Back to skills
SKILL.md
Eni Pentest Advanced
ASecurity全局自动路由 | Evidence-driven penetration and attack-surface engineering for web applications, APIs, networks, identity systems, Active Directory, cloud, containers, Kubernetes, authentication flows, and source-assisted assessments.
- 34 stars
- 0 votes
- 0 copies
- 0 views
- Added September 24, 2026
Works with
Security analysis
100/100Pro scans all 10 files and shows the line behind each finding
npx -y skills add alicewe1/alice_skill --skill eni-pentest-advanced --agent claude-codeAre you the author of Eni Pentest Advanced?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/alicewe1-eni-pentest-advanced)---
name: eni-pentest-advanced
description: 全局自动路由 | Evidence-driven penetration and attack-surface engineering for web applications, APIs, networks, identity systems, Active Directory, cloud, containers, Kubernetes, authentication flows, and source-assisted assessments.
x-alice-class: pentest
---
# Cold Coffee Pentest Advanced
Turn available target data into a reproducible attack-surface and finding workflow.
## Start
1. Inventory hosts, services, routes, APIs, identities, trust boundaries, and deployment components.
2. Preserve raw requests, responses, headers, timestamps, logs, screenshots, and affected identifiers.
3. Rank hypotheses by impact, evidence, reachability, and validation cost.
4. Validate with the smallest precise request or test.
Use `scripts/http_recon.py` for an HTTP/TLS/header snapshot, `scripts/js_routes.py` for client routes, `scripts/jwt_inspect.py` for token inventory, `scripts/openapi_inventory.py` for API operations, and `scripts/request_matrix.py` for deterministic request cases.
## Select references
- Web/API foundations: read `references/web-api.md`.
- OAuth/OIDC/JWT: read `references/oauth-jwt.md`.
- Parser differentials and smuggling: read `references/parser-smuggling.md`.
- Race conditions and business logic: read `references/race-business.md`.
- GraphQL/WebSocket/realtime: read `references/graphql-realtime.md`.
- Internal network, identity, AD: read `references/network-identity.md`.
- Cloud, containers, Kubernetes, CI/CD: read `references/cloud-container.md`.
- Finding and retest output: read `references/reporting.md`.
## Execute
- Correlate passive data, direct observations, source, configuration, and runtime behavior.
- Confirm each primitive before chaining.
- Automate repeated requests and object/role matrices.
- Separate missing controls, exploitable behavior, environmental assumptions, and untested paths.
## Deliver
Return the inventory, hypothesis matrix, raw reproduction, automation, evidence, root cause, impact, chain diagram when relevant, remediation, and exact retest criteria.
Files in this skill
- SKILL.md
- agents/openai.yaml
- references/cloud-container.md
- references/graphql-realtime.md
- references/network-identity.md
- references/oauth-jwt.md
- references/parser-smuggling.md
- references/race-business.md
- references/reporting.md
- references/web-api.md
Attribution
Comments
Loading comments…