web-front-scannerPerform a thorough client-side / browser-facing security assessment of a target web application. Use this skill whenever the user asks to pentest, audit, or...
Install via ClawdBot CLI:
clawdbot install enderphan94/web-front-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Mar 22, 2026
An online retailer wants to ensure their checkout and user account pages are secure from client-side attacks like XSS and clickjacking before a major sale. The skill scans JavaScript bundles for exposed API keys and validates CORS settings to protect customer data.
A financial technology company needs a frontend security review to identify vulnerabilities such as JWT leakage in localStorage and insecure third-party scripts that could compromise transaction integrity. The assessment focuses on non-destructive validation of client-side logic.
A healthcare provider requires a security audit of their patient portal to detect sensitive data exposure in source maps and ensure compliance with privacy regulations. The skill checks for prototype pollution and CSRF risks in frontend request patterns.
A software-as-a-service company seeks to identify client-side vulnerabilities like DOM-based XSS and open redirects in their web application to prevent data breaches. The review includes analyzing static assets for hardcoded secrets and outdated libraries.
An online learning platform wants to test for clickjacking and mixed content issues that could affect user trust. The skill performs passive analysis of JavaScript dependencies and validates iframe sandboxing configurations.
Offer ongoing client-side security assessments as a monthly subscription, providing regular reports on vulnerabilities and updates. Revenue is generated through tiered pricing based on scan frequency and target complexity.
Provide specialized pentesting services for specific projects or compliance needs, charging a fixed fee per assessment. This model targets businesses requiring ad-hoc security reviews before product launches.
Integrate the skill into a broader security platform that automates scans and offers remediation guidance. Revenue comes from licensing fees and premium features like CVE matching and detailed analytics.
💬 Integration Tip
Ensure the target URL is correctly set and use browser DevTools for manual validation alongside automated tools to reduce false positives.
Scored Apr 19, 2026
Plan and orchestrate authorized Nmap host discovery, port and service enumeration, NSE profiling, and reporting artifacts for in-scope targets.
Performs local network scans using Nmap to detect vulnerabilities, identify service versions, and fingerprint operating systems.
AI/LLM red team testing skill. Point at any LLM API endpoint and run automated security assessments. 160+ attack payloads across prompt injection, jailbreak,...
Map application security findings to OWASP Top 10 categories and generate remediation checklists. Use for normalized AppSec review outputs and category-level...
Run slither static analysis on Solidity contracts. Fast, lightweight security scanner for EVM smart contracts.
Scan networks to discover devices, gather MAC addresses, vendors, and hostnames. Includes safety checks to prevent accidental scanning of public networks.