Skip to main content

pentest-toolkit-pro-html

Single-file HTML pentesting toolkit with OWASP WSTG checklists, vulnerability tracking, CVSS scoring, and offline report generation

소스 정보

저장소
reason-machines/security-skills
최근 소스 활동
2026년 6월 7일 22:27
감지된 SKILL.md 언어
영어
스타
12
포크
1

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
pentest-toolkit-pro-html
description
Single-file HTML pentesting toolkit with OWASP WSTG checklists, vulnerability tracking, CVSS scoring, and offline report generation
triggers
["use the pentest toolkit pro html tool","open the pentesting toolkit web interface","work with the offline pentest toolkit","customize the pentest toolkit pro html","integrate vulnerability tracking in pentest toolkit","generate pentest reports with toolkit pro","add custom modules to pentest toolkit","configure OWASP WSTG checklist in toolkit"]
# PenTest Toolkit Pro HTML Skill > Skill by [ara.so](https://ara.so) — Security Skills collection. ## What It Does PenTest Toolkit Pro is a comprehensive, single-file HTML pentesting toolkit designed for security professionals. It runs entirely offline in any web browser without dependencies, providing: - **Rules of Engagement (RoE)** management and legal framework documentation - **OWASP WSTG** (Web Security Testing Guide) interactive checklists - **Vulnerability tracking** with CVSS scoring and classification - **Report generation** with printable output - **Cheat sheets** for infrastructure and web pentesting - **Timeline tracking** for mission progress - **Contract templates** for pentest engagements - **Action plan** and remediation recommendations All data is stored locally in browser localStorage, ensuring complete privacy and offline functionality. ## Installation ### Download and Use ```bash # Clone the repository git clone https://github.com/Cyber-Autopsie/PenTest-Toolkit-Pro.git cd PenTest-Toolkit-Pro # Open the HTML file directly in browser # No build process or dependencies required firefox pentest-toolkit-pro-v6.html # or google-chrome pentest-toolkit-pro-v6.html ``` Alternatively, download the single HTML file from the [releases page](https://github.com/Cyber-Autopsie/PenTest-Toolkit-Pro/releases/latest) and open it directly. ### File Structure ``` PenTest-Toolkit-Pro/ ├── pentest-toolkit-pro-v6.html # Main toolkit (single file) ├── preview.png # Screenshot ├── README.md └── LICENSE ``` ## Key Features and Usage ### Module Navigation The toolkit uses a tabbed interface with these main modules: - **RoE** - Rules of Engagement documentation - **Contrat** - Contract templates - **Timeline** - Mission chronology - **OWASP WSTG** - Web security testing checklist - **Vulnérabilités** - Vulnerability database - **Scoring** - CVSS calculator - **Actions** - Remediation plans - **Rapport** - Report generation - **Cheat Infra** - Infrastructure cheat sheet - **Cheat Web** - Web pentesting cheat sheet - **Ressources** - Reference links ### Data Storage All data is persisted in browser localStorage with these keys: ```javascript // Storage keys used by the toolkit localStorage.getItem('pentestToolkit_roe') localStorage.getItem('pentestToolkit_contract') localStorage.getItem('pentestToolkit_timeline') localStorage.getItem('pentestToolkit_owaspChecklist') localStorage.getItem('pentestToolkit_vulnerabilities') localStorage.getItem('pentestToolkit_actions') ``` ## Customization and Extension ### Adding Custom Modules To add a new module to the toolkit, modify the HTML structure: ```html <!-- Add navigation button --> <div class="tab-buttons"> <button class="tab-btn" data-tab="custom-module"> 📦 Custom Module </button> </div> <!-- Add content panel --> <div id="custom-module" class="tab-content"> <div class="section-header"> <h2>📦 Custom Module</h2> <p>Description of your custom module</p> </div> <div class="content-area"> <!