pentest

Assess security vulnerabilities in web applications, APIs, and infrastructure using PTES methodology.

7|Updated Mar 19, 2026
One-click install
npx skills add https://github.com/camilooscargbaptista/cto-toolkit --skill pentest-camilooscargbaptista
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest
Source: https://github.com/camilooscargbaptista/cto-toolkit/tree/main/pentest
Command: npx skills add https://github.com/camilooscargbaptista/cto-toolkit --skill pentest-camilooscargbaptista

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Helps engineering and security teams systematically discover, assess, and prioritize vulnerabilities in web applications, APIs, and infrastructure so organizations can reduce attack surface and remediate high-risk issues before they are exploited.

Core Features & Use Cases

  • Structured Methodology: Step-by-step PTES-aligned workflow covering reconnaissance, threat modeling, vulnerability assessment, and reporting.
  • Comprehensive Checklists: OWASP Top 10, API-specific checks, infrastructure validations, and business-logic scenarios for repeatable coverage.
  • Actionable Reporting: Severity-rated findings, CVSS/CWE alignment, reproduction steps, evidence capture, and remediation guidance tailored for engineering teams.
  • Use Case: Run a pre-release security assessment of a web application and generate a prioritized report with remediation steps for the engineering and product leadership teams.

Quick Start

Conduct a scoped penetration test of my web application at https://example.com, run the OWASP Top 10 and API checklist, and return a prioritized findings report with remediation steps.

Frequently Asked Questions about pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an OWASP Top 10 vulnerability assessment on my web application?

To run an OWASP Top 10 vulnerability assessment, execute a structured penetration test covering reconnaissance, threat modeling, and vulnerability identification to produce a prioritized findings report with remediation steps.

What is the best way to perform threat modeling and security testing for APIs?

The best way to perform threat modeling for APIs is using a PTES-aligned methodology that applies API-specific checklists and infrastructure validations to assess vulnerabilities and generate evidence-backed security reports.

Can I use a penetration test methodology to check cloud services and internal networks?

Yes, this penetration test methodology supports security testing for web apps, APIs, cloud services, and internal networks by applying comprehensive checklists and business-logic scenarios to identify security vulnerabilities.

How do I generate a security reporting document with CVSS and CWE alignment?

To generate security reporting documents, the methodology outputs severity-rated findings aligned with CVSS and CWE standards, including detailed reproduction steps, evidence capture, and tailored remediation guidance for engineering teams.

Does penetration testing enforce authorization and ethical testing constraints?

Yes, the penetration testing process enforces authorization and ethical testing constraints to ensure scoped security assessments remain compliant while discovering and prioritizing vulnerabilities in targeted infrastructure.