hoangnguyen0403/pentest
PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.
npx skills add https://github.com/HoangNguyen0403/agent-skills-standard --skill pentest
> [!IMPORTANT]
> PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.
Optional args: slug=<feature>, ticket=<id/url>, mode=interactive|autonomous|channel, channel=<id>, auto_continue=true|false, profile=business|hybrid|technical.
When the user asks to perform this workflow, execute the following steps:
Goal: Execute a red-team assessment across backend, frontend, and mobile targets with verified PoCs and audit-grade evidence.
whitebox, greybox, blackbox) and targets.common-security-audit, common-dast-tooling, and architecture docs when available.specialist-aspm-correlator, dynamic/logic to specialist-logic-hacker, binary/mobile to specialist-mobile-reverser.exposure × sensitivity × auth_coverage.artifacts/security-review.md with assumptions, source provenance, review context, runtime contract, PoCs, blast radius, finding confidence, exploit path, evidence gaps, and handoff notes.artifacts/security-review.dev.md, artifacts/security-review.appsec.md, or artifacts/security-review.exec.md only when leadership, client, or AppSec reporting is in scope.security-review.md record when pentest follows earlier design or PR security review work.| ID | Title | Platform | Severity | CVSS | CWE | PoC |
| --- | --- | --- | --- | --- | --- | --- |
| SEC-01 | [title] | [backend\|frontend\|mobile] | [Critical\|High\|Medium\|Low] | [score] | [CWE-id] | [Yes\|No] |
Take hoangnguyen0403/pentest from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.