toolkit

Is this page any good?

OWASP ZAP DAST evidence

OWASP ZAP DAST report ingestion for a deployed web candidate — reads an existing ZAP traditional JSON report, verifies that every scanned site and instance belongs to the declared candidate origin, binds the evidence to the candidate digest, normalizes risk/CWE/affected-path findings, and writes deterministic JSON plus a self-contained HTML handover report.

What this capability does

OWASP ZAP DAST report ingestion for a deployed web candidate — reads an existing ZAP traditional JSON report, verifies that every scanned site and instance belongs to the declared candidate origin, binds the evidence to the candidate digest, normalizes risk/CWE/affected-path findings, and writes deterministic JSON plus a self-contained HTML handover report.

How employees use it

Ask for the outcome in normal job language. The coding agent selects the approved implementation, records evidence, and returns a review-ready result.

“ingest a ZAP report for https://sherberandrad.com”

Where the technical instructions live

The detailed implementation guide stays inside the private Toolkit repository. Employee-facing pages intentionally use friendly capability names only.

Watch real OpenCode results in Toolkit in Action →