Skip to main content

ZeeshanSultan/pentest-agent-vs-llm-benchmark-effectiveness

SkillsMP has collected 23 skills from ZeeshanSultan/pentest-agent-vs-llm-benchmark-effectiveness. Open a skill to review its source and details.

Latest recorded source activity
SkillsMP catalog refreshed
skills collected
23
GitHub stars
6
GitHub forks
0

Skills in this repository

Showing 23 of 23 collected skills.

occupation
Information Security Analysts
description

Bug bounty white-box hunting methodology. Load when the target is an open-source project with a security advisory program, bug bounty, or responsible disclosure policy.

updated
occupation
Information Security Analysts
description

Root pointer for the analyst's vulnerability research playbooks. Load this first at iteration start to see the full catalog of vuln-class and chain-building skills.

updated
occupation
Software Developers
description

Trust boundary mapping and startup sequence audit for developer tools, CLI apps, and plugin systems. Load when the target is a developer tool, CLI, IDE extension, or any application that loads config from the current directory.

updated
occupation
Computer Occupations, All Other
description

CTF benchmark mode — meta-rules for automated benchmark runs. Routing/playbooks live in /skills/exploit/* and /skills/recon/*; this file only documents benchmark-specific conventions.

updated
occupation
Computer Occupations, All Other
description

Red team engagement lifecycle management — initiation, phase transitions, go/no-go gates, deconfliction, emergency procedures, completion.

updated
occupation
Computer Occupations, All Other
description

Mandatory first-turn startup procedure — checks for existing engagements, resume/new selection, workspace initialization.

updated
occupation
Computer Occupations, All Other
description

Final engagement report generation — executive summary, technical report, findings aggregation, attack path narrative, detection gap matrix, remediation roadmap.

updated
occupation
Computer Occupations, All Other
description

Decepticon orchestrator patterns — delegation, state management, adaptive re-planning, context handoff protocols.

updated
occupation
Computer Occupations, All Other
description

Active Directory exploitation — BloodHound analysis, Kerberoasting, AS-REP Roasting, AD CS abuse, DCSync, Golden Ticket, Constrained Delegation.

updated
occupation
Computer Occupations, All Other
description

Exploitation finding documentation — initial access reports, exploit chain documentation, CVSS v4.0 scoring, shell/credential inventory, detection gap analysis.

updated
occupation
Computer Occupations, All Other
description

Web application exploitation — the primary category skill for all web-based attacks. This is a routing skill: read this first to identify the attack type, then load the appropriate specialized sub-skill for detailed procedures. Covers 11 technique areas…

updated
occupation
Computer Occupations, All Other
description

Sliver C2 framework operations — server connection, listener setup, implant generation, BOF/Armory extensions, post-implant operations, HTTP C2 profiles.

updated
occupation
Information Security Analysts
description

Post-exploitation finding documentation — credential access, privilege escalation, lateral movement reports, detection gap analysis, attack path documentation, CVSS v4.0 scoring.

updated
occupation
Information Security Analysts
description

Active target probing — port scanning, service detection, vulnerability scanning, banner grabbing, web directory fuzzing, SSL/TLS analysis.

updated
occupation
Information Security Analysts
description

Cloud infrastructure enumeration — AWS S3 buckets, Azure blob storage, GCP buckets, cloud metadata endpoints, IAM misconfigurations, CDN origin detection.

updated
occupation
Information Security Analysts
description

Open-source intelligence gathering — email harvesting, social media profiling, breach data checking, employee enumeration, GitHub secret scanning, organizational mapping.

updated
occupation
Information Security Analysts
description

Passive intelligence gathering without touching the target — DNS, WHOIS, subdomain enumeration, Certificate Transparency, technology fingerprinting, ASN mapping.

updated
occupation
Information Security Analysts
description

Recon output formatting — report structure, CVSS v4.0 scoring (primary), MITRE ATT&CK mapping, finding prioritization, Markdown output, detection gap tracking, handoff checklists.

updated
occupation
Information Security Analysts
description

Web application enumeration hub — directory/file fuzzing, vhost discovery, API enumeration, CMS scanning, WAF detection, auth surface mapping, cookie audit.

updated
occupation
Information Security Analysts
description

Finding documentation protocol — Markdown template, YAML frontmatter schema, CVSS v4.0 severity guide, confidence levels, naming conventions, post-creation checklist.

updated
occupation
Information Security Analysts
description

When and how to use ask_user_question — structured multiple-choice prompts vs. free-text prose during the engagement interview.

updated
occupation
Information Security Analysts
description

Bug bounty report formatting for HackerOne, Bugcrowd, Immunefi, and GitHub Security Advisories. Load after validate_finding succeeds and the finding needs to be submitted to a bounty program.

updated
occupation
Information Security Analysts
description

Stage 3 triage and verification playbook. Crafts minimal PoCs, runs them with ZFP controls, promotes validated bugs to FINDING nodes with CVSS. Load at verifier-agent startup.

updated
Showing 23 of 23 collected skills.