pentest-agent-policy

Validate pentest-agent configuration against risk gates and authorization policies.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill pentest-agent-policy
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-agent-policy
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/pentest-agent-policy
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill pentest-agent-policy

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill provides a structured, read-only safety review of the pentest-agent configuration, ensuring that all security assessments adhere to defined risk gates and authorization policies before any active work begins.

Core Features & Use Cases

  • Policy Posture Review: Validates executor settings, bash-gate configurations, and redaction policies against the current environment.
  • Risk Classification: Maps intended tools and phases to risk levels, ensuring appropriate authorization and approval gates are met.
  • Unlock Guidance: Provides a clear, compliant path for requesting access to disabled-default categories like C2 or wireless testing.

Quick Start

Run the pentest-agent-policy skill to validate the current configuration and ensure all safety gates are correctly set for your engagement.

Frequently Asked Questions about pentest-agent-policy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I validate pentest configuration for risk and compliance before an engagement?

Pre-engagement policy auditing validates executor settings, bash-gate configurations, and redaction policies against risk gates to ensure pentest authorization requirements are met before active work begins.

What is pre-engagement policy auditing for security assessments?

Pre-engagement policy auditing is a read-only safety review that maps intended tools and phases to risk levels, verifying that dangerous categories and execution policies are correctly configured for security workflows.

How do I get authorization approval for disabled-default categories like C2 or wireless testing?

Unlock guidance provides a compliant path for requesting access to disabled-default categories like C2 or wireless testing, ensuring appropriate authorization and approval gates are met before execution.

Does pentest-agent-policy work across different security engagement modes?

Yes, the policy posture review operates across various engagement modes to verify that dangerous categories and execution policies are correctly configured for the current environment.

Can I use this to check if my redaction policies meet security compliance standards?

Yes, the policy posture review validates redaction policies and executor settings against the current environment to ensure security assessments adhere to defined risk gates and authorization policies.

What are the limitations of read-only safety reviews for pentest authorization?

The read-only safety review provides structured risk assessment and policy validation but does not execute active testing, meaning it cannot unlock categories itself or modify the pi-pentest-agent configuration directly.