OWASP PenTestKit Automation от pentestkit.co.uk
PTK Auto is the browser security runtime used by PTK Agent in automated tests, CLI workflows, CI/CD pipelines and supported browser-testing platforms.
5 пользователей5 пользователей
Метаданные расширения
Скриншоты
Об этом расширении
PTK Auto is the browser automation companion for OWASP Penetration Testing Kit.
It provides the browser-side security runtime used by PTK Agent, automated tests, CI/CD pipelines and supported browser-testing platforms.
PTK Auto is controlled programmatically. It allows security checks to run inside the same browser session and user workflow created by Playwright, Puppeteer, Selenium, Cypress or another supported automation client.
Use PTK Auto to:
Add OWASP PTK security checks to existing browser automation.
Test authenticated workflows using the browser state created by the automated scenario.
Capture browser-generated requests and responses during a test.
Run configured DAST checks against selected requests and parameters.
Analyse loaded client-side code with PTK SAST.
Observe security-relevant runtime behaviour with PTK IAST.
Identify vulnerable client-side dependencies with PTK SCA.
Return structured findings and evidence to the controlling automation client.
Run security tests locally, in CI/CD or through supported hosted-browser platforms.
PTK Auto works with PTK Agent, published as pentestkit.
PTK Agent controls the browser and scan lifecycle, applies the selected security policy, collects results and produces reports. PTK Auto performs the browser-side inspection and testing inside the automated session.
PTK Auto is not the interactive version of OWASP PTK and does not provide the complete manual testing interface. Install the full OWASP PTK extension if you want to inspect traffic, launch scans, modify requests or test JWTs manually.
During an authorised scan, PTK Auto may inspect application traffic, page resources and browser behaviour required by the selected checks. Use a dedicated browser profile and test environment whenever possible.
Use PTK Auto only against applications where you have explicit authorisation. Active security testing can generate additional traffic, modify application data and trigger security monitoring.
It provides the browser-side security runtime used by PTK Agent, automated tests, CI/CD pipelines and supported browser-testing platforms.
PTK Auto is controlled programmatically. It allows security checks to run inside the same browser session and user workflow created by Playwright, Puppeteer, Selenium, Cypress or another supported automation client.
Use PTK Auto to:
Add OWASP PTK security checks to existing browser automation.
Test authenticated workflows using the browser state created by the automated scenario.
Capture browser-generated requests and responses during a test.
Run configured DAST checks against selected requests and parameters.
Analyse loaded client-side code with PTK SAST.
Observe security-relevant runtime behaviour with PTK IAST.
Identify vulnerable client-side dependencies with PTK SCA.
Return structured findings and evidence to the controlling automation client.
Run security tests locally, in CI/CD or through supported hosted-browser platforms.
PTK Auto works with PTK Agent, published as pentestkit.
PTK Agent controls the browser and scan lifecycle, applies the selected security policy, collects results and produces reports. PTK Auto performs the browser-side inspection and testing inside the automated session.
PTK Auto is not the interactive version of OWASP PTK and does not provide the complete manual testing interface. Install the full OWASP PTK extension if you want to inspect traffic, launch scans, modify requests or test JWTs manually.
During an authorised scan, PTK Auto may inspect application traffic, page resources and browser behaviour required by the selected checks. Use a dedicated browser profile and test environment whenever possible.
Use PTK Auto only against applications where you have explicit authorisation. Active security testing can generate additional traffic, modify application data and trigger security monitoring.
Оценено 0 рецензентами на 0
Разрешения и данные
Требуемые разрешения:
- Получать доступ ко вкладкам браузера
- Получать доступ к активности браузера при навигации
- Получать доступ к вашим данных на всех сайтах
Требуемый сбор данных, по словам разработчика:
- Информация для аутентификации
- Активность в Интернете
- Содержимое веб-сайтов
Больше сведений
- Ссылки дополнения
- Версия
- 9.9.8.1
- Размер
- 3,02 МБ
- Последнее обновление
- 22 дня назад (6 авг. 2026 г.)
- Связанные категории
- История версий
- Добавить в подборку