pentest-expert

v2026.09.24

Penetration testing methodology expert. OWASP, PTES, reconnaissance, scanning, exploitation, reporting. Use for security assessments.

GitHub
Install command
npx skhub add duck4nh/pentest-expert
Markdown
SKILL.md

Pentest Expert

Methodology

1. Reconnaissance

# Passive
whois target.com
dig target.com ANY +noall +answer
host -t mx target.com
theHarvester -d target.com -b google,bing,linkedin

# Active
nmap -sn 192.168.1.0/24              # Host discovery
nmap -sC -sV -oA scan target         # Service scan
nmap -p- --min-rate=1000 target      # All ports fast

2. Web Enumeration

# Directory brute
gobuster dir -u http://target -w /usr/share/wordlists/dirb/common.txt
feroxbuster -u http://target -w wordlist.txt

# Subdomain enum
subfinder -d target.com
amass enum -d target.com

# Tech detection
whatweb http://target
wappalyzer http://target

3. Vulnerability Scanning

nikto -h http://target
nuclei -u http://target -t cves/
sqlmap -u "http://target/page?id=1" --batch

Severity Rating

LevelCVSSExamples
Critical9.0-10.0RCE, Auth bypass, SQLi with data
High7.0-8.9Stored XSS, IDOR with sensitive data
Medium4.0-6.9Reflected XSS, Info disclosure
Low0.1-3.9Missing headers, version disclosure

Report Structure

  1. Executive Summary
  2. Scope & Methodology
  3. Findings (sorted by severity)
  4. Remediation Recommendations
  5. Appendix (raw data, screenshots)
Discovery
Tags

No tags published for this skill.

Version
Latest version metadata

Version

v2026.09.24

Published

Sep 24, 2026

Category

Uncategorized

License

Not specified

Source path

templates/.agent/skills/pentest-expert

Default branch

main

Latest commit

90de2ac

Tree SHA

0df3a5c