ptest

Automate gated penetration testing workflows across reconnaissance, enumeration, exploitation, and reporting.

Updated Jun 23, 2024
One-click install
npx skills add https://github.com/n4igme/randscript --skill ptest
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: ptest
Source: https://github.com/n4igme/randscript/tree/main/llm/skills/ptest
Command: npx skills add https://github.com/n4igme/randscript --skill ptest

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Structured pentest engagements often suffer from ad-hoc phase transitions, inconsistent evidence, and unrepeatable results. This Skill provides a gated, self-contained workflow to manage reconnaissance, enumeration, exploitation, and reporting with mandatory gates and artifact templates.

Core Features & Use Cases

  • Phase-driven engagement lifecycle from passive recon to final reporting with enforced quality gates.
  • Evidence templates, per-phase checklists, and phase-output scaffolds to ensure auditable, reproducible results.
  • Attack-chain framing and remediation narratives to communicate business impact to stakeholders.

Quick Start

Initialize a new Hermes ptest engagement with default phase gates and an empty scope.

Frequently Asked Questions about ptest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is a gated penetration testing workflow and when do I need it for security engagements?

A gated penetration testing workflow enforces strict phase transitions across reconnaissance, enumeration, exploitation, and reporting. You need this for security engagements requiring auditable evidence collection, phase checklists, and repeatable attack-chain narratives to ensure compliance.

How do I automate evidence collection and phase checklists during a pentest?

You can automate evidence collection by using a structured workflow that applies per-phase checklists and evidence templates. This ensures that phase outputs, artifacts, and time tracking are scaffolded automatically across web, network, and API targets during the penetration test.

Does this gated pentest workflow support web, network, and API targets simultaneously?

Yes, the gated pentest workflow supports web, network, and API targets simultaneously. It manages security testing across these target types by applying uniform phase gates, artifact templates, and attack-chain framing to ensure consistent and auditable results.

What is the best way to structure attack-chain narratives and remediation paths for stakeholders?

The best way to structure attack-chain narratives is through a phase-driven engagement lifecycle that captures business impact and escalation paths. This approach frames remediation narratives and communicates them directly to stakeholders through structured reporting.

Can I track time and artifacts automatically across different pentest phases?

Yes, you can track time and artifacts automatically across penetration testing phases. The workflow enforces time tracking and generates phase-output scaffolds, ensuring that all testing artifacts are collected and auditable throughout the engagement lifecycle.

Why should I use a phase-driven engagement lifecycle instead of ad-hoc security testing?

You should use a phase-driven engagement lifecycle to avoid the inconsistent evidence and unrepeatable results of ad-hoc testing. It enforces strict quality gates and artifact templates, ensuring penetration testing remains structured, auditable, and reproducible.