web-pentest Skill
Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own o Published by NousResearch in hermes-agent.
What is web-pentest Skill?
Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own o Published by NousResearch in hermes-agent. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Testing
- Security review
- Data analysis
- Writing
- Testing use cases
Technical details
- Install or run with Copy skill directory
When to use web-pentest Skill
- Use it for testing.
- Use it for security review.
- Use it for data analysis.
- Use it for writing.
Built with
Editorial notes
Source
- Creator: NousResearch
- Repository: NousResearch/hermes-agent
- Skill file: optional-skills/security/web-pentest/SKILL.md
What it does
Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own o
Skill instructions
Web Application Penetration Testing A phased pentesting workflow for running web applications. Adapted from Shannon's pipeline (Keygraph, AGPL — concepts only, no code borrowed). Built around three rules: 1. No exploit, no report — every finding requires reproducible evidence. 2. Bounded scope — every active request goes against a target the operator pre-declared. Off-scope hosts are refused. 3. Bypass exhaustion before false-positive dismissal — a "blocked" payload is not a clean bill of health until you've tried the bypass set. --- ⚠️ Hard Guardrails — Read Before Every Engagement Violating any of these invalidates the engagement and may be illegal. 1. Authorization gate. Before the first active scan in a session, you MUST confirm with the user, in writing, that they own or have written authorization to test the target. Record the acknowledgement in engagement/authorization.md (see template). No acknowledgement → no active scanning. Reading public pages with curl is fine; sending pay
Explore related resources
Frequently asked questions
What is web-pentest?
web-pentest is a open-source AI agent skill with Copy skill directory. Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting.
Who is web-pentest best for?
web-pentest is best for reusing agent instructions, scripts, and references, testing workflows, security review workflows, data analysis workflows.
How do I install web-pentest?
Install or run web-pentest using Copy skill directory. Check web-pentest for the latest setup command.
Is web-pentest actively maintained?
web-pentest may need a closer maintenance check before production use.
Auto-fetched from GitHub.