security-assessment

Coordinate security engagements across planning, recon, testing, and reporting.

6|1|Updated Mar 1, 2026
One-click install
npx skills add https://github.com/narlyseorg/superhackers --skill security-assessment-narlyseorg
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-assessment
Source: https://github.com/narlyseorg/superhackers/tree/main/skills/security-assessment
Command: npx skills add https://github.com/narlyseorg/superhackers --skill security-assessment-narlyseorg

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Orchestrates and coordinates the complete security engagement by aligning multiple specialized skills, tools, and workflows into a single, cohesive process.

Core Features & Use Cases

  • Coordinated planning and scoping: define engagement scope, rules of engagement, and the sequence of sub-skills to invoke.
  • Depth-aware orchestration: propagate engagement depth (Quick, Standard, Deep) across recon, testing, analysis, and reporting.
  • Compliance-aligned risk management: map findings to CVSS, OWASP Top 10, and governance requirements to produce integrated deliverables.

Quick Start

Provide your scope, targets, and depth, then load this orchestrator as the master skill to coordinate the rest of the workflow.

Frequently Asked Questions about security-assessment

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I coordinate a full security assessment across web, API, and infrastructure domains?

You can orchestrate a full security assessment by aligning specialized skills for planning, recon, testing, and reporting into a single cohesive workflow. It coordinates multiple domains while enforcing scope management and structured deliverables.

How do I map security findings to CVSS and OWASP Top 10 compliance requirements?

Mapping security findings to CVSS and OWASP Top 10 compliance requirements is handled during the risk management phase of the assessment. It aligns discovered vulnerabilities with governance requirements to produce integrated, compliance-ready deliverables.

Can I adjust the depth of a penetration test from a quick scan to a deep analysis?

Yes, you can adjust penetration test depth using a depth-aware orchestration model that supports Quick, Standard, and Deep levels. The chosen depth automatically propagates across recon, testing, analysis, and reporting phases.

What is the best way to enforce scope management and rules of engagement during a pentest?

Enforcing scope management and rules of engagement during a pentest is achieved through coordinated planning before testing begins. The orchestrator strictly defines targets and boundaries, ensuring the engagement stays cohesive and compliant.

How do I generate structured deliverables for a security assessment?

Generating structured deliverables for a security assessment is the final phase of the orchestrated workflow. It compiles risk analysis, testing results, and compliance mappings into integrated reports based on the defined engagement scope.

Does this security assessment orchestrator require specific tools to be installed before use?

The security assessment orchestrator does not require external dependencies but performs tool availability checks during execution. It verifies that necessary components are present before invoking specialized sub-skills for recon and testing.