Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Ethical security testing methodology - 5-phase pipeline, OWASP checklist, proof levels, structured findings
.claude/skills/pentest-methodology/SKILL.md| Model | Eval pass | Runs |
|---|---|---|
| gemini-3.6-flash | 100% | 6 |
| gemini-3.1-pro-preview | 100% | 1 |
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-18 | ✗→✓ | ▲ Improved | — | — |
| case-01 | ✗→✓ | ▲ Improved | — | — |
| case-03 | ✗→✓ | ▲ Improved | — | — |
| case-09 | ✗→✓ | ▲ Improved | — | — |
| case-12 | ✗→✓ | ▲ Improved | — | — |
Etik guvenlik testi metodolojisi. Shannon framework'unden adapte.
ONEMLI: Bu skill sadece YETKILI guvenlik testleri icin kullanilir. Bug bounty, pentest anlasmasi, veya kendi sisteminiz olmali.
Phase 1: Recon ──▶ Phase 2: Vuln Analysis ──▶ Phase 3: Exploitation
│
Phase 5: Report ◀── Phase 4: Verification ◀────────────┘| Adim | Arac/Yontem | Cikti | |------|-------------|-------| | Subdomain enum | DNS brute, certificate transparency | Subdomain listesi | | Port scan | nmap, masscan | Acik portlar | | Tech stack | Wappalyzer, HTTP headers | Teknoloji listesi | | Directory enum | ffuf, gobuster | Endpoint listesi | | API discovery | Swagger/OpenAPI, sitemap | API endpoint'leri | | Source review | JS dosyalari, comments | Hardcoded info |
OWASP Top 10 kontrol matrisi:
| # | Vuln | Test Yontemi | |---|------|-------------| | A01 | Broken Access Control | IDOR, privilege escalation, path traversal | | A02 | Cryptographic Failures | SSL config, weak ciphers, plaintext storage | | A03 | Injection | SQLi, XSS, command injection, template injection | | A04 | Insecure Design | Business logic flaws, race conditions | | A05 | Security Misconfiguration | Default creds, verbose errors, CORS | | A06 | Vulnerable Components | CVE scan, outdated dependencies | | A07 | Auth Failures | Brute force, session fixation, JWT attacks | | A08 | Data Integrity | Deserialization, CI/CD pipeline attacks | | A09 | Logging Failures | Log injection, insufficient audit trail | | A10 | SSRF | Internal service access, cloud metadata |
Her bulgu icin:
Bulgunun gercek oldugunu dogrula:
Yapilandirilmis bulgu formati (asagida)
| Level | Tanim | Ornek | |-------|-------|-------| | L1 - Theoretical | Potansiyel risk, exploit edilmemis | "Bu endpoint input validate etmiyor" | | L2 - Demonstrated | Bypass/leak gosterildi | "SQL injection ile hata mesaji leak etti" | | L3 - Exploited | Tam exploit, veri erisimi | "Admin panel'e yetkisiz erisim saglandi" | | L4 - Chained | Birden fazla vuln zincirlendi | "XSS + CSRF = Account takeover" |
markdown## [SEVERITY] Finding Title **ID**: FINDING-001 **Severity**: Critical / High / Medium / Low / Informational **Proof Level**: L1 / L2 / L3 / L4 **CVSS**: X.X (hesapla: cvss.org) **CWE**: CWE-XXX ### Description Ne bulundu, tek paragraf. ### Impact Exploit edilirse ne olur? ### Steps to Reproduce 1. [Adim 1] 2. [Adim 2] 3. [Adim 3] ### Proof [Screenshot, HTTP request/response, veya kod] ### Remediation Nasil duzeltilir? ### References - [OWASP link] - [CWE link]
Kullanici input'unun tehlikeli bir fonksiyona ulasip ulasamadigini kontrol et:
Source (Input) ──▶ Transform/Sanitize? ──▶ Sink (Tehlikeli fonksiyon)
req.body.username ──▶ Validation var mi? ──▶ db.query(...)
req.query.redirect ──▶ URL whitelist var mi? ──▶ res.redirect(...)
req.headers.host ──▶ Sanitize var mi? ──▶ fetch(...)Source'lar: req.body, req.query, req.params, req.headers, cookies, file uploads Sink'ler: SQL query, eval(), exec(), redirect(), innerHTML, dangerouslySetInnerHTML
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-21 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-16 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-22 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-01 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-03 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-09 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-07 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +41 percentage points is the difference between those two pass rates over the 22 comparable cases.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.