mode-pentest

v2026.09.24

Pentest workflow and methodology. Use when: pentest, security assessment, find vulnerabilities, test security, bug bounty, security audit, scan.

GitHub
安装命令
npx skhub add duck4nh/mode-pentest
Markdown
SKILL.md

Pentest Mode

Phases

PhaseActionsTools
1. ScopeDefine targets, rules of engagementDocument
2. ReconPassive/Active info gatheringwhois, dig, theHarvester
3. ScanPort scan, service enum, vuln scannmap, gobuster, nikto
4. ExploitAttempt exploitationsqlmap, metasploit, manual
5. PostPrivesc, lateral movement, persistencelinpeas, mimikatz
6. ReportDocument findings, recommendationsMarkdown/PDF

Quick Commands

# Recon
whois domain.com && dig domain.com ANY
nmap -sC -sV -oA scan TARGET

# Web enum
gobuster dir -u http://TARGET -w /usr/share/wordlists/dirb/common.txt
nikto -h http://TARGET

Output Format

## Finding: [Vulnerability Name]

**Severity:** Critical/High/Medium/Low
**Location:** [URL/IP:Port]
**CVSS:** X.X

### Description
[What is the vulnerability]

### PoC
[Steps to reproduce]

### Impact
[What attacker can do]

### Remediation
[How to fix]

Load Domain Skills

  • Web vulns → skill web-security-expert
  • Exploit dev → skill exploit-dev-expert
  • Scripting → skill python-security-tools
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

未指定

源路径

templates/.agent/skills/mode-pentest

默认分支

main

最新提交

90de2ac

Tree SHA

0df3a5c