What problem does it solve?
This Skill helps security professionals systematically assess authorized web applications without relying on a fixed vulnerability checklist, while preserving test state, evidence, coverage, and reporting details across multi-stage engagements.
Core Features & Use Cases
- Autonomous threat modeling: Identifies feature-specific threats across data flows, authorization boundaries, state changes, client-controlled inputs, injection surfaces, file operations, and business logic.
- Deep discovery and validation: Reads frontend JavaScript, inventories APIs and pages, builds session and permission matrices, performs cross-role testing, and validates real business impact beyond HTTP status codes.
- Structured audit and reporting: Persists multi-project test state, enforces schema and coverage gates, records evidence and blind spots, and produces complete Markdown reports plus DOCX delivery documents.
- Use Case: Use it during an authorized assessment of a web application to discover endpoints, test role-based access controls and business workflows, verify suspected vulnerabilities, and deliver an evidence-based security report.
Quick Start
Use the pentest-lyan skill to perform an authorized security assessment of the specified web application URL using the available test accounts.