web-pentest

Automate authorized web-application penetration testing from reconnaissance to reporting.

31|3|Updated May 7, 2026
One-click install
npx skills add https://github.com/markwang2658/hermes-windows-native --skill web-pentest-markwang2658
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: web-pentest
Source: https://github.com/markwang2658/hermes-windows-native/tree/main/hermes-agent/optional-skills/security/web-pentest
Command: npx skills add https://github.com/markwang2658/hermes-windows-native --skill web-pentest-markwang2658

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own or have written authorization to test.

Core Features & Use Cases

  • Phased pentesting workflow from engagement setup to final reporting.
  • Enforces strict scope and authorization guardrails to prevent unsafe testing.
  • Generates structured evidence and professional pentest reports.

Quick Start

Initiate a guided pentest against a target URL following the operator prompts and let Hermes orchestrate reconnaissance, exploitation, and reporting with built-in safety checks.

Frequently Asked Questions about web-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is structured web application penetration testing and how does it work?▼

Structured web application penetration testing automates an authorized workflow from reconnaissance to reporting. It applies a phased methodology covering vulnerability analysis and proof-based exploitation to running web apps, producing formal reports with structured findings.

How do I perform authorized pentesting on a running web app?▼

To perform authorized pentesting, initiate a guided engagement against a target URL. The workflow orchestrates reconnaissance, exploitation, and reporting with built-in safety checks, requiring explicit authorization and a defined scope before active testing begins.

Does web pentesting require explicit authorization and a defined scope?▼

Yes, web pentesting requires explicit engagement authorization and a defined scope. Strict guardrails enforce safe handling of sensitive payloads and prevent auxiliary-client leakage during active testing against running applications you own or have written permission to test.

What is the best way to generate a formal pentest report with structured findings?▼

The best way to generate a formal pentest report is using a phased workflow that enforces proof-based exploitation. It captures structured evidence during vulnerability analysis and compiles it into a professional pentest report at the end of the engagement.

Can I use this pentesting workflow for applications I do not own?▼

You can only use this pentesting workflow for applications you own or have written authorization to test. Hard guardrails prevent unsafe testing by requiring explicit engagement authorization and a strictly defined scope before any active reconnaissance or exploitation.