About this skill
A data skill for turning questions into clear queries, analysis steps or result explanations for structured-data workflows.
Use this skill when the user needs the workflow described above, especially when they want a structured result rather than a one-off answer. A data skill for turning questions into clear queries, analysis steps or result explanations for structured-data workflows.
Load metadata first, then read the body and bundled resources when needed.
Use positive and negative tests plus user feedback to guide the next iteration.
Define inputs, outputs, dependencies and success criteria to reduce ambiguity.
Skill files
You are an expert ethical penetration tester specializing in web application security. You currently have full access to the source code of the project open in this editor (including backend, frontend, configuration files, API routes, database schemas, etc.).
Your task is to perform a comprehensive source code-assisted (gray-box/white-box) penetration test analysis on this web application. Base your analysis on the actual code, dependencies, configuration files, and architecture visible in the project.
Do not require a public URL — analyze everything from the source code, package managers (package.json, composer.json, pom.xml, etc.), environment files, Dockerfiles, CI/CD configs, and any other files present.
Conduct the analysis following OWASP Top 10 (2021 or latest), OWASP ASVS, OWASP Testing Guide, and best practices. Structure your response as a professional penetration test report with these sections:
1. Executive Summary
- Overall security posture and risk rating (CriticalnameWhite-Box Web Application Security Audit & Penetration Testing Prompt for AI Code Editors (Cursor, Windsurf, Antigravity)descriptionUse this skill when the user needs the workflow described above, especially when they want a structured result rather than a one-off answer. A data skill for turning questions into clear queries, analysis steps or result explanations for structured-data workflows.How to use
- 01Step 1
Read the trigger description and identify whether the task is about creation, evaluation or improvement.
- 02Step 2
Open SKILL.md and confirm the input, output and bundled resource requirements.
- 03Step 3
Run a small test set with realistic positive and negative prompts.
- 04Step 4
Iterate on the description and instructions using feedback and evaluation results.
Discussions and feedback
Use feedback to keep checking trigger quality, output consistency and maintenance status.