web-pentest

Automate phased web application security testing with scope enforcement and secret redaction.

Updated May 11, 2026
One-click install
npx skills add https://github.com/jason660519/Project-Manager --skill web-pentest-jason660519
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: web-pentest
Source: https://github.com/jason660519/Project-Manager/tree/main/hermes-agent/optional-skills/security/web-pentest
Command: npx skills add https://github.com/jason660519/Project-Manager --skill web-pentest-jason660519

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Authorized teams need a structured, auditable approach to web security testing that maximizes findings with safety guardrails and scope enforcement.

Core Features & Use Cases

  • Comprehensive, phased web-pentest workflow with pre-recon, recon, vulnerability analysis, exploitation, and reporting.
  • Evidence-driven methodology that redacts sensitive data and enforces authorization scopes.
  • Use cases include API endpoints, single-page apps, and multi-page sites requiring controlled testing workflows.

Quick Start

Start a new engagement by invoking the web-pentest skill against an authorized target and follow the guided phases.

Frequently Asked Questions about web-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate structured web application penetration testing for an authorized target?▼

Web penetration testing for single-page apps and APIs follows a phased workflow of pre-recon, recon, vulnerability analysis, exploitation, and reporting. This guided methodology applies evidence-driven checks with strict scope enforcement across bounded engagements.

Can I use this pentest workflow for API endpoints and single-page apps?▼

Yes, this penetration testing methodology applies to API endpoints, single-page apps, and multi-page sites. It executes controlled testing workflows across these target types while enforcing strict authorization scope boundaries.

How does this vulnerability analysis methodology handle sensitive data during reporting?▼

The vulnerability analysis methodology redacts sensitive data during the reporting phase. It utilizes an evidence-driven approach that explicitly removes secrets from generated security reports while documenting findings.

What is the best way to ensure penetration testing stays within a bounded engagement scope?▼

To maintain penetration testing within a bounded engagement, apply a workflow with explicit scope enforcement and safety guardrails. The methodology performs strict authorization checks before executing pre-recon, recon, and exploitation phases.

What are the limitations of using an automated pentest workflow for web security testing?▼

Automated web security testing workflows are limited to bounded engagements on authorized targets. They require strict scope enforcement and safety guardrails to prevent unauthorized access, relying on pre-recon checks before executing vulnerability analysis.