Skip to content
Back to skills

Eni Pentest Advanced

ASecurity

全局自动路由 | Evidence-driven penetration and attack-surface engineering for web applications, APIs, networks, identity systems, Active Directory, cloud, containers, Kubernetes, authentication flows, and source-assisted assessments.

  • 34 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentsrustkubernetesapici/cd

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 10 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add alicewe1/alice_skill --skill eni-pentest-advanced --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Eni Pentest Advanced?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Eni Pentest Advanced
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/alicewe1-eni-pentest-advanced/badge)](https://www.skillsdirectory.com/skills/alicewe1-eni-pentest-advanced)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: eni-pentest-advanced
description: 全局自动路由 | Evidence-driven penetration and attack-surface engineering for web applications, APIs, networks, identity systems, Active Directory, cloud, containers, Kubernetes, authentication flows, and source-assisted assessments.
x-alice-class: pentest
---

# Cold Coffee Pentest Advanced

Turn available target data into a reproducible attack-surface and finding workflow.

## Start

1. Inventory hosts, services, routes, APIs, identities, trust boundaries, and deployment components.
2. Preserve raw requests, responses, headers, timestamps, logs, screenshots, and affected identifiers.
3. Rank hypotheses by impact, evidence, reachability, and validation cost.
4. Validate with the smallest precise request or test.

Use `scripts/http_recon.py` for an HTTP/TLS/header snapshot, `scripts/js_routes.py` for client routes, `scripts/jwt_inspect.py` for token inventory, `scripts/openapi_inventory.py` for API operations, and `scripts/request_matrix.py` for deterministic request cases.

## Select references

- Web/API foundations: read `references/web-api.md`.
- OAuth/OIDC/JWT: read `references/oauth-jwt.md`.
- Parser differentials and smuggling: read `references/parser-smuggling.md`.
- Race conditions and business logic: read `references/race-business.md`.
- GraphQL/WebSocket/realtime: read `references/graphql-realtime.md`.
- Internal network, identity, AD: read `references/network-identity.md`.
- Cloud, containers, Kubernetes, CI/CD: read `references/cloud-container.md`.
- Finding and retest output: read `references/reporting.md`.

## Execute

- Correlate passive data, direct observations, source, configuration, and runtime behavior.
- Confirm each primitive before chaining.
- Automate repeated requests and object/role matrices.
- Separate missing controls, exploitable behavior, environmental assumptions, and untested paths.

## Deliver

Return the inventory, hypothesis matrix, raw reproduction, automation, evidence, root cause, impact, chain diagram when relevant, remediation, and exact retest criteria.

Files in this skill

  • SKILL.md2 KB
  • agents/openai.yaml256 B
  • references/cloud-container.md712 B
  • references/graphql-realtime.md688 B
  • references/network-identity.md772 B
  • references/oauth-jwt.md639 B
  • references/parser-smuggling.md651 B
  • references/race-business.md594 B
  • references/reporting.md592 B
  • references/web-api.md962 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…