Connect agentsFull MCP guide →

Coverage map

Security zones & OWASP WSTG — what we actually automate

Honest inventory of trust boundaries and standards mapping for anal-probe / VibeTesting Agent. We automate the black-box observable slice — not a full pentest mind map. Gaps are deliberate: active injection, full auth abuse, and business logic need sessions and (often) staging.

13/26
Zone items covered
8 partial · 5 out
3
WSTG cats strong
7 partial · 2 out of 12
12/14
ASVS L1 rows covered
Black-box subset
URL-only
Default scan mode
No source · no auth · no exploit payloads
Covered (black-box) Partial (opt-in / white-box helper) Out of scope

Security zones

From the public internet to multi-tenant isolation. Each card is a trust boundary attackers (or bad guys) try to cross.

Zone 0 — External / Internet edge

DNS · TLS · CDN · recon
DNS & email hygiene
Covered

SPF, DMARC, CAA, dangling-CNAME takeover heuristics

TLS transport
Covered

HTTPS, redirect, protocol/cipher grade, cert expiry, HSTS

Host intel (passive)
Partial

Resolve IPs, reverse DNS, CDN fingerprint

recon mode opt-in for ports/CVE

OSINT recon
Out of scope

Search engines, GitHub leaks, subdomain brute, archives

Zone 1 — Public web surface

Pages · headers · client assets
Security headers
Covered

CSP, HSTS, nosniff, clickjacking, COOP/CORP, Permissions-Policy

HTML / SEO / a11y hygiene
Covered

Title, meta, canonical, lang, alt, labels, mixed content

Client secrets & source maps
Covered

Keys in bundles/HTML, downloadable .map files

Vulnerable JS libraries
Covered

retire.js-style version ranges (OWASP A06)

DOM XSS · open redirect · SRI
Covered

High-confidence client sinks, redirect params, third-party integrity

Active XSS / SQLi fuzz
Out of scope

Payload-driven injection across every field

not safe black-box on production

Zone 2 — Exposure & misconfig

Config · debug · backups
Exposed paths
Covered

.env, .git, backups, actuator, swagger, metrics…

Framework footguns
Covered

Next / WP / Laravel / Django / Rails / Spring / ASP.NET

HTTP methods / CORS / TRACE
Covered

Dangerous verbs, reflected Origin + credentials

security.txt / robots / agent readiness
Covered

Researcher contact + llms.txt style signals

↓ authentication boundary

Zone 3 — Internal dashboard

Logged-in UI · workflows
AuthN / login flows
Out of scope

WorkOS, MFA, lockout, password policy, session fixation

needs authenticated testing

Dashboard authorization
Partial

Can user A see user B’s projects/scans?

white-box IDOR helpers

CSRF on state-changing forms
Partial

Heuristic on public HTML; full CSRF needs session

Business logic
Out of scope

Billing skips, race conditions, workflow abuse

Zone 4 — APIs, keys & webhooks

Bearer keys · MCP · Stripe · GitHub
API misconfig (public)
Covered

GraphQL introspection, public swagger, method sprawl

API authZ (BOLA / BFLA)
Partial

Cross-user object access, role bypass

testkit idor/rbac

API keys / JWT in browser
Covered

Leaked keys + JWT hygiene (alg:none, exp)

Webhook authenticity
Out of scope

Stripe/GitHub signature verification bugs

app unit tests

↓ strongest isolation

Zone 5 — Account & tenant separation

Multi-tenant core
IDOR / horizontal privilege
Partial

Tenant B reaches tenant A resources

idorProbe / separation mode

RBAC / vertical privilege
Partial

Anonymous / user / admin matrix

rbacProbe

Mass assignment
Partial

Client forges role / owner fields

massAssignmentProbe

Data isolation on list APIs
Partial

Shared IDs across two sessions

dataIsolationProbe

OWASP WSTG categories

Web Security Testing Guide v4.2 — the structure behind mind-map checklists like OWASP WSTG. We do not claim 100% of every test ID.

