defining-pentest-scope
Installation
SKILL.md
Defining Pentest Scope
Overview
A pentest scope is a list of permission boundaries. Get it wrong and you either (a) miss real exposure by failing to test something the customer expected covered, or (b) probe something you weren't allowed to touch and turn the engagement into a liability event. Both failure modes share a root cause: the scope list was a vague narrative ("test the marketing site and the API") rather than a machine-readable, syntactically-validated, conflict-checked artifact.
This skill takes the in-scope and out-of-scope sections from a ROE and produces three deliverables: