confirming-pentest-authorization
Installation
SKILL.md
Confirming Pentest Authorization
Overview
Penetration testing is computer access. Without explicit authorization from the owner of the system under test, that access is a crime — Computer Fraud and Abuse Act in the US, Computer Misuse Act in the UK, equivalent laws everywhere else. The line between an authorized pentester and an unauthorized attacker is one signature on one document.
The penetration-tester pack's other skills (TLS analysis, CORS audit, dependency CVE scan, etc.) all assume that line has been crossed correctly. This skill is the first gate the orchestrator routes to. It refuses to declare an engagement authorized until a Rules of Engagement (ROE) attestation file exists, is signed, and contains the fields any real-world legal review will look for.