What problem does it solve? Web application security testing requires strict authorization controls, disciplined scope enforcement, and reproducible evidence for every finding. This Skill provides a phased penetration testing workflow that prevents off-scope testing, eliminates unverified findings, and produces professional reports with proof-of-concept evidence for each vulnerability. ## Core Features & Use Cases - Authorization-Gated Workflow: Requires written operator confirmation and maintains a machine-readable scope allowlist before any active scanning begins, with fail-closed host checking on every request. - Proof-Based Exploitation: Follows a "No Exploit, No Report" methodology where findings are promoted through levels (identified, partial, confirmed, critical) only with reproducible witness payloads, and false positives require bypass-set exhaustion. - Structured Reporting: Generates CVSS-scored findings with request/response evidence, reproduction steps, and remediation guidance using standardized templates. - Use Case: A developer wants to security-test their staging application before launch. The Skill sets up an engagement directory, records authorization, runs rate-limited recon with nmap and whatweb, analyzes six vulnerability classes (injection, XSS, auth, authz, SSRF, infra), confirms exploitable issues with minimal witness payloads, and produces a professional pentest report. ## Quick Start Ask the agent to pentest your staging application URL and reply "authorized" when prompted to confirm ownership and begin the engagement.