Favicon of web-pentest

web-pentest Skill

AI Agent SkillPythonOpen source

Authorized web pentest: recon, proof-based exploits, report. Published by NousResearch in hermes-agent.

Decision snapshot

Is this a fit?

Best for

Testing, Writing, Includes SKILL.md, Reusable instructions

Works with

Compatibility not yet detected.

Access

Permission behavior not yet detected.

Setup

Copy skill directory

Project health

29 days ago · MIT license

Considerations

No specific cautions were detected. Review the source and requested permissions before installing.

What is web-pentest Skill?

Authorized web pentest: recon, proof-based exploits, report. Published by NousResearch in hermes-agent. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
100/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Testing
  • Writing
  • Testing use cases
  • Writing use cases

Declared skill metadata

  • Declared author: Teknium (teknium1), Hermes Agent
  • Declared license: MIT
  • Source file: optional-skills/security/web-pentest/SKILL.md

These fields retain source and confidence evidence from the indexed SKILL.md.

Compatibility and setup

Copy skill directory
  • Install or run with Copy skill directory

When to use web-pentest Skill

  • Use it for testing.
  • Use it for writing.

Built with

PythonCopy skill directory

Editorial notes

Source

  • Creator: NousResearch
  • Repository: NousResearch/hermes-agent
  • Skill file: optional-skills/security/web-pentest/SKILL.md

What it does

Authorized web pentest: recon, proof-based exploits, report.

Skill instructions

Web Application Penetration Testing A phased pentesting workflow for running web applications. Adapted from Shannon's pipeline (Keygraph, AGPL — concepts only, no code borrowed). Built around three rules: 1. No exploit, no report — every finding requires reproducible evidence. 2. Bounded scope — every active request goes against a target the operator pre-declared. Off-scope hosts are refused. 3. Bypass exhaustion before false-positive dismissal — a "blocked" payload is not a clean bill of health until you've tried the bypass set. --- ⚠️ Hard Guardrails — Read Before Every Engagement Violating any of these invalidates the engagement and may be illegal. 1. Authorization gate. Before the first active scan in a session, you MUST confirm with the user, in writing, that they own or have written authorization to test the target. Record the acknowledgement in engagement/authorization.md (see template). No acknowledgement → no active scanning. Reading public pages with curl is fine; sending pay

Verified compatibility and discovery

Frequently asked questions

What is web-pentest?

web-pentest is a open-source AI agent skill with Copy skill directory. Authorized web pentest: recon, proof-based exploits, report.

Who is web-pentest best for?

web-pentest is best for reusing agent instructions, scripts, and references, testing workflows, writing workflows.

How do I install web-pentest?

Install or run web-pentest using Copy skill directory. Check web-pentest for the latest setup command.

Is web-pentest actively maintained?

web-pentest may need a closer maintenance check before production use.

Share:

Stars
228,028
Forks
44,793
Last commit
29 days ago
Last verified
Aug 10, 2026
Metadata fetched
Aug 10, 2026
Repository age
1 year
License
MIT

Project health auto-fetched from the source repository.

Maintain this resource?

Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.

Alternatives to web-pentest