← ClaudeAtlas

pentest-windftsylisted

A Web security assessment workflow built on globally installed Chrome DevTools MCP and Burp MCP. It establishes real browser state, synchronizes Burp evidence, models endpoints and permissions, validates vulnerabilities endpoint by endpoint, and completes threat convergence. It outputs structured data only.
do-whilefor/JaseSkills · ★ 7 · AI & Automation · score 80
Install: claude install-skill do-whilefor/JaseSkills
# Web Application Security Assessment ```text Chrome establishes identity/object/state → Burp captures/replays/mutates → Endpoint and permission modeling → Complete vulnerability coverage → Impact validation and rating → Threat convergence ``` ## Highest-Priority Principles The following principles take precedence over every other description in this Skill. Apply this section whenever a conflict exists. - Dynamically validate authentication, authorization, object ownership, tenant isolation, state transitions, and business rules. Do not substitute static indicators or tool output for validation. - Explore broadly and draw conclusions strictly. Treat hypotheses, errors, scanner hits, fingerprints, and theoretical exploit chains only as leads. - Mark the first technical hit as `candidate/unrated`, then validate capability, object, data, privilege, asset, business outcome, scope, and prerequisites. - A single failure, error, or path with no result is insufficient to close a lead. Continued validation must introduce a new identity, object, entry point, state, parsing path, or evidence source. Close a lead only after critical variables have been reasonably covered and no new evidence remains, and record reopening conditions. - Do not assign P1-P3 before impact validation. Do not rate based on the vulnerability name, CVSS, tool rating, historical cases, or theoretical maximum impact. - Do not confirm a vulnerability without real requests/responses, state changes, logs, files, d