CategoryCoverageWhat we doHow / limits
WSTG-INFO
Information Gathering
Fingerprint stack, metafiles, JS leakage, architecture mapping
Partial
  • · WSTG-INFO-01 robots
  • · WSTG-INFO-08 disclosure
  • · source maps
  • · host fingerprint
Black-box homepage + passive host; not Google/GitHub/subdomain brute
WSTG-CONF
Configuration & Deployment
TLS, HTTP methods, debug surfaces, file exposure, security headers
Covered
  • · WSTG-CONF-04 exposed paths
  • · WSTG-CONF-06 methods
  • · WSTG-CONF-07 HSTS
  • · WSTG-CONF-12 CSP
Core of the free + full black-box suite
WSTG-IDNT
Identity Management
Registration, account enumeration, provisioning
Out of scope
  • · duplicate registration
  • · username enum
  • · weak email verify
Needs account lifecycle tests against the app
WSTG-ATHN
Authentication
Credential transport, lockout, MFA, default creds
Partial
  • · WSTG-ATHN-01 rate-limit (opt-in)
  • · TLS for credential channel
Not full login abuse; WorkOS owns hosted auth
WSTG-ATHZ
Authorization
Privilege escalation, IDOR, path traversal
Partial
  • · WSTG-ATHZ-04 IDOR via idorProbe
  • · rbacProbe
White-box helpers — not automatic from a single URL
WSTG-SESS
Session Management
Cookie flags, fixation, CSRF, logout
Partial
  • · WSTG-SESS-02 cookies
  • · WSTG-SESS-05 CSRF heuristic
  • · WSTG-SESS-10 JWT
Cookie/JWT/CSRF heuristics; not fixation or logout flows
WSTG-INPV
Input Validation
XSS, SQLi, SSRF, SSTI, LFI, command injection
Partial
  • · WSTG-CLNT-01 DOM-XSS heuristic
  • · WSTG-INPV-17 host-header
No active payload fuzzing (by design on production targets)
WSTG-ERRH
Error Handling
Stack traces, verbose errors, information leakage
Covered
  • · WSTG-ERRH-01 stack traces
When error pages leak internals
WSTG-CRYP
Cryptography
Weak TLS, bad crypto, secrets in transit/storage
Partial
  • · WSTG-CRYP-01 TLS
  • · WSTG-CRYP-03 channel
  • · WSTG-CRYP-04 client secrets
Transport + client-exposed secrets; not server-side crypto review
WSTG-BUSL
Business Logic
Workflow abuse, races, price tampering, upload abuse
Out of scope
  • · checkout skip
  • · race on quotas
  • · file upload
Manual / product-specific E2E
WSTG-CLNT
Client-side
DOM XSS, clickjacking, CORS, storage, SRI
Covered
  • · WSTG-CLNT-01
  • · WSTG-CLNT-04 open redirect
  • · WSTG-CLNT-07 CORS
  • · WSTG-CLNT-09 clickjacking
  • · WSTG-CLNT-11 SRI
Strong black-box coverage of client surface
WSTG-APIT
API Testing
REST/GraphQL authz, mass assignment, inventory
Partial
  • · GraphQL introspection
  • · swagger exposure
  • · API1 via idorProbe
  • · mass assignment helper
Public misconfig automatic; BOLA needs two sessions

OWASP ASVS 4.0.3 — Level 1 (black-box subset)

Requirements verifiable without source access or active exploitation. Full detail lives in the OSS package (docs/compliance.md). Run anal-probe URL --compliance for a live grade.

V3.4.1–4
Session cookie Secure / HttpOnly / SameSite / __Host-
V3.4.5
Cookie Path scoped tightly
V7.4.1
Generic errors, no stack traces
V8.2.1
Anti-caching on sensitive responses
V9.1.1–3
TLS everywhere, strong ciphers & protocols
V12.5.1
Backup/temp files not web-served
V13.1.3
URLs/client code do not expose secrets
V14.2.2–3
No sample/debug surfaces; SRI on external assets
V14.3.2–3
Debug off; no version banners
V14.4.1
Content-Type + charset
V14.4.2
Content-Disposition on API responses
V14.4.3–7
CSP, nosniff, HSTS, Referrer-Policy, clickjacking
V14.5.1
HTTP methods restrained
V14.5.3
CORS not wide-open with credentials

Try it on a URL

Free lite scan on the homepage, or the full CLI with compliance output.

npx github:newsengine/anal-probe https://your-app.example.com --compliance

Not a substitute for a professional pentest. A clean scan does not mean the application is secure. Active WSTG items (injection, full auth abuse, business logic) belong on staging with authorization — ZAP, Burp, or a human tester — plus our white-box helpers for multi-tenant suites.