pentest-engagement-methodology
Installation
SKILL.md
Penetration Test Engagement Methodology
Work through a structured, repeatable methodology for authorized penetration tests.
When to Use
- You are planning or executing a penetration test with written authorization
- You need to ensure coverage and consistency across an engagement
- You are preparing deliverables for a client or internal stakeholder
Hard Rules
- Never test without written authorization. Verify the scope statement, rules of engagement (RoE), and emergency contacts before touching anything.
- Stay in scope. Check every IP, domain, and URL against the scope document before testing. If unsure, ask — do not guess.
- No destructive actions unless explicitly authorized: no DoS, no data destruction, no production brute-force lockouts.