Project overview
site-security-assessment tests websites only after an ownership gate: a matching session email domain unlocks passive reconnaissance, while a token file placed under the target domain unlocks deeper levels. The four levels cover passive checks, limited active probes, authenticated DAST, and webhook threat modeling, with per-test approval, evidence-based findings, and false-positive checks. It refuses third-party targets, denial-of-service or load tests, brute force, active automated scanners, and production-data access, and does not bypass harness denials.
Repository facts
- Primary language
- Shell
- License
- MIT
- Repository updated
- May 11, 2026
- Default branch
- main
Resource types
General skill
Use cases
Security and privacyTesting and debugging
Platforms
Claude Code, Codex, and more
Runtime
Local
Protocols & integrations
Webhooks
Capabilities
Verification and evals
Audience
Security engineers