web-pentest

Automate authorized web application penetration testing with phase-based workflows and evidence capture.

Updated Jun 19, 2026
One-click install
npx skills add https://github.com/AnandaAnugrahHandyanto/savarez_agent --skill web-pentest-anandaanugrahhandyanto
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web-pentest
Source: https://github.com/AnandaAnugrahHandyanto/savarez_agent/tree/main/optional-skills/security/web-pentest
Command: npx skills add https://github.com/AnandaAnugrahHandyanto/savarez_agent --skill web-pentest-anandaanugrahhandyanto

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires whatweb, nmap, python3, curl, sed, and includes scripts (resource) and references (resource) components.

What problem does it solve?

Automates structured, authorized web application penetration testing with phase-based workflows, guardrails, and standardized evidence collection.

Core Features & Use Cases

  • Phase-driven engagement lifecycle with authorization checks and enforced scope.
  • Guided templates for authorization, scope, evidence capture, and reporting.
  • Reproducible reconnaissance and evidence-backed findings suitable for client engagements.

Quick Start

Initialize an engagement with a defined scope and authorization, then run the Recon phase to map endpoints and technologies.

Frequently Asked Questions about web-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate web application penetration testing while maintaining compliance for authorized targets?

Automate web application penetration testing for authorized targets using phase-based workflows, built-in guardrails, and standardized evidence capture to ensure strict compliance. The structured lifecycle enforces authorization checks and scope before mapping endpoints and collecting findings.

What do I need to set up before starting a guided pentest engagement?

Before starting a guided pentest engagement, you need to define explicit scope and authorization. You also need optional tooling installed, including python3, nmap, whatweb, and curl, to execute reconnaissance and map the target's technologies within legal boundaries.

How does structured web pentest reconnaissance map endpoints and technologies?

Structured web pentest reconnaissance maps endpoints and technologies by running the initial engagement phase using tools like nmap and whatweb. This phase safely maps the target's attack surface and identifies underlying frameworks for evidence-backed findings.

Can I use nmap and whatweb during web application penetration testing?

Yes, you can use nmap and whatweb during web application penetration testing to perform reconnaissance. The Skill integrates these dependencies to map endpoints and identify web technologies within an authorization-bounded scope.

Does penetration testing reporting require manual formatting after evidence capture?

Penetration testing reporting does not require manual formatting after evidence capture, as the workflow uses guided templates to produce a formal report. Evidence-backed findings are collected automatically during the phases to build reproducible client deliverables.

When should I not use automated web security testing?

You should not use automated web security testing when explicit scope and authorization are absent. The enforced guardrails prevent operation outside legal boundaries, meaning the workflow halts without documented authorization for the target.