pentestcompanion-workspace

Centralize penetration testing engagements and generate client-ready reports.

11|1|Updated May 16, 2026
One-click install
npx skills add https://github.com/Aradotso/security-skills --skill pentestcompanion-workspace
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pentestcompanion-workspace
Source: https://github.com/Aradotso/security-skills/tree/main/skills/pentestcompanion-workspace
Command: npx skills add https://github.com/Aradotso/security-skills --skill pentestcompanion-workspace

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Penetration testing teams waste time stitching together engagement tracking, tool execution, finding management, and reporting across separate spreadsheets and consoles.

Core Features & Use Cases

  • Engagement & Target Tracking: Organize clients, scopes, targets, ports, credentials, timelines, and PTES-style workflow stages in one place.
  • Finding Management with Evidence: Create and auto-import findings with severity and CVSS v3.1 scoring, upload evidence, and organize remediation and references.
  • Integrated Tooling & Automation: Run multi-tool scan workflows (e.g., nmap/gobuster/nikto/sqlmap) with live output streaming, scheduled recurring scans, and webhook notifications for new critical items.
  • Reporting for Clients: Generate branded DOCX/PDF reports including executive summaries and technical findings directly from engagement data.

Quick Start

Install Pentest Companion from its Docker instructions, then open it at http://localhost:5000 to create an engagement and run your first scan.

Frequently Asked Questions about pentestcompanion-workspace

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I centralize penetration testing engagement tracking and reporting in one workspace?

Centralize penetration testing by using a self-hosted workspace that organizes clients, scopes, targets, and PTES workflow stages while converting scattered scan outputs into structured findings and client-ready DOCX or PDF reports.

Can I auto-import vulnerability findings and apply CVSS scoring from scan outputs?

Yes, you can auto-import vulnerability findings from multi-tool scan workflows, apply CVSS v3.1 severity scoring, upload evidence, and organize remediation references directly within the engagement management interface.

How do I schedule recurring web scans and get notified of new critical vulnerabilities?

Schedule recurring web scans by configuring multi-tool execution workflows like nmap and nikto, then enable webhook notifications to receive automated alerts when new critical vulnerability findings are discovered.

What is the best way to generate branded pentest reports with executive summaries from engagement data?

Generate branded pentest reports by using automated report generation endpoints that compile engagement data, executive summaries, and technical findings directly into client-ready DOCX and PDF formats.

Do I need a self-hosted server to run multi-tool scan workflows and manage pentest findings?

Yes, you need a running self-hosted Pentest Companion server with engagement and target management capabilities, tool execution with auto-import parsing, and local infrastructure backing the report generation endpoints.

Does this pentest management workspace support live output streaming from tools like sqlmap and gobuster?

Yes, the workspace supports running integrated multi-tool scan workflows including sqlmap and gobuster with live output streaming, scheduled recurring scans, and automated webhook notifications for critical findings.