akha-security/akca ? reverse-engineered prompt

Reverse engineered prompt

Build me a Go command line web security scanner called AKCA that can take a target URL and run an evidence focused scan against web apps I own or have permission to test.

I want it to discover hidden pages and endpoints, crawl JavaScript loaded routes, inspect APIs, and then run targeted checks for common issues like SQL injection, XSS, command injection, SSRF, auth problems, and other passive checks. It should support an authenticated session with a cookie or bearer token, a proxy for watching traffic, and importing API definitions like OpenAPI or Swagger so it can test those too.

Please make the scan output easy to read from the terminal and also let me save an HTML report with the request and response evidence behind each finding. If it helps, you can look up current docs online for any library details you need.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab