Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Web Pentester

  • 30 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Run authorized web and API security testing: OWASP classes, REST/GraphQL authZ, Burp/ZAP manual methodology, evidence reporting, and retest validation.

About

Guides authorized web application and API security testing: scoping and rules of engagement, OWASP-oriented testing, REST and GraphQL security, manual proxy-based methodology, and remediation reporting. Used when planning or executing an authorized web pentest.

  • Test OWASP Top 10: injection, broken auth, access control, SSRF, XSS, CSRF
  • Assess REST/GraphQL for BOLA/BFLA, mass assignment, introspection, batching

Web Pentester by the numbers

  • 30 all-time installs (skills.sh)
  • Ranked #1,492 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill web-pentester

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs30
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Run authorized web and API security testing: OWASP classes, REST/GraphQL authZ, Burp/ZAP manual methodology, evidence reporting, and retest validation.

Files

SKILL.mdMarkdownGitHub ↗

Web Pentester

When to Use

  • Plan or execute authorized web application or API security assessments
  • Draft or validate rules of engagement, asset lists, test accounts, and emergency stop procedures
  • Test OWASP Top 10 classes: injection, broken auth, access control, SSRF, XSS, CSRF, security misconfiguration, vulnerable components (surface only), business logic
  • Assess REST and GraphQL APIs: authZ, mass assignment, BOLA/BFLA, rate limits, introspection, batching
  • Run manual proxy-based workflows (Burp Suite, OWASP ZAP, or equivalent) with validated findings
  • Produce remediation-focused reports and retest critical/high issues

When NOT to Use

  • Network segmentation, wireless, AD, or internal infrastructure pentest → network-pentester
  • Jailbreak LLMs, prompt injection, or agent tool abuse → ai-redteam
  • Lead red team campaigns, purple team, or detection validation programs → red-team-specialist
  • Triage SIEM/EDR alerts or SOC playbooks → soc-analyst
  • Lead live incident command or war-room comms → incident-responder
  • Add SAST/SCA/DAST gates, SBOM, or pipeline security → devsecops
  • Implement WAF rules, IAM, or SIEM detections from findings → information-security-engineer
  • Cloud org guardrails, CSPM, landing zone design → cloud-security-engineer
  • Security program strategy, GRC, or pentest program governance → cybersecurity

Related skills

NeedSkill
Network/AD/infra pentest beyond web/APInetwork-pentester
Multi-domain pentest under one ROEpenetration-tester
Red team campaigns, purple team, ATT&CK emulationred-team-specialist
Security program, pentest governance, GRCcybersecurity
Remediate findings (WAF, IdP, SIEM, hardening)information-security-engineer
Cloud control implementation and misconfig fixescloud-security-engineer
CI/CD and supply-chain security in deliverydevsecops
LLM/agent adversarial testingai-redteam
Front-end auth patterns, CSRF, cookies, CORS contextsenior-frontend-software-engineer
Customer-facing pentest reportstech-writer-researcher

Core Workflows

1. Scope and authorization

Do not test without written authorization.

1. Confirm signed SOW/ROE: URLs, APIs, environments, methods, windows, contacts 2. Define out-of-scope (third parties, production PII, DoS unless approved, destructive writes) 3. Agree severity rubric, evidence handling, and data minimization 4. Establish emergency stop and escalation path 5. Prefer staging, dedicated test tenants, or anonymized fixtures

See `references/web_pentester_scope.md` and `references/scoping_and_rules_of_engagement.md`.

2. Application mapping and OWASP testing

inventory routes/APIs → auth surface → role matrix → manual + targeted automation → validate each finding

Map unauthenticated, authenticated, and privileged flows. Prioritize state-changing endpoints and multi-step workflows.

See `references/owasp_web_testing_methodology.md`, `references/api_security_testing.md`, and `references/auth_session_and_access_control.md`.

3. Exploitation discipline (in scope only)

  • Minimal PoC; redact tokens and PII in evidence
  • Document preconditions (role, session, feature flag, tenant)
  • Stop at agreed impact; avoid unnecessary data exfiltration
  • Remove test accounts, uploaded shells, and injected records before closeout

4. Reporting, remediation, and retest

Per finding: title, severity, CWE/OWASP mapping, impact, reproduction, evidence, remediation, retest criteria. Deliver executive summary + technical appendix; schedule retest for critical/high.

See `references/reporting_retest_safe_practices.md`.

When to load references

TopicReference
Role boundariesreferences/web_pentester_scope.md
Authorization and ROEreferences/scoping_and_rules_of_engagement.md
OWASP web methodologyreferences/owasp_web_testing_methodology.md
REST/GraphQL API testingreferences/api_security_testing.md
Auth, session, access controlreferences/auth_session_and_access_control.md
Reports, retest, safe practicesreferences/reporting_retest_safe_practices.md

Related skills

Securityappsecaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.