agency-penetration-tester

Conduct authorized penetration testing across network, web, and cloud infrastructure.

Updated Jul 23, 2026
One-click install
npx skills add https://github.com/rajyeole6/AI-RECRUITER --skill agency-penetration-tester
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: agency-penetration-tester
Source: https://github.com/rajyeole6/AI-RECRUITER/tree/main/.agents/skills/security-penetration-tester
Command: npx skills add https://github.com/rajyeole6/AI-RECRUITER --skill agency-penetration-tester

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires subfinder, amass, dnsx, httpx, naabu, whatweb, gowitness, h8mail, requests, chisel, ligolo-ng, and includes scripts (resource) components.

What problem does it solve?

This skill addresses the need for structured, repeatable, and comprehensive offensive security testing, ensuring that vulnerabilities are identified and validated through a rigorous, professional methodology.

Core Features & Use Cases

  • Attack Surface Mapping: Automates reconnaissance, subdomain enumeration, and port scanning to identify potential entry points.
  • Vulnerability Validation: Provides structured methodologies for testing web application flaws like SQL injection and Active Directory attack chains.
  • Use Case: A security team needs to perform a time-boxed penetration test on a new web application; this skill guides the operator through the reconnaissance, exploitation, and reporting phases to ensure no critical attack vectors are missed.

Quick Start

Use the agency-penetration-tester skill to perform an external reconnaissance scan on the target domain example.com.

Frequently Asked Questions about agency-penetration-tester

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct authorized penetration testing and vulnerability assessments across network and web infrastructure?

Authorized penetration testing across network and web infrastructure is conducted by executing reconnaissance, exploitation, and post-exploitation workflows based on industry-standard frameworks like MITRE ATT&CK and OWASP. This ensures vulnerabilities are rigorously identified and validated through a structured methodology.

What is the best way to automate attack surface mapping and subdomain enumeration for a new web application?

The best way to automate attack surface mapping for a new web application is using specialized security tooling for network discovery and subdomain enumeration. This automates reconnaissance and port scanning to accurately identify potential entry points before deeper exploitation.

Can I use this penetration testing skill to validate web application flaws like SQL injection?

Yes, you can use this penetration testing skill to validate web application flaws like SQL injection. It provides structured methodologies for vulnerability validation, testing web application flaws and Active Directory attack chains to ensure critical vectors are missed.

Do I need specialized security tools like subfinder and amass to perform external reconnaissance scans?

Yes, you need specialized security tools like subfinder and amass to perform external reconnaissance scans. The skill requires dependencies including dnsx, httpx, naabu, and whatweb to properly execute network discovery, vulnerability scanning, and privilege escalation analysis.

Does this vulnerability assessment methodology support red teaming and post-exploitation workflows?

Yes, this vulnerability assessment methodology supports red teaming and post-exploitation workflows. It conducts assessments across network, web, and cloud infrastructure, executing post-exploitation workflows based on industry-standard frameworks to ensure comprehensive offensive security testing.