pentest-scope-and-roe

Prepare and review Rules of Engagement for security testing activities.

Updated May 28, 2026
One-click install
npx skills add https://github.com/SensLiao/Claude-code-setting --skill pentest-scope-and-roe
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-scope-and-roe
Source: https://github.com/SensLiao/Claude-code-setting/tree/main/skills/pentest-scope-and-roe
Command: npx skills add https://github.com/SensLiao/Claude-code-setting --skill pentest-scope-and-roe

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a governance and planning framework for security testing, ensuring a comprehensive and controlled testing process with predefined Rules of Engagement (ROE).

Core Features & Use Cases

  • Predefined ROE Checklist: Offers a detailed 11-point checklist to ensure all aspects of security testing are covered.
  • Authorization and Governance: Ensures all testing activities are authorized and aligned with governance policies.
  • Use Case: Before executing any security test, the Skill helps to prepare a comprehensive ROE document, ensuring that all necessary checks are in place and documented.

Quick Start

Initiate the pentest-scope-and-roe skill to start the ROE planning process.

Frequently Asked Questions about pentest-scope-and-roe

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a rules of engagement document for security testing?

A rules of engagement (ROE) checklist for penetration testing ensures comprehensive coverage of authorized activities, governance policies, and scope boundaries. It typically includes an 11-point checklist to document all necessary approvals and adherence to standards.

How do I prepare a penetration testing scope and ROE document?

To prepare a penetration testing ROE document, you complete a predefined 11-point checklist requiring manual input for scope definition and authorization. This process ensures all governance policies and testing boundaries are documented before execution.

Does this ROE framework support NIST SP 800-115 and OWASP WSTG compliance?

Yes, the ROE preparation framework ensures adherence to established security testing standards including NIST SP 800-115, OWASP WSTG, and PTES. It aligns authorization and governance policies with these standards to maintain compliance during testing.

When do I need to define rules of engagement for a penetration test?

You need to define rules of engagement before executing any security testing activities. Establishing a comprehensive ROE document beforehand ensures all necessary governance checks, authorizations, and scope limitations are documented and approved.

What are the limitations of using a predefined ROE checklist for security testing?

The main limitation of a predefined ROE checklist is that it requires manual input to complete the authorization and scope definition process. It provides a structured planning framework but cannot automatically enforce governance policies without human intervention.