integrating-dast-with-owasp-zap-in-pipeline

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Orchestrates security scans by executing Docker commands via Python's subprocess module. This functionality is implemented in scripts/agent.py and scripts/process.py to run the OWASP ZAP scanner in an isolated container.\n- [EXTERNAL_DOWNLOADS]: Utilizes trusted security testing resources, including the zaproxy/zap-stable Docker image and official OWASP ZAP GitHub Actions (zaproxy/action-baseline, zaproxy/action-full-scan, and zaproxy/action-api-scan). These downloads originate from a well-known security organization and are appropriate for the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 12:00 AM