pentest-web-enumeration

Installation
SKILL.md

Pentest Web Enumeration

Purpose

Own the active web-enumeration phase from scoped targets to a deduplicated application inventory and prioritized foothold hypotheses. Use Nuclei as the primary scanner, but do not substitute scanner output for direct validation.

Boundaries And Handoffs

  • Require explicit authorization and record the target, allowed ports, identities, exclusions, and rate limits before active enumeration.
  • Remain the owner while the blocker is discovering or fingerprinting web surfaces.
  • Hand off to pentest-web-application-logic-mapper when multi-step workflows, authenticated routes, or application state need mapping.
  • Hand off to the matching auth, access-control, input/protocol, XSS, business-logic, OOB, or CVE skill when a concrete vulnerability class becomes the blocker.
  • Hand off to pentest-exploit-execution-payload-control only after a primitive is confirmed.
  • Use pentest-evidence-structuring-report-synthesis for a full client deliverable; produce the phase report here regardless.

Required Inputs

Normalize what is known into:

Installs
6
GitHub Stars
3
First Seen
Aug 14, 2026
pentest-web-enumeration — crtvrffnrt/skills