offensive-security
Installation
SKILL.md
Offensive Security
Authorization Boundary
- Confirm scope, authorization, target ownership, allowed techniques, test window, and reporting requirements before active testing guidance.
- Do not provide instructions for unauthorized access, persistence, stealth, evasion, credential theft, destructive actions, or real-world exploitation against third parties.
- Prefer lab-safe proof, vulnerability explanation, detection, and remediation when the request is dual-use.
Assessment Workflow
- Define scope: targets, exclusions, credentials, rate limits, legal constraints, and success criteria.
- Build a test plan aligned to the asset type: web, API, network, cloud, mobile, identity, or source code.
- Collect evidence safely with minimal impact and clear timestamps.
- Validate findings enough to prove risk without expanding access unnecessarily.
- Report business impact, reproduction summary, affected assets, severity rationale, and remediation.