{"_id":"@aegiskit/dast","_rev":"3-b6b6a272f3ab9f92994bde475df381fb","name":"@aegiskit/dast","dist-tags":{"latest":"0.0.3"},"versions":{"0.0.1":{"name":"@aegiskit/dast","version":"0.0.1","keywords":["security","dast","dynamic-analysis","penetration-testing","nextjs","supabase","appsec"],"author":{"name":"tomodahinata"},"license":"MIT","_id":"@aegiskit/dast@0.0.1","maintainers":[{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"}],"homepage":"https://github.com/tomodahinata/aegis/tree/main/packages/dast#readme","bugs":{"url":"https://github.com/tomodahinata/aegis/issues"},"dist":{"shasum":"10c4217cab01ed610db86f74d150b8b715a996a1","tarball":"https://registry.npmjs.org/@aegiskit/dast/-/dast-0.0.1.tgz","fileCount":5,"integrity":"sha512-b87w1+IOPzMcB9T1hni1xPHk3k6qzB1/k92gkaZljz95xVNrQAa3HyGg/6Binar4twmTWvHBHkyYzlZmw+6s2A==","signatures":[{"sig":"MEQCIBmh6qFu4yZ/Dmyoj9vwlkV9rI+MirFyyIk5dzrqBdSoAiA+cgdDhetpK5CEwQSXAmhTC9Solx/3DMVzITex58u6kg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":61348},"main":"./dist/index.js","type":"module","_from":"file:aegiskit-dast-0.0.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"},"_resolved":"/tmp/d78d97da85749f92f62200caa3b58c86/aegiskit-dast-0.0.1.tgz","_integrity":"sha512-b87w1+IOPzMcB9T1hni1xPHk3k6qzB1/k92gkaZljz95xVNrQAa3HyGg/6Binar4twmTWvHBHkyYzlZmw+6s2A==","repository":{"url":"git+https://github.com/tomodahinata/aegis.git","type":"git","directory":"packages/dast"},"_npmVersion":"11.13.0","description":"Dynamic application security testing for Aegis — confirms vulnerabilities against YOUR OWN running Next.js/Supabase app via bounded, non-destructive HTTP probes, and correlates them with static findings.","directories":{},"sideEffects":false,"_nodeVersion":"24.17.0","dependencies":{"@aegiskit/scanner":"0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.9","fast-check":"^4.8.0","typescript":"^6.0.3","@types/node":"^24.0.0"},"_npmOperationalInternal":{"tmp":"tmp/dast_0.0.1_1782540504184_0.3070144551392935","host":"s3://npm-registry-packages-npm-production"}},"0.0.2":{"name":"@aegiskit/dast","version":"0.0.2","keywords":["security","dast","dynamic-analysis","penetration-testing","nextjs","supabase","appsec"],"author":{"name":"tomodahinata"},"license":"MIT","_id":"@aegiskit/dast@0.0.2","maintainers":[{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"}],"homepage":"https://github.com/tomodahinata/aegis/tree/main/packages/dast#readme","bugs":{"url":"https://github.com/tomodahinata/aegis/issues"},"dist":{"shasum":"5f6221966363c0299a753e0a1fe0d67524ad7ab8","tarball":"https://registry.npmjs.org/@aegiskit/dast/-/dast-0.0.2.tgz","fileCount":5,"integrity":"sha512-R57monh/Ggh3/X29rS/ppIHtuDhQgDfznRVbBPVxaWBWwrAsA1nbGHWa/WrpZ8/iZPK/Nbbd+MJ/LtZa8v481g==","signatures":[{"sig":"MEUCIAnCh/paDgbJweGy7zdWK+AOkZue2TEh7GEXS8yPVAbOAiEAw9NBahWnC6lhsM7UBiN6qbLHIRyY+HxpxGM8rG+7t2g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aegiskit%2fdast@0.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":61348},"main":"./dist/index.js","type":"module","_from":"file:aegiskit-dast-0.0.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=24.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"},"_resolved":"/tmp/1f44a97d29da5370cb86fa469e3b2f50/aegiskit-dast-0.0.2.tgz","_integrity":"sha512-R57monh/Ggh3/X29rS/ppIHtuDhQgDfznRVbBPVxaWBWwrAsA1nbGHWa/WrpZ8/iZPK/Nbbd+MJ/LtZa8v481g==","repository":{"url":"git+https://github.com/tomodahinata/aegis.git","type":"git","directory":"packages/dast"},"_npmVersion":"11.13.0","description":"Dynamic application security testing for Aegis — confirms vulnerabilities against YOUR OWN running Next.js/Supabase app via bounded, non-destructive HTTP probes, and correlates them with static findings.","directories":{},"sideEffects":false,"_nodeVersion":"24.17.0","dependencies":{"@aegiskit/scanner":"0.