Mmcp.market

pentest-checklist skill

by zebbern·zebbern/claude-code-guide·4.6k stars·MIT

This skill should be used when the user asks to "plan a penetration test", "create a security assessment checklist", "prepare for penetration testing", "define pentest scope", "follow security testing best practices", or needs a structured methodology for penetration testing engagements.

A100/100content scan

Is the pentest-checklist skill safe?

Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.

No findings.

Install the pentest-checklist skill

A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.

git clone --depth 1 https://github.com/zebbern/claude-code-guide.git /tmp/claude-code-guide
mkdir -p ~/.claude/skills
cp -r /tmp/claude-code-guide/skills/pentest-checklist ~/.claude/skills/pentest-checklist
available in every project

In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub

The instructions your agent would load

SKILL.md as published, without the frontmatter. Read it on GitHub

Pentest Checklist

Purpose

Provide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities.

Inputs/Prerequisites

  • Clear business objectives for testing
  • Target environment information
  • Budget and timeline constraints
  • Stakeholder contacts and authorization
  • Legal agreements and scope documents

Outputs/Deliverables

  • Defined pentest scope and objectives
  • Prepared testing environment
  • Security monitoring data
  • Vulnerability findings report
  • Remediation plan and verification

Core Workflow

Phase 1: Scope Definition

Define Objectives

  • [ ] Clarify testing purpose - Determine goals (find vulnerabilities, compliance, customer assurance)
  • [ ] Validate pentest necessity - Ensure penetration test is the right solution
  • [ ] Align outcomes with objectives - Define success criteria

Reference Questions:

  • Why are you doing this pentest?
  • What specific outcomes do you expect?
  • What will you do with the findings?

Know Your Test Types

Enumerate Likely Threats

  • [ ] Identify high-risk areas - Where could damage occur?
  • [ ] Assess data sensitivity - What data could be compromised?
  • [ ] Review legacy systems - Old systems often have vulnerabilities
  • [ ] Map critical assets - Prioritize testing targets

Define Scope

  • [ ] List in-scope systems - IPs, domains, applications
  • [ ] Define out-of-scope items - Systems to avoid
  • [ ] Set testing boundaries - What techniques are allowed?
  • [ ] Document exclusions - Third-party systems, production data

Budget Planning

Budget Reality Check:

  • Cheap pentests often produce poor results
  • Align budget with asset criticality
  • Consider ongoing vs. one-time testing

Phase 2: Environment Preparation

Prepare Test Environment

  • [ ] Production vs. staging decision - Determine where to test
  • [ ] Set testing limits - No DoS on production
  • [ ] Schedule testing window - Minimize business impact
  • [ ] Create test accounts - Provide appropriate access levels

Environment Options:

Production  - Realistic but risky
Staging     - Safer but may differ from production
Clone       - Ideal but resource-intensive

Run Preliminary Scans

  • [ ] Execute vulnerability scanners - Find known issues first
  • [ ] Fix obvious vulnerabilities - Don't waste pentest time
  • [ ] Document existing issues - Share with testers

Common Pre-Scan Tools:

# Network vulnerability scan
nmap -sV --script vuln TARGET

# Web vulnerability scan
nikto -h http://TARGET

Review Security Policy

  • [ ] Verify compliance requirements - GDPR, PCI-DSS, HIPAA
  • [ ] Document data handling rules - Sensitive data procedures
  • [ ] Confirm legal authorization - Get written permission

Notify Hosting Provider

  • [ ] Check provider policies - What testing is allowed?
  • [ ] Submit authorization requests - AWS, Azure, GCP requirements
  • [ ] Document approvals - Keep records

Cloud Provider Policies:

  • AWS: https://aws.amazon.com/security/penetration-testing/
  • Azure: https://docs.microsoft.com/security/pentest
  • GCP: https://cloud.google.com/security/overview

Freeze Developments

  • [ ] Stop deployments during testing - Maintain consistent environment
  • [ ] Document current versions - Record system states
  • [ ] Avoid critical patches - Unless security emergency

Phase 3: Expertise Selection

Find Qualified Pentesters

  • [ ] Seek recommendations - Ask trusted sources
  • [ ] Verify credentials - OSCP, GPEN, CEH, CREST
  • [ ] Check references - Talk to previous clients
  • [ ] Match expertise to scope - Web, network, mobile specialists

Evaluation Criteria:

