web-pentest Skill
Authorized web pentest: recon, proof-based exploits, report. Published by NousResearch in hermes-agent.
Decision snapshot
Is this a fit?
Testing, Writing, Includes SKILL.md, Reusable instructions
Compatibility not yet detected.
Permission behavior not yet detected.
Copy skill directory
30 days ago · MIT license
No specific cautions were detected. Review the source and requested permissions before installing.
What is web-pentest Skill?
Authorized web pentest: recon, proof-based exploits, report. Published by NousResearch in hermes-agent. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Testing
- Writing
- Testing use cases
- Writing use cases
Declared skill metadata
- Declared author: Teknium (teknium1), Hermes Agent
- Declared license: MIT
- Source file: optional-skills/security/web-pentest/SKILL.md
These fields retain source and confidence evidence from the indexed SKILL.md.
Compatibility and setup
- Install or run with Copy skill directory
When to use web-pentest Skill
- Use it for testing.
- Use it for writing.
Built with
Editorial notes
Source
- Creator: NousResearch
- Repository: NousResearch/hermes-agent
- Skill file: optional-skills/security/web-pentest/SKILL.md
What it does
Authorized web pentest: recon, proof-based exploits, report.
Skill instructions
Web Application Penetration Testing A phased pentesting workflow for running web applications. Adapted from Shannon's pipeline (Keygraph, AGPL — concepts only, no code borrowed). Built around three rules: 1. No exploit, no report — every finding requires reproducible evidence. 2. Bounded scope — every active request goes against a target the operator pre-declared. Off-scope hosts are refused. 3. Bypass exhaustion before false-positive dismissal — a "blocked" payload is not a clean bill of health until you've tried the bypass set. --- ⚠️ Hard Guardrails — Read Before Every Engagement Violating any of these invalidates the engagement and may be illegal. 1. Authorization gate. Before the first active scan in a session, you MUST confirm with the user, in writing, that they own or have written authorization to test the target. Record the acknowledgement in engagement/authorization.md (see template). No acknowledgement → no active scanning. Reading public pages with curl is fine; sending pay
Verified compatibility and discovery
Frequently asked questions
What is web-pentest?
web-pentest is a open-source AI agent skill with Copy skill directory. Authorized web pentest: recon, proof-based exploits, report.
Who is web-pentest best for?
web-pentest is best for reusing agent instructions, scripts, and references, testing workflows, writing workflows.
How do I install web-pentest?
Install or run web-pentest using Copy skill directory. Check web-pentest for the latest setup command.
Is web-pentest actively maintained?
web-pentest may need a closer maintenance check before production use.
Project health auto-fetched from the source repository.
Maintain this resource?
Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.