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.5.1","vitest":"^4.1.9","fast-check":"^4.8.0","typescript":"^6.0.3","@types/node":"^24.0.0"},"_npmOperationalInternal":{"tmp":"tmp/dast_0.0.2_1782659676837_0.019741016602051298","host":"s3://npm-registry-packages-npm-production"}},"0.0.3":{"name":"@aegiskit/dast","version":"0.0.3","description":"Dynamic application security testing for Aegis — confirms vulnerabilities against YOUR OWN running Next.js/Supabase app via bounded, non-destructive HTTP probes, and correlates them with static findings.","license":"MIT","type":"module","sideEffects":false,"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"dependencies":{"@aegiskit/scanner":"0.3.0"},"devDependencies":{"@types/node":"^26.0.1","fast-check":"^4.8.0","tsup":"^8.5.1","typescript":"^6.0.3","vitest":"^4.1.9"},"engines":{"node":">=24.0.0"},"keywords":["security","dast","dynamic-analysis","penetration-testing","nextjs","supabase","appsec"],"author":{"name":"tomodahinata"},"homepage":"https://github.com/tomodahinata/aegis/tree/main/packages/dast#readme","repository":{"type":"git","url":"git+https://github.com/tomodahinata/aegis.git","directory":"packages/dast"},"bugs":{"url":"https://github.com/tomodahinata/aegis/issues"},"publishConfig":{"access":"public"},"scripts":{"build":"tsup","typecheck":"tsc --noEmit"},"_id":"@aegiskit/dast@0.0.3","_integrity":"sha512-iW7i023IDfTKtRF2nTyCjnHakvQjDtEF2bMaxiQaiMWqzzzEQKH5PDsy4Mypkh/bwDvLcZi6YafMwuNs4LIetw==","_resolved":"/tmp/26f9543c301ad6637cc7d4ed39ba660d/aegiskit-dast-0.0.3.tgz","_from":"file:aegiskit-dast-0.0.3.tgz","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-iW7i023IDfTKtRF2nTyCjnHakvQjDtEF2bMaxiQaiMWqzzzEQKH5PDsy4Mypkh/bwDvLcZi6YafMwuNs4LIetw==","shasum":"e37f193bf6a13b98e91c62b1b22c6e7e72f2fcc4","tarball":"https://registry.npmjs.org/@aegiskit/dast/-/dast-0.0.3.tgz","fileCount":5,"unpackedSize":61348,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@aegiskit%2fdast@0.0.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD606gEP2DgODR0sP7slpzbehzhlEwTRoz3rndlC4zZawIgNDMsqUNr+heHv3W8m74I0QbIFi3E453WNPya8Qif5O0="}]},"_npmUser":{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"},"directories":{},"maintainers":[{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dast_0.0.3_1783680187313_0.3116843175667581"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-27T06:08:24.076Z","modified":"2026-07-10T10:43:07.750Z","0.0.1":"2026-06-27T06:08:24.332Z","0.0.2":"2026-06-28T15:14:36.978Z","0.0.3":"2026-07-10T10:43:07.470Z"},"bugs":{"url":"https://github.com/tomodahinata/aegis/issues"},"author":{"name":"tomodahinata"},"license":"MIT","homepage":"https://github.com/tomodahinata/aegis/tree/main/packages/dast#readme","keywords":["security","dast","dynamic-analysis","penetration-testing","nextjs","supabase","appsec"],"repository":{"type":"git","url":"git+https://github.com/tomodahinata/aegis.git","directory":"packages/dast"},"description":"Dynamic application security testing for Aegis — confirms vulnerabilities against YOUR OWN running Next.js/Supabase app via bounded, non-destructive HTTP probes, and correlates them with static findings.","maintainers":[{"name":"tomodahinata","email":"hikaru.hinata.hikari@icloud.com"}],"readme":"# @aegiskit/dast\n\n**Dynamic application security testing for Aegis** — send safe, bounded, **non-destructive** HTTP probes to a **running app you own**, confirm a subset of vulnerabilities at runtime, and **correlate** them with `@aegiskit/scanner`'s static findings.\n\n```bash\n# Probe a running localhost app (passive, non-destructive — the safe default).\naegis probe http://localhost:3000\n\n# Confirm static findings at runtime: a \"possible SQLi\" that reproduces becomes build-blocking.\naegis probe http://localhost:3000 --correlate\n\n# See exactly what it WOULD send, without sending anything.