penetration-tester

Guide authorized penetration testing workflows with ROE-defined scope and reporting.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill penetration-tester-daemon-blockint-tech
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: penetration-tester
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/penetration-tester
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill penetration-tester-daemon-blockint-tech

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Guides authorized penetration testing workflows by outlining how to obtain written authorization, define ROE, coordinate reconnaissance, exploitation, and reporting, ensuring engagements stay within legal and ethical boundaries.

Core Features & Use Cases

  • ROE-driven scoping and authorization: Defines authorization gates, scope worksheets, emergency stop procedures, and engagement boundaries.
  • Reconnaissance, vulnerability identification, and exploitation guidance: Provides structured steps for passive/active discovery, validation, PoC development, and safe post-exploitation practices.
  • Reporting, remediation, and retest planning: Frames evidence collection, remediation actions, and retest criteria aligned with customer ROE.

Quick Start

Authorize a scoped pentest by preparing ROE, assets, and contacts, then initiate the engagement.

Frequently Asked Questions about penetration-tester

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I define rules of engagement for an authorized penetration testing workflow?

Defining rules of engagement for authorized penetration testing requires establishing written authorization, scope worksheets, and emergency stop procedures. The workflow structures these boundaries to ensure assessments across cloud, network, and application layers remain legally compliant.

What is the process for conducting reconnaissance and vulnerability identification during a pentest?

Reconnaissance and vulnerability identification during a pentest involve structured steps for passive and active discovery. The workflow guides validation, proof-of-concept development, and safe post-exploitation practices within the defined scope and authorization boundaries.

How do I plan remediation and retests after completing a penetration test?

Planning remediation and retests after a penetration test involves framing evidence collection and aligning remediation actions with customer rules of engagement. The workflow defines specific retest criteria to verify that identified vulnerabilities have been properly resolved.

Can I use this structured workflow for security assessments across cloud and network layers?

Yes, this structured workflow supports ROE-driven security assessments across cloud, network, and application layers. It applies to the full penetration testing lifecycle including reconnaissance, exploitation, and reporting regardless of the specific infrastructure environment.

Why do I need written authorization before initiating a scoped penetration test?

Written authorization is required before initiating a scoped penetration test to establish legal and ethical boundaries. The workflow defines authorization gates and engagement boundaries to ensure all reconnaissance and exploitation activities remain explicitly permitted.

What are the limitations when applying ROE-driven security assessments to active exploitation?

ROE-driven security assessments limit active exploitation to explicitly defined engagement boundaries and scope worksheets. The workflow enforces emergency stop procedures and restricts post-exploitation practices to prevent activities exceeding written authorization.