Pentest Checklist

Plan, execute, and track penetration testing engagements with structured checklists.

4.5k|458|Updated Jun 21, 2025
One-click install
npx skills add https://github.com/zebbern/claude-code-guide --skill pentest-checklist
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Pentest Checklist
Source: https://github.com/zebbern/claude-code-guide/tree/main/skills/pentest-checklist
Command: npx skills add https://github.com/zebbern/claude-code-guide --skill pentest-checklist

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Pentest Checklist provides a structured, repeatable process to plan, execute, and follow up on penetration testing engagements, helping security teams avoid scope creep, misconfigurations, and overlooked remediation.

Core Features & Use Cases

  • Structured planning: defines objectives, scope, prerequisites, and stakeholder alignment.
  • Stepwise execution: guides environment preparation, testing phases, evidence collection, and validation.
  • Remediation & reporting templates: includes templates for risk ratings, action plans, and retesting guidance.

Quick Start

Begin a pentest project by creating a project brief, obtaining authorization, and running the checklist across Phase 1 (Scope) and Phase 2 (Environment) to ensure readiness.

Frequently Asked Questions about Pentest Checklist

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a penetration testing engagement to avoid scope creep?

To plan a penetration testing engagement without scope creep, you need a structured checklist that defines objectives, scope boundaries, prerequisites, and stakeholder alignment before execution begins.

What steps are required to prepare the environment for a pentest?

Environment preparation for a pentest requires completing Phase 2 readiness steps, including configuring testing environments, validating prerequisites, and ensuring monitoring and evidence collection mechanisms are active.

Can I use this checklist for internal and web application penetration tests?

Yes, this checklist applies to security teams conducting external, internal, web, or hybrid penetration tests across defined scopes, timelines, and compliance requirements.

How do I track remediation and validate vulnerabilities after a penetration test?

Tracking remediation after a penetration test involves using structured templates for risk ratings, action plans, and retesting guidance to ensure vulnerabilities are validated and documented.

What should be included in penetration testing documentation and reporting?

Penetration testing documentation should include project briefs, authorization records, testing checklists, evidence collection, risk ratings, and remediation action plans to ensure comprehensive compliance tracking.