Install
$ agentstack add skill-hoangnguyen0403-agent-skills-standard-common-pentest-methodology ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Penetration Testing Methodology (PTES-Aligned)
Priority: P0 (CRITICAL)
Always-Apply Rules
- No Exploit = No Report: Every finding requires reproducible Proof-of-Concept. Hypotheses without PoC are discarded.
- No Production Testing: All dynamic probes target local/staging only. Confirm authorization before Phase 1.
- No Single-Platform Bias: Assess backend, frontend, AND mobile surfaces when in-scope.
Workflow
Load alongside /pentest workflow. Provides methodology backbone for all 7 phases.
- Scope → Define test mode (whitebox/greybox/blackbox), platforms, exclusions.
- Recon → Build asset inventory per platform. See [platform-recon](references/platform-recon.md).
- Threat Model → Rank endpoints by risk. See [threat-modeling](references/threat-modeling.md).
- Analyze → Run vulnerability matrix across all domains. Load
common-owasp,common-security-audit,common-dast-tooling. - Exploit → Validate each finding with PoC. See [exploit-techniques](references/exploit-techniques.md).
- Post-Exploit → Assess blast radius, lateral movement, privilege escalation.
- Report → Audit-grade output with CVSS scoring. See [report-template](references/report-template.md) and [compliance-mapping](references/compliance-mapping.md).
Platform Coverage Matrix
| Domain | Backend/API | Frontend/Web | Mobile (iOS/Android) | |---|---|---|---| | Injection | SQLi, CMDi, NoSQLi, LDAPi | Template injection, DOM sinks | Content provider SQLi, Intent injection | | XSS | Response encoding | DOM XSS, innerHTML, framework bypasses | WebView loadUrl, JavaScript bridges | | Auth | JWT, OAuth, Session, MFA | Token storage, session management | Keychain/Keystore, biometric bypass | | AuthZ | BOLA/IDOR, BFLA, Mass Assignment | Client-side role gates | Local permission checks without server | | SSRF | HTTP client + user URL | SSR with user-supplied URL | Custom scheme fetching arbitrary URLs | | Business Logic | Race conditions, workflow bypass | Client-only validation, price tamper | IAP bypass, receipt validation skip | | Crypto | Weak hash, missing TLS | HTTP calls, weak CSP | Missing cert pin, cleartext traffic | | Config | CORS, debug mode, headers | Source maps, debug flags in prod | debuggable=true, ATS exceptions | | Deps/SCA | npm audit, pip-audit, cargo audit | Bundle vuln analysis | pod audit, Gradle dependency scan | | Secrets | Entropy + regex + liveness | Secrets in JS bundles | Keys in BuildConfig/Info.plist | | LLM/AI | Prompt injection, excessive agency | Output to DOM sinks | Agent tools without confirmation |
Continuous & Compliance Execution
- Continuous Testing: Execute Delta scans on PRs or Replay regression PoCs. See [continuous-pentest](references/continuous-pentest.md).
- Compliance Mapping: Map findings to SOC 2, ISO 27001, PCI DSS, or OWASP MASVS. See [compliance-mapping](references/compliance-mapping.md).
Anti-Patterns
- No "scan and dump": Raw tool output not a pentest. Correlate findings across SAST + DAST + manual.
- No severity inflation: Theoretical risk without exploit evidence ≠ confirmed vulnerability.
- No happy-path-only: Test error states, edge cases, race conditions, not just golden flow.
References
- [Platform Reconnaissance](references/platform-recon.md) — Phase 1 recon commands per platform
- [Threat Modeling Guide](references/threat-modeling.md) — Phase 2 attack surface prioritization
- [Exploit Techniques](references/exploit-techniques.md) — Phase 4 PoC construction per vuln class
- [Report Template](references/report-template.md) — Phase 6 audit-grade report format
- [OWASP Mobile Top 10](references/owasp-mobile.md) — Mobile vulnerability detection
- [Compliance Mapping](references/compliance-mapping.md) — SOC 2, ISO 27001, PCI DSS mapping
- [Continuous Pentesting](references/continuous-pentest.md) — CI/CD integration and Delta testing
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: HoangNguyen0403
- Source: HoangNguyen0403/agent-skills-standard
- License: Apache-2.0
- Homepage: https://www.npmjs.com/package/agent-skills-standard
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.