pentest-expert

Guide penetration tests with commands for reconnaissance, enumeration, and vulnerability scanning.

Updated Jan 21, 2026
One-click install
npx skills add https://github.com/mahamaneharouna9-cpu/Apex-invoice-billing-automation --skill pentest-expert
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-expert
Source: https://github.com/mahamaneharouna9-cpu/Apex-invoice-billing-automation/tree/main/.opencode/skill/pentest-expert
Command: npx skills add https://github.com/mahamaneharouna9-cpu/Apex-invoice-billing-automation --skill pentest-expert

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill provides a structured methodology and practical commands for conducting comprehensive penetration tests, ensuring thorough security assessments.

Core Features & Use Cases

  • Methodology Guidance: Follows industry-standard phases like Reconnaissance, Enumeration, and Vulnerability Scanning.
  • Command Execution: Offers ready-to-use bash commands for various security tools (nmap, gobuster, nuclei, sqlmap, etc.).
  • Severity Assessment: Includes a clear framework for rating vulnerabilities based on CVSS scores.
  • Reporting Structure: Outlines a standard report format for clear communication of findings.
  • Use Case: A security analyst can use this Skill to guide their assessment of a web application, ensuring all critical areas are covered from initial scanning to final reporting.

Quick Start

Execute the pentest-expert skill to perform reconnaissance on target.com.

Frequently Asked Questions about pentest-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform penetration testing with tools like nmap and sqlmap?

Penetration testing with nmap and sqlmap involves running structured reconnaissance and vulnerability scanning commands. This Skill provides ready-to-use bash commands for these tools to ensure deterministic task execution during security assessments.

What is the standard methodology for conducting a web application security assessment?

A standard web application security assessment follows phases like Reconnaissance, Web Enumeration, and Vulnerability Scanning. This methodology ensures thorough coverage from initial target scanning to final reporting using industry-standard techniques.

How do I rate vulnerability severity using CVSS scores during ethical hacking?

Rating vulnerability severity using CVSS scores requires mapping discovered flaws to a clear assessment framework. This Skill includes a structured severity rating system to classify vulnerabilities accurately during penetration testing.

Can I use gobuster and nuclei for web enumeration and vulnerability scanning?

Yes, gobuster and nuclei are specifically utilized for web enumeration and vulnerability scanning. This Skill integrates these tools into its methodology to provide comprehensive command execution for security assessments.

What is the best way to structure a penetration testing report after reconnaissance?

The best way to structure a penetration testing report is to follow a standard reporting format that communicates findings clearly. This Skill outlines a structured report format to document vulnerabilities, severity ratings, and assessment results.

Do I need any specific dependencies to run security assessments with this methodology?

No specific dependencies are required to run this security assessment methodology. The Skill operates independently, providing the structured methodology and bash commands for tools like nmap and sqlmap without external library requirements.