web-pentest

Automate phased web application security testing with scope enforcement and secret redaction.

Updated May 11, 2026
One-click install
npx skills add https://github.com/jason660519/Project-Manager --skill web-pentest-jason660519
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web-pentest
Source: https://github.com/jason660519/Project-Manager/tree/main/hermes-agent/optional-skills/security/web-pentest
Command: npx skills add https://github.com/jason660519/Project-Manager --skill web-pentest-jason660519

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Authorized teams need a structured, auditable approach to web security testing that maximizes findings with safety guardrails and scope enforcement.

Core Features & Use Cases

  • Comprehensive, phased web-pentest workflow with pre-recon, recon, vulnerability analysis, exploitation, and reporting.
  • Evidence-driven methodology that redacts sensitive data and enforces authorization scopes.
  • Use cases include API endpoints, single-page apps, and multi-page sites requiring controlled testing workflows.

Quick Start

Start a new engagement by invoking the web-pentest skill against an authorized target and follow the guided phases.

Frequently Asked Questions about web-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate structured web application penetration testing for an authorized target?

Web penetration testing for single-page apps and APIs follows a phased workflow of pre-recon, recon, vulnerability analysis, exploitation, and reporting. This guided methodology applies evidence-driven checks with strict scope enforcement across bounded engagements.

Can I use this pentest workflow for API endpoints and single-page apps?

Yes, this penetration testing methodology applies to API endpoints, single-page apps, and multi-page sites. It executes controlled testing workflows across these target types while enforcing strict authorization scope boundaries.

How does this vulnerability analysis methodology handle sensitive data during reporting?

The vulnerability analysis methodology redacts sensitive data during the reporting phase. It utilizes an evidence-driven approach that explicitly removes secrets from generated security reports while documenting findings.

What is the best way to ensure penetration testing stays within a bounded engagement scope?

To maintain penetration testing within a bounded engagement, apply a workflow with explicit scope enforcement and safety guardrails. The methodology performs strict authorization checks before executing pre-recon, recon, and exploitation phases.

What are the limitations of using an automated pentest workflow for web security testing?

Automated web security testing workflows are limited to bounded engagements on authorized targets. They require strict scope enforcement and safety guardrails to prevent unauthorized access, relying on pre-recon checks before executing vulnerability analysis.