penetration-assessment

Run authorized penetration tests using a six-phase workflow and report templates.

650|44|Updated Mar 4, 2026
One-click install
npx skills add https://github.com/Superagentsys/novalclaw --skill penetration-assessment
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: penetration-assessment
Source: https://github.com/Superagentsys/novalclaw/tree/main/skills/penetration-assessment
Command: npx skills add https://github.com/Superagentsys/novalclaw --skill penetration-assessment

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Streamlines authorized security assessments by providing a repeatable penetration-testing workflow and templates.

Core Features & Use Cases

  • Six-phase workflow aligned with predefined phases for scope, reconnaissance, threat modeling, vulnerability verification, privilege escalation within allowed boundaries, and reporting.
  • Includes structured templates for reports and PoC guidance to ensure auditability and traceability.
  • Use Case: Security teams performing web app, API, or infrastructure tests within an approved scope can generate consistent deliverables and remediation guidance.

Quick Start

Initiate an authorized penetration assessment using the six-phase workflow and templates to generate a structured report.

Frequently Asked Questions about penetration-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a phase-driven penetration testing workflow?

A phase-driven penetration testing workflow structures authorized security assessments into sequential stages: scope definition, reconnaissance, threat modeling, vulnerability verification, privilege escalation, and reporting, ensuring documented artifacts and auditability.

How do I generate structured reports for authorized security audits?

You generate structured reports for authorized security audits by applying standardized reporting templates to phase-by-phase testing outputs, ensuring traceability, auditability, and consistent remediation guidance for web app, API, or infrastructure tests.

Can I use this penetration testing workflow for API and web app security assessments?

Yes, the penetration testing workflow is applicable to security teams conducting web app, API, and infrastructure tests, provided the testing occurs within a written scope and formal authorization boundaries.

Does authorized penetration testing require predefined scope and threat modeling?

Yes, authorized penetration testing requires a predefined scope and threat modeling to establish formal authorization boundaries, guide vulnerability verification, and ensure that privilege escalation remains within allowed limits.

What is the best way to standardize deliverables across multiple penetration tests?

Standardize deliverables by using a repeatable six-phase workflow with structured templates for reports and proof-of-concept guidance, generating consistent artifacts and remediation guidance across multiple security assessments.