External (perimeter / internet-facing) infrastructure penetration testing. Use when the user mentions external pentest, perimeter test, OSINT, subdomain enumeration, ASN, BBOT, Shodan, port scan, banner grab, service enumeration, edge-device CVEs (Ivanti, Citrix, F5, Fortinet, PAN, Sophos, MOVEit, ScreenConnect, Confluence, vCenter), credential stuffing/spraying against public portals, or cloud bucket enumeration.
Installation
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Passive before active. BBOT-led recon for the deep passive pass; mark active items with 🛰 vs ⚠ per CONVENTIONS.md.
Nuclei + targeted version-CVE matching for vulnerability analysis. Track edge-device CVEs current to year of engagement (see tool-mappings/03-infra-external-tools.md).
Each finding maps to stable ID in the relevant phase file. Generate findings via templates/finding-template.md.
On foothold, transition to pentest-infra-internal. Web app at the perimeter → also pentest-web-api.