Security

Web Security Studio

Seven security skills combining focused web reviews with an authorized pentest workflow for web, API, mobile, desktop, backend, cloud and AI applications.

My library
Resource type
Downloadable pack
Version
1.0.0
Licence
marketplace terms
Illustrative demonstration

See the boundaries before the gaps.

Fictional scenario and sample data. This preview runs no agent, audit or analysis of your data. Check the included contents for the pack’s scope.

Fictional example
POST /api/profile
Content-Type: application/json

{
  "displayName": "Example Studio"
}

Review question: who can modify this profile?

01

Start with a concrete exchange

A fictional profile update helps identify the expected controls.

01Identity
02Origin
03Data
02

Separate responsibilities

Identity, origin and incoming data are checked on the server.

sample-review.mdFictional example
  • 01Session: review scopeReview checkpoint
  • 02Origin: test validationReview checkpoint
  • 03JSON body: define limitsReview checkpoint
03

Read a sample report

The statuses below illustrate a review to perform on your application.

Contents and terms

Seven skills, from focused review to structured pentesting

Seven security skills combining focused web reviews with an authorized pentest workflow for web, API, mobile, desktop, backend, cloud and AI applications. The workflow adapts controls to the architecture, maps trust boundaries and links findings to minimized evidence, contextual severity and retesting. Existing authorization is preserved without repeated confirmations.

Practical deliverables

Scope, test matrix, finding and technical/executive report templates. Two synthetic engagements illustrate a portal with an API and a desktop/mobile application. Tool-selection guidance covers HTTP proxies, code analysis and platform inspection within the agreed scope.

Offline verification

Two dependency-free Python helpers check an access matrix or the consistency of a plan, its budgets, declared coverage and evidence. Tests, bilingual guides and OWASP/NIST primary references are included. No scanner, automatic execution permission or certification is supplied. Conclusions remain limited to the evidence actually examined.

Pack contents

  • Six specialized web reviews and one pentest workflow
  • Web, API, mobile, desktop, backend, cloud and AI profiles
  • Authorized scope, mapping and bounded tests
  • Minimized evidence, severity, remediation and retest
  • Scope, matrix, finding and report templates
  • Two offline helpers with tests and synthetic cases

7 included skills

  • stellarr-pentest-workflow
  • stellarr-web-api-review
  • stellarr-web-authorization
  • stellarr-web-headers
  • stellarr-web-sessions
  • stellarr-web-threat-model
  • stellarr-web-uploads

Installation and compatibility

ZIP archive with Agent Skills instructions, references, templates and examples. French and English guides, English operational instructions requesting deliverables in your language. Python 3.10+ installer for Codex (.agents/skills), Claude Code (.claude/skills) and OpenCode-compatible Moon CLI (.opencode/skills). Preview before copying; existing customisations are preserved. Tool subscriptions are not included.

Licence and delivery

One-time purchase for one individual user, version 1.0.0. Personal, professional and client work permitted. Pack files may not be resold or published as a resource library. Project deliverables may be supplied to clients. Private archive available in your account after payment confirmation.

Support and limitations

Delivery issues: contact@stellarrstudio.com. Bespoke consulting, API usage and hosting are not included. Skills assist human review; they are not a security certification or an operational SaaS application. Statutory guarantees remain applicable.

Adapted to your application

Methods independent of Moon AI, Stellarr branding or a prescribed stack. Each skill starts from the actual project and its remit: web, mobile, desktop, CLI, API, SaaS or AI when relevant. APPLICABILITY.md helps select useful checks and explain those that do not apply.

Getting started

01

Compatibility

The technologies on this page provide a starting point. Check exact versions, dependencies and requirements in the included guides before installation.

  • Agent Skills
  • Claude Code
  • Codex
  • Moon CLI
  • OpenCode
02

Set up at your own pace

Download the archive from your account, extract it into a dedicated directory and follow README.md or README.en.md. Review commands and try the provided examples before using your own data.

03

An explicit scope

This page describes the delivered contents. Integration with your product or bespoke assistance is arranged separately with the studio. Usage rights are specified in the licence below.

Discuss a specific requirement

This resource’s licence

Read the complete terms before ordering. They define permitted uses and redistribution obligations.

Show the full text
Stellarr Studio Skills Commercial Licence 1.0

Copyright 2026 STELLARR STUDIO. Version dated 9 September 2026.

Permission to use

Purchasing this pack grants the buyer a non-exclusive, worldwide, perpetual licence to the delivered version. One licence covers one individual user, including when a business purchases it for that individual. The user may install, adapt and use the files on their devices and private repositories for personal projects, business projects and client work. Contact contact@stellarrstudio.com for a team licence covering additional users.

Deliverables and redistribution

You may exploit project deliverables and provide them to clients. This licence grants no rights over third-party materials used in those deliverables. Reselling, publishing, sublicensing or sharing the pack, its instructions, scripts or templates as a resource library is excluded. Do not place commercial skills in a public repository. Private backup copies are permitted. Keep this licence notice with copies of the pack.

Scope and requirements

The purchase covers the files and version described on the product page, without a recurring subscription. Assistant accounts, subscriptions, API usage, hardware and hosting are separate. Claude Code, Codex and OpenCode names describe integration formats, without partnership or endorsement by their publishers. Moon CLI compatibility applies where the installed version uses the documented OpenCode skill format.

Limitations and support

These resources structure the work of an assistant and a team. They are not a certified audit, a certification or an operational SaaS application. They do not guarantee model responses, vulnerability-free software or compliance of every project. Human review and appropriate verification remain necessary. Delivery support and complaints are handled at contact@stellarrstudio.com. Bespoke consultancy and future feature updates are not included unless expressly stated on the product page.

Mandatory rights

Applicable statutory guarantees, including those governing supply and conformity of digital content, remain fully applicable. This licence does not remove mandatory consumer rights or statutory remedies. The terms presented at checkout supplement this licence. Purchasing a pack does not license the Stellarr Studio or Moon AI names and logos for branding use.

A first conversation

Let’s talk about your project.

Tell us about your project in a few lines. Your message will be sent directly to our team.

PhoneMonday to Friday, 10:00 to 22:00

Saturday and Sunday: email only

Paris time (Europe/Paris)

An anti-bot check protects this form. It also runs when you choose to send your message.

Your contact details and message are used to handle your enquiry and reply to you. Learn more about your data.

You can also email contact@stellarrstudio.com.

Explore the studio

What are you looking for?

Enter a few words to find a page.

    Cookies and external content