# Pentest

> PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

- Skill: `hoangnguyen0403/pentest` (Agent Skill)
- Install (CLI): `npx skillmds add hoangnguyen0403/pentest`
- Raw SKILL.md: https://api.skillmd.com/api/skills/hoangnguyen0403/pentest/raw
- Safety review: pending (external: skill-scanner PASS, skillspector CAUTION)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Web & Frontend
- Author: HoangNguyen0403 (https://skillmd.com/u/hoangnguyen0403)
- Updated: 2026-08-19
- Page: https://skillmd.com/skills/hoangnguyen0403/pentest

---

# Pentest Skill

> [!IMPORTANT]
> PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

Optional args: slug=<feature>, ticket=<id/url>, mode=interactive|autonomous|channel, channel=<id>, auto_continue=true|false, profile=business|hybrid|technical.

## Instructions

When the user asks to perform this workflow, execute the following steps:


# 🕵️‍♂️ Penetration Test (PTES-Aligned)

Goal: Execute a red-team assessment across backend, frontend, and mobile targets with verified PoCs and audit-grade evidence.

## Steps

1. Scope and authorization:
   - Determine mode (`whitebox`, `greybox`, `blackbox`) and targets.
   - Verify explicit authorization; stop if unauthorized.

2. Intel and threat model:
   - Identify stack, endpoints, parameters, local storage, schemes, and secrets.
   - Use `common-security-audit`, `common-dast-tooling`, and architecture docs when available.
   - Map trust boundaries, secrets, external integrations, and privileged workflows before exploit attempts.

3. Vulnerability analysis:
   - Run scans and delegate: SAST/SCA to `specialist-aspm-correlator`, dynamic/logic to `specialist-logic-hacker`, binary/mobile to `specialist-mobile-reverser`.
   - Rank targets by `exposure × sensitivity × auth_coverage`.

4. Exploit verification:
   - **No Exploit = No Report.** Discard unverified findings.
   - Build reproducible PoCs and record preconditions, payloads, evidence, and blast radius.

5. Reporting:
   - Write `artifacts/security-review.md` with assumptions, source provenance, review context, runtime contract, PoCs, blast radius, finding confidence, exploit path, evidence gaps, and handoff notes.
   - Emit `artifacts/security-review.dev.md`, `artifacts/security-review.appsec.md`, or `artifacts/security-review.exec.md` only when leadership, client, or AppSec reporting is in scope.
   - Score from 100: Critical -25 (cap 25), High -15 (cap 40), Medium -8, Low -3.
   - Reuse the existing `security-review.md` record when pentest follows earlier design or PR security review work.
   - Deliver findings in the standard template below.

## Output Template

### Executive Summary

- **Hacker Score**: X/100 ([Critical/Vulnerable/Moderate/Hardened])
- **Target Scope**: [repos, URLs, mobile apps]
- **Findings**: [Critical/High/Medium/Low counts]

### Findings Table

| ID | Title | Platform | Severity | CVSS | CWE | PoC |
| --- | --- | --- | --- | --- | --- | --- |
| SEC-01 | [title] | [backend\|frontend\|mobile] | [Critical\|High\|Medium\|Low] | [score] | [CWE-id] | [Yes\|No] |


