scope-grill

Build a structured penetration testing engagement brief with scope and rules of engagement.

30|6|Updated May 13, 2026
One-click install
npx skills add https://github.com/Rifteo/skills --skill scope-grill
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: scope-grill
Source: https://github.com/Rifteo/skills/tree/main/scope-grill
Command: npx skills add https://github.com/Rifteo/skills --skill scope-grill

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Prevents unauthorized testing by ensuring proper pentest scope is defined and documented before any testing begins, reducing legal risk and improving the quality of the engagement.

Core Features & Use Cases

  • Engagement Briefing: Asks questions to capture target, scope, rules of engagement, auth, and deliverables into a structured brief.
  • Prompt Response: Triggered when the user starts a pentest, describes a target without scope/authorization, or wants to structure an engagement.
  • Legal Risk Mitigation: Assists in ensuring compliance with legal requirements related to testing authorization and scope.

Quick Start

Start a pentest on 'acmecorp.com' and ensure proper authorization by using the 'scope-grill' skill.

Frequently Asked Questions about scope-grill

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I define penetration testing scope before starting an engagement?

A penetration testing engagement brief is a structured document capturing target scope, rules of engagement, and authorization details. It is needed to ensure legal compliance and prevent unauthorized testing before any security auditing begins.

How do I structure a penetration testing engagement brief to ensure legal compliance?

To structure a penetration testing engagement brief for legal compliance, you must capture the target, scope, rules of engagement, authorization, and deliverables. This structured approach mitigates legal risk by ensuring proper authorization is documented.

What should be included in rules of engagement for security auditing?

Rules of engagement for security auditing should include the defined target scope, authorization parameters, testing boundaries, and required deliverables. Documenting these details ensures effective testing strategies and legal compliance during the penetration test.

Can I start a penetration test if I have a target but no documented authorization?

You should not start a penetration test without documented authorization. Defining the scope and capturing authorization details into an engagement brief first prevents unauthorized testing, reduces legal risk, and ensures compliance with legal requirements.

What are the limitations of relying on a penetration testing engagement brief?

A penetration testing engagement brief does not execute the actual security testing or vulnerability scanning itself. Its limitation is strictly scope definition and legal risk mitigation; it only builds the structured foundation for the testing strategy.

Related Skills