web-pentest

Automate authorized web-application penetration testing from reconnaissance to reporting.

31|3|Updated May 7, 2026
One-click install
npx skills add https://github.com/markwang2658/hermes-windows-native --skill web-pentest-markwang2658
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web-pentest
Source: https://github.com/markwang2658/hermes-windows-native/tree/main/hermes-agent/optional-skills/security/web-pentest
Command: npx skills add https://github.com/markwang2658/hermes-windows-native --skill web-pentest-markwang2658

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own or have written authorization to test.

Core Features & Use Cases

  • Phased pentesting workflow from engagement setup to final reporting.
  • Enforces strict scope and authorization guardrails to prevent unsafe testing.
  • Generates structured evidence and professional pentest reports.

Quick Start

Initiate a guided pentest against a target URL following the operator prompts and let Hermes orchestrate reconnaissance, exploitation, and reporting with built-in safety checks.

Frequently Asked Questions about web-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is structured web application penetration testing and how does it work?

Structured web application penetration testing automates an authorized workflow from reconnaissance to reporting. It applies a phased methodology covering vulnerability analysis and proof-based exploitation to running web apps, producing formal reports with structured findings.

How do I perform authorized pentesting on a running web app?

To perform authorized pentesting, initiate a guided engagement against a target URL. The workflow orchestrates reconnaissance, exploitation, and reporting with built-in safety checks, requiring explicit authorization and a defined scope before active testing begins.

Does web pentesting require explicit authorization and a defined scope?

Yes, web pentesting requires explicit engagement authorization and a defined scope. Strict guardrails enforce safe handling of sensitive payloads and prevent auxiliary-client leakage during active testing against running applications you own or have written permission to test.

What is the best way to generate a formal pentest report with structured findings?

The best way to generate a formal pentest report is using a phased workflow that enforces proof-based exploitation. It captures structured evidence during vulnerability analysis and compiles it into a professional pentest report at the end of the engagement.

Can I use this pentesting workflow for applications I do not own?

You can only use this pentesting workflow for applications you own or have written authorization to test. Hard guardrails prevent unsafe testing by requiring explicit engagement authorization and a strictly defined scope before any active reconnaissance or exploitation.