---
name: web-application-security
description: Review web applications for injection, XSS, CSRF, SSRF, unsafe redirects, uploads, and browser security weaknesses.
---

# Web Application Security

Trace untrusted input to SQL, shell, templates, HTML, URLs, file paths, parsers, and outbound requests. Check output encoding, validation, same-origin protections, upload type and size, path traversal, SSRF allowlists, security headers, and safe error handling.