-- Your module content here --> <textarea id="customModuleData" placeholder="Enter data..."></textarea> <button onclick="saveCustomData()">Save</button> </div> </div> <!-- Add JavaScript handler --> <script> function saveCustomData() { const data = document.getElementById('customModuleData').value; localStorage.setItem('pentestToolkit_customModule', data); showNotification('Custom data saved', 'success'); } function loadCustomData() { const data = localStorage.getItem('pentestToolkit_customModule') || ''; document.getElementById('customModuleData').value = data; } // Load on page ready document.addEventListener('DOMContentLoaded', loadCustomData); </script> ``` ### Customizing OWASP WSTG Checklist The OWASP WSTG module uses checkboxes with localStorage persistence: ```javascript // Add custom security test items function addCustomOWASPTest(category, testId, testName, description) { const checklistHTML = ` <div class="checklist-item"> <input type="checkbox" id="${testId}" onchange="saveOWASPProgress()"> <label for="${testId}"> <strong>${testName}</strong> <span class="test-desc">${description}</span> </label> </div> `; document.querySelector(`#${category}-tests`).insertAdjacentHTML( 'beforeend', checklistHTML ); } // Example: Add custom authentication test addCustomOWASPTest( 'authentication', 'WSTG-ATHN-99', 'Test Custom OAuth Flow', 'Verify custom OAuth 2.0 implementation security' ); ``` ### Adding Vulnerability Templates Create custom vulnerability entry templates: ```javascript function addVulnerabilityTemplate(vuln) { const vulnEntry = { id: Date.now(), title: vuln.title || '', severity: vuln.severity || 'Medium', cvss: vuln.cvss || '5.0', description: vuln.description || '', impact: vuln.impact || '', remediation: vuln.remediation || '', status: 'Open', foundDate: new Date().toISOString().split('T')[0] }; // Get existing vulnerabilities const vulns = JSON.parse( localStorage.getItem('pentestToolkit_vulnerabilities') || '[]' ); vulns.push(vulnEntry); localStorage.setItem('pentestToolkit_vulnerabilities', JSON.stringify(vulns)); return vulnEntry.id; } // Example: Add SQL injection finding addVulnerabilityTemplate({ title: 'SQL Injection in Login Form', severity: 'Critical', cvss: '9.8', description: 'The login endpoint is vulnerable to SQL injection via the username parameter', impact: 'Complete database compromise, authentication bypass', remediation: 'Implement prepared statements and input validation' }); ``` ### Customizing Report Generation Modify report output by updating the print stylesheet or export function: ```javascript function generateCustomReport() { const reportData = { client: document.getElementById('clientName').value, date: new Date().toLocaleDateString('fr-FR'), vulnerabilities: JSON.parse( localStorage.getItem('pentestToolkit_vulnerabilities') || '[]' ), timeline: JSON.parse( localStorage.getItem('pentestToolkit_timeline') || '[]' ) }; // Generate custom HTML report const reportHTML = ` <!DOCTYPE html> <html> <head> <title>Pentest Report - ${reportData.client}</title> <style> @page { margin: 2cm; } body { font-family: Arial, sans-serif; } .critical { color: #d32f2f; font-weight: bold; } .high { color: #f57c00; } .medium { color: #fbc02d; } .low { color: #388e3c; } </style> </head> <body> <h1>Penetration Test Report</h1> <h2>Client: ${reportData.client}</h2> <h3>Date: ${reportData.date}</h3> <h2>Executive Summary</h2> <p>Total vulnerabilities found: ${reportData.vulnerabilities.length}</p> <h2>Findings</h2> ${reportData.vulnerabilities.map(v => ` <div class="vulnerability ${v.severity.toLowerCase()}"> <h3>${v.title} [${v.severity}]</h3> <p><strong>CVSS:</strong> ${v.cvss}</p> <p><strong>Description:</strong> ${v.description}</p> <p><strong>Impact:</strong> ${v.impact}</p> <p><strong>Remediation:</strong> ${v.remediation}</p> </div> `).join('')} </body> </html> `; // Open in new window for printing const printWindow = window.open('', '_blank'); printWindow.document.write(reportHTML); printWindow.document.close(); printWindow.print(); } ``` ### Exporting Data Export toolkit data to JSON for backup or integration: ```javascript function exportAllData() { const allData = { roe: localStorage.getItem('pentestToolkit_roe'), contract: localStorage.getItem('pentestToolkit_contract'), timeline: JSON.parse(localStorage.getItem('pentestToolkit_timeline') || '[]'), owasp: JSON.parse(localStorage.getItem('pentestToolkit_owaspChecklist') || '{}'), vulnerabilities: JSON.parse(localStorage.getItem('pentestToolkit_vulnerabilities') || '[]'), actions: JSON.parse(localStorage.getItem('pentestToolkit_actions') || '[]'), exportDate: new Date().toISOString() }; const dataStr = JSON.stringify(allData, null, 2); const dataBlob = new Blob([dataStr], { type: 'application/json' }); const url = URL.createObjectURL(dataBlob); const downloadLink = document.createElement('a'); downloadLink.href = url; downloadLink.download = `pentest-toolkit-export-${Date.now()}.json`; downloadLink.click(); URL.revokeObjectURL(url); } function importData(jsonFile) { const reader = new FileReader(); reader.onload = function(e) { const data = JSON.parse(e.target.result); // Restore all data if (data.roe) localStorage.setItem('pentestToolkit_roe', data.roe); if (data.contract) localStorage.setItem('pentestToolkit_contract', data.contract); if (data.timeline) localStorage.setItem('pentestToolkit_timeline', JSON.stringify(data.timeline)); if (data.owasp) localStorage.setItem('pentestToolkit_owaspChecklist', JSON.stringify(data.owasp)); if (data.vulnerabilities) localStorage.setItem('pentestToolkit_vulnerabilities', JSON.stringify(data.vulnerabilities)); if (data.actions) localStorage.setItem('pentestToolkit_actions', JSON.stringify(data.actions)); location.reload(); // Reload to reflect changes }; reader.readAsText(jsonFile); } ``` ## Common Patterns ### Starting a New Pentest Engagement ```javascript // 1. Clear previous engagement data (optional) function startNewEngagement() { if (confirm('Clear all existing data and start new engagement?')) { localStorage.clear(); location.reload(); } } // 2. Set engagement details in RoE function initializeEngagement(details) { const roeTemplate = ` PENTEST ENGAGEMENT ================== Client: ${details.clientName} Scope: ${details.scope} Start Date: ${details.startDate} End Date: ${details.endDate} Contact: ${details.contactEmail} AUTHORIZED TARGETS ------------------ ${details.targets.map(t => `- ${t}`).join('\n')} RULES OF ENGAGEMENT ------------------- - Testing hours: ${details.testingHours} - Communication protocol: ${details.commProtocol} - Emergency contact: ${details.emergencyContact} `; localStorage.setItem('pentestToolkit_roe', roeTemplate); document.getElementById('roeContent').value = roeTemplate; } // Example usage initializeEngagement({ clientName: 'Acme Corp', scope: 'Web Application Security Assessment', startDate: '2026-06-01', endDate: '2026-06-15', contactEmail: 'security@acme.example', targets: ['https://app.acme.example', '10.0.0.0/24'], testingHours: '09:00 - 18:00 UTC', commProtocol: 'Email + Slack', emergencyContact: '+1-555-0100' }); ``` ### Tracking Vulnerability Workflow ```javascript // Add vulnerability with full lifecycle function trackVulnerability(finding) { const vuln = { id: Date.now(), title: finding.title, severity: calculateSeverity(finding.cvss), cvss: finding.cvss, cwe: finding.cwe || '', description: finding.description,
GitHub에서 보기
이 SKILL.md는 매우 커서 SkillsMP가 여기에는 첫 섹션만 미리 보여줍니다. GitHub에서 보기