pentest-toolkit

Automate web application and API security testing with vulnerability detection and reporting.

2|1|Updated Nov 30, 2025
One-click install
npx skills add https://github.com/nibzard/skills-marketplace --skill pentest-toolkit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest-toolkit
Source: https://github.com/nibzard/skills-marketplace/tree/main/skills/pentest-toolkit
Command: npx skills add https://github.com/nibzard/skills-marketplace --skill pentest-toolkit

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) components.

What problem does it solve?

Provides intelligent, agent-empowered security testing capabilities to automate discovery, pattern-based analysis, and targeted testing, reducing manual effort and accelerating security assessments.

Core Features & Use Cases

  • Intelligent discovery tools: Map API structure, data models, and authentication patterns.
  • Pattern libraries & knowledge: Access business logic and data relationship vulnerability patterns.
  • Agent workflow enhancements: Generate context-aware tests and adapt based on results.
  • Reporting: Produce professional security reports and machine-readable JSON/Markdown outputs.

Quick Start

Install and initialize the toolkit, then run with a target URL and mode (quick, comprehensive, or API-focused). Use the provided CLI to list tools and generate reports.

Frequently Asked Questions about pentest-toolkit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate security testing for web applications and APIs?

Automated security testing discovers vulnerabilities and maps API structure through agent-driven penetration testing. This toolkit runs command-line scans across single or multi-target scopes in quick, comprehensive, or API-focused modes, generating machine-readable JSON and executive reports without manual test writing.

Can I use an AI agent to handle penetration testing workflows?

Yes. Agent-driven penetration testing adapts test generation based on discovered patterns and application context. This toolkit applies LLM-powered agents to orchestrate discovery, vulnerability detection, and reporting across web applications and APIs with environment management via uv.

What's the best way to discover API vulnerabilities and data model patterns?

Intelligent discovery tools map API structure, authentication patterns, and data relationships to identify business logic vulnerabilities. Pattern-based analysis surfaces risks across endpoints, then targeted tests validate findings with results exported as JSON, Markdown, or professional reports.

How do I set up and run security tests from the command line?

Install the toolkit, initialize with a target URL, and execute via CLI in your chosen mode—quick for rapid scans, comprehensive for depth, or API-focused for endpoint testing. The uv-backed environment handles dependencies; results output as machine-readable files and executive summaries.

Does this support multi-target security assessments?

Yes. The toolkit orchestrates agent-based penetration testing across multiple targets in a single scope, automating discovery and vulnerability detection across each target, then consolidating results into unified machine-readable outputs and reports.

What output formats does the toolkit generate for reporting?

Security testing produces professional executive reports alongside machine-readable JSON and Markdown outputs, enabling integration into CI/CD pipelines, compliance workflows, and stakeholder communication channels.