mode-pentest

v2026.09.24

Pentest workflow and methodology. Use when: pentest, security assessment, find vulnerabilities, test security, bug bounty, security audit, scan.

GitHub
Install command
npx skhub add duck4nh/mode-pentest
Markdown
SKILL.md

Pentest Mode

Phases

PhaseActionsTools
1. ScopeDefine targets, rules of engagementDocument
2. ReconPassive/Active info gatheringwhois, dig, theHarvester
3. ScanPort scan, service enum, vuln scannmap, gobuster, nikto
4. ExploitAttempt exploitationsqlmap, metasploit, manual
5. PostPrivesc, lateral movement, persistencelinpeas, mimikatz
6. ReportDocument findings, recommendationsMarkdown/PDF

Quick Commands

# Recon
whois domain.com && dig domain.com ANY
nmap -sC -sV -oA scan TARGET

# Web enum
gobuster dir -u http://TARGET -w /usr/share/wordlists/dirb/common.txt
nikto -h http://TARGET

Output Format

## Finding: [Vulnerability Name]

**Severity:** Critical/High/Medium/Low
**Location:** [URL/IP:Port]
**CVSS:** X.X

### Description
[What is the vulnerability]

### PoC
[Steps to reproduce]

### Impact
[What attacker can do]

### Remediation
[How to fix]

Load Domain Skills

  • Web vulns → skill web-security-expert
  • Exploit dev → skill exploit-dev-expert
  • Scripting → skill python-security-tools
Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

Not specified

Source path

templates/.agent/skills/mode-pentest

Default branch

main

Latest commit

90de2ac

Tree SHA

0df3a5c