web-pentest

Identify web application attack surfaces with Hermes-guided recon and phase-based workflows.

Updated May 4, 2026
One-click install
npx skills add https://github.com/Plaidmustache/hermes-nulab --skill web-pentest-plaidmustache
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web-pentest
Source: https://github.com/Plaidmustache/hermes-nulab/tree/main/optional-skills/security/web-pentest
Command: npx skills add https://github.com/Plaidmustache/hermes-nulab --skill web-pentest-plaidmustache

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

Web pentesting requires careful scope and safe procedures to avoid legal issues and data leakage. This skill provides a disciplined framework with guardrails, phase-driven workflow, and evidence capture to conduct web pentests responsibly.

Core Features & Use Cases

  • Phase-driven workflow: Pre-Recon, Recon, Vulnerability Analysis, Exploitation, and Reporting.
  • Guardrails and scope enforcement to prevent unsafe testing.
  • Evidence-first approach with templates and queue structures for findings.

Quick Start

Set up an engagement with the provided templates and begin Phase 1 Recon to start live assessment.

Frequently Asked Questions about web-pentest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a web application pentest without going out of scope?

Web application pentesting requires strict scope enforcement to prevent unauthorized access. This skill applies phase-based guardrails and engagement files to ensure all recon and vulnerability analysis stays within proven authorized boundaries.

What is the best way to structure web pentest findings and evidence?

Structured evidence capture uses a dedicated pipeline with recon.md files and findings queues. This approach documents the attack surface and potential vulnerabilities systematically through provided templates during the reporting phase.

How does phase-driven vulnerability analysis work for web applications?

Phase-driven vulnerability analysis progresses through Pre-Recon, Recon, Vulnerability Analysis, Exploitation, and Reporting. This structured workflow ensures safe procedures by applying hard guardrails at each step to prevent legal issues and data leakage.

Can I use Hermes-guided recon for identifying a web application's attack surface?

Yes, Hermes-guided recon identifies and documents a web application's attack surface. The skill enforces authorization and scope from engagement files to ensure all reconnaissance actions remain safe and compliant.

What do I need to set up before starting a safe web pentest engagement?

You need to set up an engagement using provided templates and define authorization scope. This preparatory phase ensures the pentest begins with hard guardrails active to prevent unauthorized access and data leakage.

When should I not use an automated web pentest workflow?

You should not use automated web pentest workflows without clearly defined engagement scope and authorization files. Bypassing the structured guardrails and evidence pipeline risks unauthorized access and potential legal issues during vulnerability analysis.