Prove real web vulnerabilities before attackers do.
application security
Finds exploitable vulnerabilities in a running web application and validates each finding with a working proof of concept.
When to use it
Use when the user asks to penetration-test, hack, security-test, or audit a web application or staging site.
Give it an authorized web-app target and scope; it asks for missing details, tests it, and reports confirmed findings.
What you provide
This skill
target web application
Sends real exploit payloads
The strix binary must be available; another skill covers installation when its version check fails.
Requires a running web application, such as a live URL, staging environment, or local development server.
A test account optionally enables testing beyond the application's public marketing surface.
Hands validated findings to this skill for root-cause patching before retesting.