Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Provide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities.
.claude/skills/sickn33-pentest-checklist/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-08 | ✗→✓ | ▲ Improved | 118% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 102% | 0% |
| case-14 | ✗→✓ | ▲ Improved | 71% | 0% |
| case-17 | ✗→✓ | ▲ Improved | 70% | 0% |
| case-06 | ✓→✗ | ▼ Worse | 135% | 0% |
> ⚠️ AUTHORIZED USE ONLY > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited.
> Mandatory confirmation gate > Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target: > 1. Ask the user to state the exact target URL, IP, account, or resource. > 2. Ask the user to confirm written authorization and the permitted scope. > 3. Show the exact command(s) and explain their expected effect. > 4. Wait for explicit confirmation in the current conversation. > > Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
> AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
Provide a comprehensive checklist for planning, executing, and following up on penetration tests. Ensure thorough preparation, proper scoping, and effective remediation of discovered vulnerabilities.
Reference Questions:
| Type | Purpose | Scope | |------|---------|-------| | External Pentest | Assess external attack surface | Public-facing systems | | Internal Pentest | Assess insider threat risk | Internal network | | Web Application | Find application vulnerabilities | Specific applications | | Social Engineering | Test human security | Employees, processes | | Red Team | Full adversary simulation | Entire organization |
| Factor | Consideration | |--------|---------------| | Asset Value | Higher value = higher investment | | Complexity | More systems = more time | | Depth Required | Thorough testing costs more | | Reputation Value | Brand-name firms cost more |
Budget Reality Check:
Environment Options:
Production - Realistic but risky
Staging - Safer but may differ from production
Clone - Ideal but resource-intensiveCommon Pre-Scan Tools:
bash# Network vulnerability scan nmap -sV --script vuln TARGET # Web vulnerability scan nikto -h http://TARGET
Cloud Provider Policies:
Evaluation Criteria:
| Factor | Questions to Ask | |--------|------------------| | Experience | Years in field, similar projects | | Methodology | OWASP, PTES, custom approach | | Reporting | Sample reports, detail level | | Communication | Availability, update frequency |
Testing Approaches:
| Type | Access Level | Simulates | |------|-------------|-----------| | Black Box | No information | External attacker | | Gray Box | Partial access | Insider with limited access | | White Box | Full access | Insider/detailed audit |
Report Should Include:
Monitoring Tools:
bash# Check security logs tail -f /var/log/auth.log tail -f /var/log/apache2/access.log # Monitor network tcpdump -i eth0 -w capture.pcap
Key Logs to Monitor:
Testing Frequency Factors:
□ Scope defined and documented
□ Authorization obtained
□ Environment prepared
□ Hosting provider notified
□ Team briefed
□ Monitoring enabled
□ Backups verified□ Report received and reviewed
□ Findings prioritized
□ Remediation assigned
□ Fixes implemented
□ Verification testing scheduled
□ Environment cleaned up
□ Next test scheduledmarkdown**Target:** Corporate web application (app.company.com) **Type:** Gray box web application pentest **Duration:** 5 business days **Excluded:** DoS testing, production database access **Access:** Standard user account provided
bash# Enable comprehensive logging sudo systemctl restart rsyslog sudo systemctl restart auditd # Start packet capture tcpdump -i eth0 -w /tmp/pentest_capture.pcap &
| Issue | Solution | |-------|----------| | Scope creep | Document and require change approval | | Testing impacts production | Schedule off-hours, use staging | | Findings disputed | Provide detailed evidence, retest | | Remediation delayed | Prioritize by risk, set deadlines | | Budget exceeded | Define clear scope, fixed-price contracts |
This skill is applicable to execute the workflow or actions described in the overview.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-03 | pass→pass | 11,973 | 12,889 | +8% | 1 | 1 | 0% | 2,300 | 4,046 | +76% | 0 | 0 | — |
case-01 | fail→fail | 17,035 | 13,553 | -20% | 1 | 1 | 0% | 3,036 | 4,851 | +60% | 0 | 0 | — |
case-02 | pass→pass | 10,318 | 5,805 | -44% | 1 | 1 | 0% | 1,662 | 3,373 | +103% | 0 | 0 | — |
case-04 | pass→pass | 10,143 | 7,183 | -29% | 1 | 1 | 0% | 1,776 | 3,617 | +104% | 0 | 0 | — |
case-05 | pass→pass | 10,433 | 4,920 | -53% | 1 | 1 | 0% | 2,018 | 3,350 | +66% | 0 | 0 | — |
case-06 | pass→fail | 7,774 | 5,198 | -33% | 1 | 1 | 0% | 1,408 | 3,312 | +135% | 0 | 0 | — |
case-07 | pass→pass | 15,730 | 9,987 | -37% | 1 | 1 | 0% | 2,461 | 4,033 | +64% | 0 | 0 | — |
case-08 | fail→pass | 9,565 | 5,395 | -44% | 1 | 1 | 0% | 1,523 | 3,326 | +118% | 0 | 0 | — |
case-09 | fail→pass | 10,864 | 7,631 | -30% | 1 | 1 | 0% | 1,845 | 3,725 | +102% | 0 | 0 | — |
case-10 | pass→pass | 12,653 | 5,115 | -60% | 1 | 1 | 0% | 2,131 | 3,199 | +50% | 0 | 0 | — |
case-11 | pass→pass | 11,420 | 6,213 | -46% | 1 | 1 | 0% | 1,833 | 3,340 | +82% | 0 | 0 | — |
case-12 | fail→fail | 14,544 | 9,666 | -34% | 1 | 1 | 0% | 2,530 | 3,955 | +56% | 0 | 0 | — |
case-13 | pass→pass | 11,687 | 7,193 | -38% | 1 | 1 | 0% | 1,872 | 3,536 | +89% | 0 | 0 | — |
case-14 | fail→pass | 13,894 | 10,723 | -23% | 1 | 1 | 0% | 2,408 | 4,116 | +71% | 0 | 0 | — |
case-15 | pass→pass | 15,387 | 5,935 | -61% | 1 | 1 | 0% | 2,322 | 3,327 | +43% | 0 | 0 | — |
case-16 | pass→pass | 9,938 | 6,135 | -38% | 1 | 1 | 0% | 1,796 | 3,451 | +92% | 0 | 0 | — |
case-17 | fail→pass | 10,599 | 5,069 | -52% | 1 | 1 | 0% | 2,004 | 3,399 | +70% | 0 | 0 | — |
case-18 | pass→pass | 11,374 | 8,696 | -24% | 1 | 1 | 0% | 1,933 | 3,755 | +94% | 0 | 0 | — |
case-19 | fail→fail | 15,576 | 6,418 | -59% | 1 | 1 | 0% | 2,367 | 3,482 | +47% | 0 | 0 | — |
case-20 | pass→pass | 9,206 | 6,745 | -27% | 1 | 1 | 0% | 1,651 | 3,680 | +123% | 0 | 0 | — |
case-21 | pass→pass | 7,412 | 4,333 | -42% | 1 | 1 | 0% | 1,615 | 3,301 | +104% | 0 | 0 | — |
case-22 | pass→pass | 10,158 | 9,043 | -11% | 1 | 1 | 0% | 2,410 | 4,419 | +83% | 0 | 0 | — |
case-23 | pass→pass | 10,872 | 8,645 | -20% | 1 | 1 | 0% | 2,256 | 4,196 | +86% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +13 percentage points is the difference between those two pass rates over the 23 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.