Thank you for contributing to OWASP PTK. Contributions to the browser extension, scanning engines, tests, documentation, and build tooling are welcome.
- Search existing issues and pull requests to avoid duplicate work.
- Open an issue before a large or security-sensitive change so scope and compatibility can be discussed.
- Never test PTK against a system unless you are authorised to do so.
- Do not include credentials, API keys, cookies, access tokens, browser profiles, or unredacted scan artifacts in an issue or pull request.
PTK requires a current Node.js and npm environment.
git clone https://github.com/DenisPodgurskii/pentestkit.git
cd pentestkit
npm ci
npm run buildFor Chromium-family browsers, enable developer mode on the extensions page and load the repository's src/ directory as an unpacked extension.
Build all store and automation variants with:
npm run build_pkgGenerated artifacts are written under dist/ and must not be committed.
- Create a focused branch from the repository's default branch.
- Keep unrelated formatting and dependency changes out of the pull request.
- Explain what changed, why it changed, and how it was tested.
- Add or update automated tests for behaviour changes.
- Include browser, operating system, target application, and reproduction details where relevant.
- Redact secrets and personal or target-specific data from logs and screenshots.
Run checks in proportion to the affected area. Useful repository checks include:
npm run validate:modules
node --test test/*.test.jsChanges that affect extension loading, scan execution, automation, or packaging should also be validated against the relevant Chromium and Firefox builds. Engine changes should include a bounded reproduction case and demonstrate that DAST, SAST, IAST, or SCA results have not regressed unexpectedly.
Changes to PTK Agent, its frameworks, providers, or published npm package belong in ptklabs/ptk-agent. This repository keeps link-forwarding npm documentation only so existing documentation URLs remain useful.
Keep input validation, URL scope, extension message boundaries, DOM rendering, storage, and secret handling explicit. Changes that alter browser permissions, content-script injection, scan scope, automation trust, or the ZAP browser lifecycle need clear threat and regression analysis.
Scanning probes must respect the configured scope and must not introduce destructive behaviour by default. Document any probe that can change application state or create significant load.
Do not report security vulnerabilities in a public issue. Follow the private disclosure process in SECURITY.md.
By contributing, you agree that your contributions will be licensed under the project's GNU Affero General Public License v3.0.