pentest

Automate security assessments of AWS and Azure cloud environments.

145|28|Updated Apr 4, 2026
One-click install
npx skills add https://github.com/transilienceai/shasta --skill pentest-transilienceai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentest
Source: https://github.com/transilienceai/shasta/tree/main/.claude/skills/pentest
Command: npx skills add https://github.com/transilienceai/shasta --skill pentest-transilienceai

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Automates a security assessment of cloud environments to identify internet-exposed resources, attack paths, and network vulnerabilities.

Core Features & Use Cases

  • Automated discovery of internet-exposed resources and misconfigurations in AWS and Azure environments.
  • Attack-path analysis and risk scoring across multi-account setups for proactive mitigation.
  • Audit-ready reporting with remediation guidance and evidence collection for compliance requirements.

Quick Start

Run the pentest workflow using your configured Python command to generate a findings report.

Frequently Asked Questions about pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate a security assessment of AWS and Azure cloud environments?

The pentest workflow automates cloud security assessment by scanning AWS and Azure environments to identify internet-exposed resources, attack paths, and network vulnerabilities, producing a JSON findings report for audit readiness.

What is attack path analysis and how does it score exposure risk in cloud workloads?

Attack path analysis maps potential attacker routes through cloud environments by evaluating exposed assets. The pentest workflow scores exposure risk across multi-account AWS and Azure setups to prioritize proactive mitigation.

Does this pentest workflow require a specific environment configuration to run?

Yes, running the pentest workflow requires a configured Shasta environment with valid credentials to access AWS and Azure workloads, enabling automated asset discovery and remediation-ready findings generation.

Can I generate audit-ready reports with remediation guidance for compliance checks?

Yes, the pentest workflow produces a JSON report containing audit-ready findings with remediation guidance and evidence collection, supporting compliance requirements by documenting exposed resources and network vulnerabilities.

What is the best way to discover internet-exposed resources and misconfigurations in multi-account cloud setups?

The pentest workflow automates discovery of internet-exposed resources and misconfigurations across multi-account AWS and Azure setups, evaluating exposure risk and mapping attack paths for proactive mitigation and audit readiness.