Define Methodology

  • [ ] Select testing standard - PTES, OWASP, NIST
  • [ ] Determine access level - Black box, gray box, white box
  • [ ] Agree on techniques - Manual vs. automated testing
  • [ ] Set communication schedule - Updates and escalation

Testing Approaches:

Define Report Format

  • [ ] Review sample reports - Ensure quality meets needs
  • [ ] Specify required sections - Executive summary, technical details
  • [ ] Request machine-readable output - CSV, XML for tracking
  • [ ] Agree on risk ratings - CVSS, custom scale

Report Should Include:

  • Executive summary for management
  • Technical findings with evidence
  • Risk ratings and prioritization
  • Remediation recommendations
  • Retesting guidance

Phase 4: Monitoring

Implement Security Monitoring

  • [ ] Deploy IDS/IPS - Intrusion detection systems
  • [ ] Enable logging - Comprehensive audit trails
  • [ ] Configure SIEM - Centralized log analysis
  • [ ] Set up alerting - Real-time notifications

Monitoring Tools:

# Check security logs
tail -f /var/log/auth.log
tail -f /var/log/apache2/access.log

# Monitor network
tcpdump -i eth0 -w capture.pcap

Configure Logging

  • [ ] Centralize logs - Aggregate from all systems
  • [ ] Set retention periods - Keep logs for analysis
  • [ ] Enable detailed logging - Application and system level
  • [ ] Test log collection - Verify all sources working

Key Logs to Monitor:

  • Authentication events
  • Application errors
  • Network connections
  • File access
  • System changes

Monitor Exception Tools

  • [ ] Track error rates - Unusual spikes indicate testing
  • [ ] Brief operations team - Distinguish testing from attacks
  • [ ] Document baseline - Normal vs. pentest activity

More skills from zebbern/claude-code-guide

  • Aacademic-paper-reviewerSimulates academic peer review, evaluating papers across Originality, Methodology, Results, and Writing to provide Major/Minor Revision recommendations with actionable feedback. Triggers when a user asks to \"review my paper,\" \"simulate peer review,\" or \"give my paper a peer review.
  • Aactive-directory-attacksThis skill should be used when the user asks to "attack Active Directory", "exploit AD", "Kerberoasting", "DCSync", "pass-the-hash", "BloodHound enumeration", "Golden Ticket", "Silver Ticket", "AS-REP roasting", "NTLM relay", or needs guidance on Windows domain penetration testing.
  • Capi-fuzzing-bug-bountyThis skill should be used when the user asks to "test API security", "fuzz APIs", "find IDOR vulnerabilities", "test REST API", "test GraphQL", "API penetration testing", "bug bounty API testing", or needs guidance on API security assessment techniques.
  • Aapi-shape-explorerGenerate multiple radically different interface designs for a module using parallel sub-agents. Use when user wants to design an API, explore interface options, compare module shapes, or mentions "design it twice".
  • Aaudit-flowInteractive system flow tracing across CODE, API, AUTH, DATA, NETWORK layers with SQLite persistence and Mermaid export. Use for security audits, compliance documentation, flow tracing, feature ideation, brainstorming, debugging, architecture reviews, or incident post-mortems. Triggers on audit, trace flow, document flow, security review, debug flow, brainstorm, architecture review, post-mortem, incident review.
  • Aauthentication-patternsAuthentication patterns: session vs JWT vs OAuth comparison, provider selection (NextAuth, Clerk, Supabase Auth), security checklist, and common mistakes. Use when implementing auth, reviewing auth flows, or choosing auth providers.
  • Aaws-penetration-testingThis skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.
  • Abroken-authenticationThis skill should be used when the user asks to "test for broken authentication vulnerabilities", "assess session management security", "perform credential stuffing tests", "evaluate password policies", "test for session fixation", or "identify authentication bypass flaws". It provides comprehensive techniques for identifying authentication and session management weaknesses in web applications.
  • Cburp-suite-testingThis skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.
  • AcachingCaching strategies — invalidation, TTL guidelines, cache keys, cache layers, and when not to cache. Use when implementing or reviewing caching logic.
  • Achart-imageGenerate publication-quality PNG chart images from data, supporting line, bar, area, candlestick, pie, and heatmap charts. Triggers when the user asks to visualize data, create a graph, plot a time series, or generate a chart for a report, alert, or dashboard. Runs as a lightweight, headless Node.js process without a browser.
  • Dcloud-penetration-testingThis skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.

All agent skills → · MCP servers