Authors: Akshat Kumar, Gaurav Sharma, Deep Singh, Roovi
Abstract: Automated web security auditing combines several tasks that produce different kinds of evidence: discovering exposed functionality, exercising application behaviour, interpreting observations, and deciding which weaknesses deserve attention. This focused narrative review examines five selected studies on cross-origin resource sharing, stateful REST testing, GraphQL testing, language-model-assisted penetration testing, and vulnerability prioritization. Four protocol specifications provide supporting definitions. The literature is compared by input requirements, treatment of application state, evidence produced, and limits of interpretation. The synthesis indicates that wider endpoint coverage, successful testing actions, and confirmed security weaknesses are distinct outcomes. Schema-aware testing helps explore structured APIs, while language models can support interpretation and planning; neither removes the need to validate findings against observable behavior. The review identifies evaluation comparability, authentication context, evidence of traceability, and constrained AI assistance as priorities for an AI Security Auditor project. It presents design implications and future evaluation questions without reporting a new implementation, benchmark, or experiment. The source selection is purposive rather than exhaustive, and conclusions are limited to the reviewed material.
International Journal of Science, Engineering and Technology