一键导入
engagement-planning
Rules of engagement, scope definition, and authorized penetration test planning
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Rules of engagement, scope definition, and authorized penetration test planning
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Authorized AI penetration testing assistant for web applications, APIs, and infrastructure. Performs reconnaissance, vulnerability assessment, PoC validation, exploit chaining, and professional reporting. Use when the user asks for pentest, penetration test, security assessment, vulnerability scan, bug bounty research, authorized hacking, SQLi/XSS/IDOR/SSRF testing, API security audit, or exploit validation.
Authorized AI penetration testing for web apps, APIs, cloud, and infrastructure. Full kill-chain methodology with PoC validation, vulnerability chaining, and professional reporting. Triggers on: pentest, penetration test, security assessment, vuln scan, bug bounty, red team, authorized hack, SQL injection test, XSS test, IDOR, SSRF, API security, exploit validation, security audit.
Authorized AI penetration testing assistant — full-spectrum security testing with deep exploitation skills and integrated tooling. Use for web app pentests, API security, vuln validation, PoC development, bug bounty, and security assessments. Triggers on pentest, penetration test, security audit, exploit, SQLi, XSS, IDOR, SSRF.
API安全测试的专业技能和方法论
JWT and OIDC security testing covering token forgery, algorithm confusion, and claim manipulation
AWS cloud security testing covering IAM misconfigurations, S3 exposure, metadata abuse, and privilege escalation paths
| name | engagement-planning |
| description | Rules of engagement, scope definition, and authorized penetration test planning |
IN-SCOPE:
- https://app.example.com (all subpaths)
- api.example.com
- 10.0.0.0/24 (staging only)
OUT-OF-SCOPE:
- Production payment gateway
- Third-party SaaS (Stripe, Auth0)
- Social engineering / phishing
- DoS / availability attacks
| Phase | Goal | Skills to Load |
|---|---|---|
| Recon | Attack surface map | subfinder-tooling, httpx-tooling, nmap-tooling |
| Enum | Services, endpoints, tech stack | katana-tooling, ffuf-tooling, nuclei-tooling |
| Assess | Vuln discovery | vulnerability-specific skills |
| Exploit | PoC validation | deep-pentest-methodology |
| Report | Findings + remediation | engagement-planning |