Favicon of web-pentest

web-pentest Skill

AI Agent SkillPythonOpen source

Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own o Published by NousResearch in hermes-agent.

What is web-pentest Skill?

Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own o Published by NousResearch in hermes-agent. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
100/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Testing
  • Security review
  • Data analysis
  • Writing
  • Testing use cases

Technical details

Copy skill directory
  • Install or run with Copy skill directory

When to use web-pentest Skill

  • Use it for testing.
  • Use it for security review.
  • Use it for data analysis.
  • Use it for writing.

Built with

PythonCopy skill directory

Editorial notes

Source

  • Creator: NousResearch
  • Repository: NousResearch/hermes-agent
  • Skill file: optional-skills/security/web-pentest/SKILL.md

What it does

Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting. Adapts Shannon's "No Exploit, No Report" methodology with hard guardrails for scope, authorization, and aux-client leakage. Active testing against running applications you own o

Skill instructions

Web Application Penetration Testing A phased pentesting workflow for running web applications. Adapted from Shannon's pipeline (Keygraph, AGPL — concepts only, no code borrowed). Built around three rules: 1. No exploit, no report — every finding requires reproducible evidence. 2. Bounded scope — every active request goes against a target the operator pre-declared. Off-scope hosts are refused. 3. Bypass exhaustion before false-positive dismissal — a "blocked" payload is not a clean bill of health until you've tried the bypass set. --- ⚠️ Hard Guardrails — Read Before Every Engagement Violating any of these invalidates the engagement and may be illegal. 1. Authorization gate. Before the first active scan in a session, you MUST confirm with the user, in writing, that they own or have written authorization to test the target. Record the acknowledgement in engagement/authorization.md (see template). No acknowledgement → no active scanning. Reading public pages with curl is fine; sending pay

Explore related resources

Frequently asked questions

What is web-pentest?

web-pentest is a open-source AI agent skill with Copy skill directory. Authorized web application penetration testing — reconnaissance, vulnerability analysis, proof-based exploitation, and professional reporting.

Who is web-pentest best for?

web-pentest is best for reusing agent instructions, scripts, and references, testing workflows, security review workflows, data analysis workflows.

How do I install web-pentest?

Install or run web-pentest using Copy skill directory. Check web-pentest for the latest setup command.

Is web-pentest actively maintained?

web-pentest may need a closer maintenance check before production use.

Share:

Stars
214,436
Forks
39,858
Last commit
9 days ago
Repository age
1 year
License
MIT

Auto-fetched from GitHub.

Similar to web-pentest