offensive-security-engineer

Simulate offensive security weaknesses via red-team testing and adversary emulation.

1|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill offensive-security-engineer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: offensive-security-engineer
Source: https://github.com/coreymaypray/sloth-skill-tree/tree/main/plugins/maycrest-secure/skills/offensive-security-engineer
Command: npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill offensive-security-engineer

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Expert offensive security assessments are essential to validate real-world risk by thinking like an attacker, designing adversary emulations, and delivering actionable PoCs and remediation guidance.

Core Features & Use Cases

  • Red-team style assessments across web, mobile, and cloud to identify chained vulnerabilities and validate attacker paths.
  • Adversary emulation and PoC development that demonstrate impact with concrete evidence.
  • Structured engagement design (scope, rules of engagement, reporting) and risk communication tailored for engineering and leadership.

Quick Start

Initiate an authorized red-team engagement and deliver a PoC-based risk report.

Frequently Asked Questions about offensive-security-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I develop a proof-of-concept for a chained attack path across web and cloud environments?

Red-team style adversary emulation simulates real-world attacker behavior to identify chained vulnerabilities and validate exploitable paths across web, mobile, and cloud environments. It requires ethical authorization, documented scope, and rules of engagement to ensure testing aligns with PTES and OWASP guidance.

How do I structure an authorized pentest to validate authentication bypass vulnerabilities?

Authorized pentests validate authentication bypasses by applying structured engagement design with defined scope and rules of engagement. Testing simulates offensive security weaknesses, producing PoC deliverables, risk statements, and remediation guidance aligned with PTES and OWASP standards.

Can I use adversary emulation to validate threat paths in mobile environments?

Adversary emulation supports threat path validation in mobile environments by simulating attacker behaviors and chained vulnerabilities. It generates PoC deliverables and risk communication tailored for engineering and leadership, demonstrating concrete impact under authorized engagement scopes.

What is the best way to document proof-of-concept deliverables for a red-team engagement?

Documenting PoC deliverables for a red-team engagement involves capturing chain-of-events attack-path simulations and risk statements. It requires aligning outputs with PTES and OWASP guidance to provide actionable remediation steps tailored for both engineering and leadership audiences.

Do I need documented scope and ethical authorization before running vulnerability validation testing?

Vulnerability validation testing requires explicit ethical authorization and documented scope before execution. Red-team style assessments must follow rules of engagement and align with PTES and OWASP guidance to ensure PoC development and attack-path simulations remain legally compliant.