Penetration Testing Plugin¶
A professional reference for authorized offensive security work, written for in-house security teams, consultancies, and bug-bounty participants operating inside a published scope — and the people who hire and manage them. It is a methodology, process, and professional-practice reference: the parts practitioners actually get wrong — authorization, scoping, method, evidence, and communication — not exploitation recipes, working exploit code, or defensive-evasion techniques. Documented, informed authorization for a defined scope and window is the prerequisite for everything in it.
One reference, split into 4 skills along its section groups so a task loads only the part it needs. Section numbers (§N) are shared across the set and cross-references into a sibling skill are written as §N → skill. Reference, not tutorial: sections are independent, every claim is tagged by how durable it is (settled practice vs. versioned specifics vs. genuinely contested questions), and a currency snapshot (verified August 2026) flags what goes stale first.
Skills¶
- pentest-authorization-scoping-and-methodology — Authorization and Law, Engagement Types and Scoping, and Methodology (§0–§3): Routing; Authorization and Law; Engagement Types and Scoping; Methodology.
- pentest-technical-domains — Reconnaissance and Testing Across Web, Network, Active Directory, Cloud, and Other Domains (§4–§9): Reconnaissance and Attack Surface; Web Application Testing; Network and Infrastructure; Active Directory and Identity; Cloud; Other Domains.
- pentest-red-team-ai-and-reporting — Social Engineering, Red/Purple Teaming, Post-Exploitation, AI Systems, and Reporting (§10–§13): Social Engineering and Physical; Red Teaming, Purple Teaming, Post-Exploitation; AI Systems; Reporting.
- pentest-disclosure-career-and-reference — Disclosure and Career, Anti-Patterns, Contested Questions, Currency, and Canon (§14–§20): Disclosure, Career, and Certification; Anti-Patterns; Contested Questions; Currency Snapshot; The Canon; Quick Reference; Sources and Method.
Skills in this plugin¶
- pentest-authorization-scoping-and-methodology
- pentest-disclosure-career-and-reference
- pentest-red-team-ai-and-reporting
- pentest-technical-domains