CtrlK
BlogDocsLog inGet started
Tessl Logo

configure-dast-scan

Add Dynamic Application Security Testing (DAST) steps to existing Harness pipelines using Harness STO scanners. Supports API DAST / Traceable (default), Burp Suite Enterprise, ZAP (OWASP), Nikto, and Nmap. Scans running application instances for vulnerabilities including API security issues, injection flaws, misconfigurations, and exposed services. Can insert the scan step into an existing CI or SecurityTests stage or create a dedicated SecurityTests stage. Use when asked to add DAST scanning, configure dynamic application testing, set up API security scanning, scan a running application, or add runtime security testing to a pipeline. Trigger phrases: add DAST scan, dynamic application security testing, API DAST, configure Traceable, scan running app, add Burp Suite scan, add ZAP scan, add Nikto scan, runtime security scan, API security scan.

68

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

65%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with concrete MCP calls and copy-paste YAML for every scanner and mode, and its ten-step sequence is clear. Its weaknesses are token efficiency (triplicated YAML and inlined option catalogs) and a missing validate-before-update checkpoint for a mutating pipeline operation.

Suggestions

Add an explicit validation/confirmation step before harness_update (e.g., show the user the diff of the new step, validate YAML indentation and the identifier pattern, and confirm before overwriting the existing pipeline) to lift workflow_clarity above the destructive/batch cap of 3.

Deduplicate the YAML: define the Traceable orchestration step once and reference it from Step 8 scenarios, and collapse the near-identical ZAP/Nikto/Nmap templates into one parameterized template noting only the `type` field changes.

Move the Burp and Nmap configuration-option catalogs (and optionally the full per-scanner YAML) into reference files under references/ and link to them one level deep, reducing the inline bulk and improving progressive_disclosure.

DimensionReasoningScore

Conciseness

Mostly efficient and reference-grade, but it could be tightened: the Traceable orchestration YAML is repeated three times (Step 6, Step 8 Scenario B, Step 8 Scenario C) and the ZAP/Nikto/Nmap templates are near-identical, while a 23-option Burp config catalog is inlined rather than linked.

3 / 5

Actionability

Fully executable guidance throughout: concrete MCP tool calls with parameters, copy-paste-ready YAML templates per scanner and scan mode, an exact secret-reference format, a curl example for ingestion, and per-scanner invocation examples in the Examples section.

5 / 5

Workflow Clarity

The ten steps are clearly sequenced, but the workflow mutates an existing pipeline via harness_update with no proactive validation or user-confirmation checkpoint before overwriting; the rubric's destructive/batch cap (missing validation feedback loop) bounds this to 3.

3 / 5

Progressive Disclosure

Section headers and step structure are good, but the 670-line body is a monolith with zero external references, inlining bulk catalogs (Burp/Nmap config options) and repeated templates that clearly belong in separate reference files; the under-50-line exception does not apply.

3 / 5

Total

14

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is strong: it states concrete capabilities, names every supported scanner, and pairs a clear 'what' with an explicit 'Use when' clause and a trigger-phrase list, all in third person with no fluff. It closely matches the rubric's good-overall examples.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ("insert the scan step into an existing CI or SecurityTests stage or create a dedicated SecurityTests stage") plus a comprehensive enumeration of supported scanners (Traceable, Burp Suite Enterprise, ZAP, Nikto, Nmap), matching the comprehensive-coverage anchor.

5 / 5

Completeness

Explicitly answers both what ("Add Dynamic Application Security Testing (DAST) steps to existing Harness pipelines using Harness STO scanners") and when ("Use when asked to add DAST scanning... or add runtime security testing to a pipeline") with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Beyond an explicit "Use when asked to add DAST scanning..." clause, it provides a dedicated "Trigger phrases" list with natural terms and synonyms ("add DAST scan", "API DAST", "configure Traceable", "add ZAP scan", "runtime security scan"), giving comprehensive coverage.

5 / 5

Distinctiveness Conflict Risk

It carves a clear niche (DAST scanning in Harness pipelines via STO scanners) with distinct, specific triggers, so it is unlikely to fire for unrelated skills.

5 / 5

Total

20

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (689 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
harness/harness-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.