdiscovery
---

# skill-saas-dast-recon

## Authorization gate

Only run this skill against systems the user owns or is explicitly authorized to test. If scope is unclear, ask for:

- Target base URL.
- Allowed environment: local, staging, preview, or production.
- In-scope hosts, paths, and tenants.
- Out-of-scope paths, hosts, tenants, and destructive actions.
- Whether active checks are allowed.

Default to passive/baseline scans. Production scans must use low rate limits and avoid destructive, brute-force, or fuzzing templates.

## Core workflow

1. Record the target, environment, scope, and authorization statement in the final report.
2. Validate the target is an explicit `http://` or `https://` URL provided by the user.
3. Start with passive checks:
   - HTTP headers and TLS.
   - Exposed files and known misconfigurations.
   - Baseline ZAP scan only when a pinned or explicitly approved Docker image is configured.
4. Crawl only within the provided base URL.
5. Use Nuclei with severity filters and conservative rate limits:
   - Prefer maintained `projectdiscovery/nuclei-templates`.
   - Use tags/severities instead of running every template against production.
6. Keep raw results in `security-reports/dast/`.
7. Summarize reproducible findings, false-positive risk, affected URLs, tenant impact, and remediation.

## Default command

```bat
"{{USER_HOME}}/.orquestrador\skills\skill-saas-dast-recon\scripts\saas-dast-recon.cmd" https://staging.example.com --i-own-this-target
```

## Severity and gates

- Critical: confirmed auth bypass, cross-tenant data access, exposed secrets, unauthenticated admin access, or exploit with sensitive data impact. Stop and report immediately.
- High: reproducible IDOR, SQL/command injection, dangerous CORS, missing access control on sensitive endpoints, or exposed backup/config files. Block release.
- Medium: missing security headers, weak cookies, verbose errors, rate-limit gaps, exposed metadata without secrets. Require ticketed remediation.
- Low/Info: fingerprinting, minor header gaps, informational exposure. Track without blocking.

For active DAST, stop after the first critical finding unless the user explicitly asks to continue within scope.

## SaaS-specific checks

- Tenant boundary leaks: URLs with workspace, org, user, invoice, subscription, or project IDs.
- Auth transitions: login, logout, magic links, OAuth callbacks, password reset, invitation acceptance.
- CORS and cookies: wildcard origins, missing `HttpOnly`, missing `Secure`, weak `SameSite`.
- Public files: `.env`, source maps, build manifests, logs, backup files, admin routes.
- Headers: CSP, HSTS, X-Frame-Options or `frame-ancestors`, Referrer-Policy, Permissions-Policy.
- Rate limiting: login, signup, password reset, webhooks, public API endpoints.
- API behavior: IDOR, broken object/property authorization, over-broad CORS, verbose errors, exposed source maps.

## Bundled resources

- Read `references/repository-catalog.md` when choosing or updating DAST tools.
- Run `scripts/saas-dast-recon.cmd` with an explicit authorization flag.

## Source baseline

- OWASP ZAP for passive/baseline web application checks.
- ProjectDiscovery Nuclei and `nuclei-templates` for template-based checks.
- OWASP ASVS and OWASP API Security guidance for interpreting findings.

## Hard stops

- Do not run credential stuffing, brute force, destructive fuzzing, exploit templates, or state-changing attacks without explicit written approval in the current task.
- Do not bypass authentication or access another tenant's data unless the user provided a controlled test tenant pair.
- Do not follow redirects to third-party domains unless they are explicitly in scope.

Attribution

IAPro-CommunityIAPro-Community
View sourceSee grades on GitHubMore from IAPro-Community →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →