What problem does it solve? Security teams and developers need a disciplined, evidence-based way to test web applications they own for vulnerabilities like SQLi, XSS, IDOR, and SSRF without crossing legal or scope boundaries. This Skill enforces written authorization, scope allowlists, and proof-based findings so every reported issue is reproducible. ## Core Features & Use Cases - Phased Engagement Workflow: Runs engagement setup, read-only recon, per-class vulnerability analysis, conditional exploitation, and CVSS-scored reporting. - Hard Guardrails: Requires written operator authorization, enforces a scope.txt allowlist on every request, rate-limits traffic, and blocks destructive payloads without approval. - Proof-Based Findings: Promotes candidates through L1-L4 evidence levels and exhausts documented bypass sets before dismissing anything as a false positive. - Use Case: Point the agent at your staging application, confirm authorization, and receive a professional pentest report with reproducible curl commands, request/response evidence, and remediation guidance for each confirmed finding. ## Quick Start Ask the agent to pentest your staging application URL and reply authorized when it presents the engagement confirmation prompt.