web-pentester

Plan and conduct authorized OWASP Top 10 web and API security testing.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill web-pentester-daemon-blockint-tech
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: web-pentester
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/web-pentester
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill web-pentester-daemon-blockint-tech

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Plans and conducts authorized web application and API security testing to identify weaknesses, verify exploitability, and guide remediation.

Core Features & Use Cases

  • OWASP Top 10 coverage for web apps and APIs with manual proxy-based testing workflows.
  • ROE-aware governance including scoping, authorization checks, evidence collection, and remediation-focused reporting.
  • Use Case: A security team conducts an authorized assessment of a new web surface, gathers findings, and prepares a retest-ready plan.

Quick Start

Instruct the AI to perform an authorized web security assessment for the target app and return a prioritized findings report.

Frequently Asked Questions about web-pentester

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan and execute authorized web application security testing?

Authorized web application security testing requires establishing scope and Rules of Engagement (ROE) first, then conducting manual proxy-based testing to identify OWASP Top 10 weaknesses and verify exploitability. This approach ensures comprehensive coverage while maintaining strict governance for safe, compliant engagements.

Does this approach work for testing REST and GraphQL APIs?

Yes, this approach works for testing REST and GraphQL APIs by applying manual proxy-based testing workflows to identify vulnerabilities. It covers API-specific OWASP Top 10 risks, authentication, session management, and authorization controls to verify exploitability across web surfaces.

What is the best way to ensure ROE compliance during a pentest?

The best way to ensure ROE compliance during a pentest is to enforce authorization checks and scoping rules before testing begins. This governance framework mandates written authorization, continuous evidence collection, and remediation-focused reporting to maintain safe, authorized security assessments.

How do I generate a remediation-focused report after a web security assessment?

To generate a remediation-focused report after a web security assessment, you must collect evidence during manual proxy-based testing and document verified exploitability. The report should include prioritized findings, actionable remediation guidance, and defined retest criteria for subsequent validation.

Can I use manual proxy testing for OWASP Top 10 coverage?

Yes, you can use manual proxy testing for OWASP Top 10 coverage to effectively identify and verify web application vulnerabilities. This testing methodology applies to authentication, session management, authorization controls, and API security testing while gathering necessary exploitability evidence.

What are the limitations of automated web pentesting compared to manual proxy-based testing?

Manual proxy-based testing overcomes automated limitations by verifying actual exploitability of authentication, session management, and authorization controls. It enables ROE-aware governance, precise evidence collection, and accurate remediation guidance that automated scanners cannot reliably provide for complex web applications.