pentest

Automate penetration testing across web, CVE, cloud, AI, and internal network assessments.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/hanc00l/nemo-agent --skill pentest-hanc00l
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest
Source: https://github.com/hanc00l/nemo-agent/tree/main/claude-code/.claude/skills/pentest
Command: npx skills add https://github.com/hanc00l/nemo-agent --skill pentest-hanc00l

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a structured, end‑to‑end workflow for authorized security assessments and CTF challenges, eliminating the need to manually coordinate reconnaissance, vulnerability testing, exploitation, and reporting across multiple domains.

Core Features & Use Cases

  • Multi‑zone Coverage: Web application testing, CVE exploitation, cloud security, AI infrastructure attacks, and internal network penetration.
  • Integrated Toolset: Leverages browser automation, terminal sessions, competition API, and a persistent note system to keep findings organized.
  • CTF Automation: Drives the full competition workflow—fetching challenges, managing timeouts, requesting hints, and submitting flags—while maintaining detailed reports.

Quick Start

Use the pentest skill to automatically enumerate a target, test for known vulnerabilities, and generate a concise report linked to the challenge code.

Frequently Asked Questions about pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate penetration testing for web applications and internal networks?

To automate penetration testing for web and internal networks, this Skill coordinates reconnaissance, vulnerability testing, and exploitation across multiple zones, generating a concise report linked to your challenge code.

Can I use this Skill to automate CTF competition workflows and flag submission?

Yes, you can automate CTF workflows by fetching challenges, managing timeouts, requesting hints, and submitting flags. It maintains detailed reports throughout the competition using the integrated competition API.

What tools do I need to perform CVE exploitation and cloud security assessments?

Performing CVE exploitation and cloud security assessments requires access to toolset APIs, browser automation, terminal sessions, and a persistent note management system to execute reconnaissance and keep findings organized.

Does this penetration testing suite support AI infrastructure attacks?

Yes, the penetration testing suite supports AI infrastructure attacks alongside web, CVE, cloud, and internal network assessments, providing a structured end-to-end workflow for authorized security evaluations across these domains.

What is the best way to organize reconnaissance findings during a security audit?

The best way to organize reconnaissance findings during a security audit is using the integrated persistent note system, which links exploitation results and vulnerability testing data directly to your reporting workflow.

Are there limitations when using automated penetration testing for authorized security evaluations?

Automated penetration testing requires authorized access to target systems and external toolset APIs; unauthorized scanning is unsupported, and successful exploitation depends on the target environment's configuration and accessible browser or terminal sessions.