Pentest Checklist
This Pentest Checklist generates a comprehensive security audit plan, streamlining penetration testing and ensuring thorough coverage.
Install on your platform
We auto-selected Claude Code based on this skillβs supported platforms.
Run in terminal (recommended)
claude mcp add zebbern-pentest-checklist npx -- -y @trustedskills/zebbern-pentest-checklist
Or manually add to ~/.claude/settings.json
{
"mcpServers": {
"zebbern-pentest-checklist": {
"command": "npx",
"args": [
"-y",
"@trustedskills/zebbern-pentest-checklist"
]
}
}
}Requires Claude Code (claude CLI). Run claude --version to verify your install.
About This Skill
What it does
This skill provides a comprehensive pentesting checklist to guide security assessments. It helps ensure thoroughness and consistency in penetration testing procedures, covering various stages from reconnaissance to reporting. The checklist is designed to be adaptable for different environments and attack surfaces.
When to use it
- When preparing for a penetration test engagement to ensure all necessary steps are considered.
- During a red team exercise to systematically execute attack phases.
- As a training tool for security professionals learning about pentesting methodologies.
- To create a repeatable and auditable process for vulnerability assessments.
Key capabilities
- Provides a structured checklist of penetration testing tasks.
- Covers multiple stages of the pentest lifecycle.
- Offers a framework for consistent assessment practices.
- Adaptable to various environments.
Example prompts
- "Generate a pentesting checklist for a web application."
- "Show me the reconnaissance phase of the pentest checklist."
- βWhat are the post-exploitation steps in the pentest checklist?β
Tips & gotchas
The skill assumes basic familiarity with cybersecurity concepts and terminology. While adaptable, tailoring the checklist to specific environments may require manual adjustments after generation.
Tags
TrustedSkills Verification
Unlike other registries that point to live repositories, TrustedSkills pins every skill to a verified commit hash. This protects you from malicious updates β what you install today is exactly what was reviewed and verified.
Security Audits
| Gen Agent Trust Hub | Pass |
| Socket | Pass |
| Snyk | Pass |
π Community
Passed automated security scans.