pentest-scope

Define penetration testing engagement scope with targets, objectives, and authorization.

19|3|Updated Feb 28, 2026
One-click install
npx skills add https://github.com/qa-aman/claude-skills --skill pentest-scope
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-scope
Source: https://github.com/qa-aman/claude-skills/tree/main/skills/by-role/security/pentest-scope
Command: npx skills add https://github.com/qa-aman/claude-skills --skill pentest-scope

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Write a penetration testing engagement boundary document to ensure authorized, scoped, and compliant testing without ambiguity.

Core Features & Use Cases

  • Defines in-scope targets, out-of-scope targets, and testing window to prevent scope creep and legal risk.
  • Documents objectives, success criteria, and testing methods to align client and tester expectations.
  • Provides a reusable template for engagements across web apps, networks, and red team exercises.

Quick Start

Provide engagement details such as organization, assets, testing window, and authorization to generate the scoped pentest document.

Frequently Asked Questions about pentest-scope

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a penetration testing scope document used for?

A penetration testing scope document defines testing boundaries, objectives, and authorization to ensure compliant security testing. It specifies in-scope targets, permitted techniques, and out-of-scope restrictions to prevent scope creep and legal risk during the engagement.

How do I define rules of engagement for a red team exercise?

Defining rules of engagement for a red team exercise involves documenting testing boundaries, permitted techniques, and escalation plans. You must specify in-scope assets, test accounts, time windows, and out-of-scope systems to align client and tester expectations while ensuring legal compliance.

How do I prevent scope creep during a security testing engagement?

To prevent scope creep during a security testing engagement, generate a documented boundary specifying in-scope targets, out-of-scope systems, and a strict testing window. Enforcing these restrictions and objectives ensures actionable findings without ambiguity or unauthorized testing.

Does this pentest scope template work for both web apps and network testing?

Yes, the pentest scope template works for web apps, networks, and red team exercises. It provides a reusable engagement management format that documents objectives, success criteria, and testing methods across different security testing scenarios.

What details do I need to provide to generate a pentest scope document?

To generate a pentest scope document, you need to provide the organization name, target assets, testing window, and authorization details. These inputs allow the system to define boundaries, apply permitted techniques, and list restrictions for the security testing engagement.

Why do I need an escalation plan in my penetration testing rules of engagement?

You need an escalation plan in your penetration testing rules of engagement to ensure legal compliance and manage critical findings safely. It establishes a documented boundary and communication protocol within the testing window to handle incidents during security testing.