Pentest Checklist

Automate structured penetration testing plans with scoping and remediation workflows.

Updated Jan 12, 2026
One-click install
npx skills add https://github.com/jcastillotx/vibe-skeleton-app --skill pentest-checklist-jcastillotx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Pentest Checklist
Source: https://github.com/jcastillotx/vibe-skeleton-app/tree/main/setup/skills/pentest-checklist
Command: npx skills add https://github.com/jcastillotx/vibe-skeleton-app --skill pentest-checklist-jcastillotx

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

The Pentest Checklist provides a structured, auditable framework to plan, execute, and follow up on penetration testing engagements, reducing scope creep and ensuring thorough remediation.

Core Features & Use Cases

  • Scope definition, objective setting, and authorization capture for pentests
  • Step-by-step workflows covering environment prep, testing methodologies, monitoring, remediation, and reporting
  • Use Case: A security team plans a web application pentest and uses the checklist to generate a formal scope, test plan, and remediation roadmap.

Quick Start

  • Create a new Pentest project and populate the project identity fields
  • Select the applicable pentest type (external, internal, or web) and define the scope
  • Follow the phased process to prepare, execute, and close the engagement

Frequently Asked Questions about Pentest Checklist

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a penetration test and prevent scope creep during the engagement?

To plan a penetration test and prevent scope creep, define a structured scope, set objectives, and capture authorization upfront. This checklist enforces a phased process covering environment prep, testing methodologies, and reporting to keep engagements auditable and contained.

What is risk-based prioritization in a pentest remediation workflow?

Risk-based prioritization in a pentest remediation workflow ranks discovered vulnerabilities by their potential impact and threat level. This structured checklist enforces prioritized remediation planning, helping security teams address the most critical exposures first after testing concludes.

How do I structure a penetration testing plan for web application, internal, and external scenarios?

Structure a penetration testing plan by selecting the applicable scenario—external, internal, or web application—and defining the scope. This checklist generates a formal test plan, deliverables, and a remediation roadmap tailored to the specific environment being tested.

Do I need prior authorization before executing a penetration test?

Yes, you need prior authorization before executing a penetration test. This checklist requires capturing formal authorization as part of the initial project identity and scope definition phase to ensure the engagement remains compliant and auditable.

What is the best way to document deliverables and remediation steps after a penetration test?

The best way to document deliverables and remediation steps is to follow a structured closing phase. This checklist enforces defined deliverables and a risk-prioritized remediation roadmap, ensuring thorough follow-up and clear reporting after the testing concludes.