Authorised dynamic security testing of the project's OWN application (dev/staging or explicitly approved prod) — OWASP ZAP baseline/API scan (OpenAPI/GraphQL), Nuclei, Schemathesis fuzzing, testssl.sh, nmap on the project's own host, manual OWASP checks for auth/IDOR/GraphQL limits; report with CVSS and fixes in docs/security/pentest-<date>.md. Scope must be confirmed first.
Scanned 9/22/2026
Install to Claude Code
npx -y skills add gonimar/claude-web-studio --skill pentest --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Pentest?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/gonimar-pentest)More formats (shields.io, HTML) on the badges page.
---
name: pentest
description: "Authorised dynamic security testing of the project's OWN application (dev/staging or explicitly approved prod) — OWASP ZAP baseline/API scan (OpenAPI/GraphQL), Nuclei, Schemathesis fuzzing, testssl.sh, nmap on the project's own host, manual OWASP checks for auth/IDOR/GraphQL limits; report with CVSS and fixes in docs/security/pentest-<date>.md. Scope must be confirmed first."
argument-hint: "[target-url] [--scope dev|staging|prod] [--quick]"
user-invocable: true
allowed-tools: Read, Glob, Grep, Bash, Write, Task, AskUserQuestion
model: sonnet
agent: appsec-engineer
---
# Pentest (the project's own application)
Reply in the project conversation language (CLAUDE.md → Language); code, identifiers, paths and commit messages stay in English.
Template `templates/pentest-report.md`; reference `stack-reference/security-standards.md`. **The scope is fixed before the first request**: only the project's own hosts/domains from technical-preferences/deployment docs; production only with an explicit "yes" and in an agreed window. Targets outside the project are refused.
## Phase 1: Scope and confirmation
`AskUserQuestion`: target (URL), environment, window, accounts for authenticated checks, exclusions (payments, e-mails). Record the scope as the report's first section.
## Phase 2: Tools (whatever is installed; otherwise docker images with consent)
ZAP baseline → full/API scan (OpenAPI or GraphQL introspection on dev); Nuclei (web/misconfig templates); Schemathesis on OpenAPI / GraphQL fuzzing; `testssl.sh`; `nmap -sV` on the project's own host; manual checks: IDOR (two accounts), GraphQL field permissions, depth/batching limits, login rate limit, password reset, uploads, CSRF/CORS, headers.
`--quick` — ZAP baseline + headers + testssl only.
## Phase 3: Findings
Severity/CVSS, steps, evidence (no secrets), fix (code/config), verification after the fix; "clean" areas listed.
## Phase 4: Write
"May I write `docs/security/pentest-<date>.md`?" — one `AskUserQuestion`: write (Recommended) · show the draft/diff first · not now. Stories for High+. After the "write" answer: `touch .claude/.write-consent` (rule 7 — the consent-guard hook checks the marker).
Verdict: `PASS` | `FINDINGS (C/H/M/L)`. Next step — one `AskUserQuestion`: fixes, then `/pentest --quick` again (Recommended) · `/harden` · report only.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!