\naegis probe http://localhost:3000 --dry-run\n\n# Enable active (state-changing-method) probes.\naegis probe http://localhost:3000 --active\n```\n\n> The credentialed `dast/auth-required` and `dast/idor` probes need test identities, which are\n> supplied only via the programmatic API (`probe({ origin, mode: 'active', identities })`). The\n> `aegis probe` CLI does not yet expose an `--identities` flag, so `--active` alone enables the\n> active-method probes but not the credentialed ones.\n\n## What it does\n\nStatic analysis *suspects*; dynamic analysis *confirms*. When the scanner flags a possible SQL injection on `app/api/x/route.ts` and a probe **reproduces** it on the live `/api/x`, Aegis upgrades that finding to **confirmed exploitable at runtime** — raising its confidence to `high` (so it now fails the build) and attaching the real HTTP exchange as evidence. That cross-check is the point: it kills the false-positive fatigue that erodes trust in security tooling.\n\nFindings flow through the **same** reporters as the scanner (`pretty`, `json`, SARIF) — a DAST finding is just a `Finding` located by `METHOD /path` instead of `file:line`.\n\n### Probes\n\n| Probe | Detects | Default |\n| --- | --- | --- |\n| `dast/security-headers` | CSP/HSTS/X-Frame-Options/etc. missing at runtime | ✓ |\n| `dast/cookie-flags` | session cookie without HttpOnly/Secure/SameSite | ✓ |\n| `dast/error-disclosure` | leaked stack traces / framework errors | ✓ |\n| `dast/open-redirect` | redirect to an attacker-controlled host | ✓ |\n| `dast/reflected-xss` | a marker reflected **unescaped** into HTML | ✓ |\n| `dast/sql-injection` | boolean-differential / error-based injection (no destruction) | ✓ |\n| `dast/ssrf` | server-side fetch of an attacker URL, via an out-of-band **canary** | ✓ |\n| `dast/missing-rate-limit` | no 429 across a bounded burst | ✓ |\n| `dast/auth-required` | a route marked protected reachable **unauthenticated** | `--active` + identities (API) |\n| `dast/idor` | one identity reading another's object | `--active` + identities (API) |\n\n## Safety (non-negotiable)\n\nThis is a **defensive tool you point at your own app**, not an attack framework. It is built to be impossible to casually misuse:\n\n- **Localhost by default.** A non-loopback target requires **both** `--allow-remote` and `--i-own \"<attestation>\"` whose origin matches the target. The attestation is recorded in the report.\n- **Scope-confined.** Requests never leave the target origin; off-origin redirects and link-local / cloud-metadata IPs (`169.254.169.254`) are hard-blocked even with consent (the SSRF-into-the-scanner defense). Redirects are captured, never followed.\n- **Non-destructive.** SQLi uses boolean/error *inference* (never `DROP`/stacked queries); SSRF uses an out-of-band canary (never a real internal fetch); rate-limit uses a small bounded burst. Nothing mutates state.\n- **Bounded.** A hard request cap, concurrency limit, self-rate-limit, per-request timeout, and global deadline — enforced centrally so no probe can exceed them.\n- **Fail secure.** On any ambiguity it sends nothing; a probe that errors is *inconclusive*, never a pass. Response bodies are truncated and secrets redacted before they enter a report.\n\n## Honest scope\n\nDAST covers **only the surface it can reach and was told to probe**. It is **not exhaustive**, does not crawl your whole app, and finds nothing in code paths it never reaches. Aegis does **not** \"run every attack a world-class attacker would\" — that claim is false, and false confidence is itself the worst security outcome. This **complements** — it does not replace — static analysis, the runtime controls in `@aegiskit/next`/`@aegiskit/core`, code review, and **manual penetration testing**. Only point it at systems you own or are explicitly authorized to test.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}