pentest-interactiveProvides an interactive, structured reference for manual penetration testing across 7 phases with safe command templates and guidance for security assessments.
Install via ClawdBot CLI:
clawdbot install tooled-app/pentest-interactiveGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"Ignore previous instructions"Calls external URL not in known-safe list
https://example.comAudited May 28, 2026 · audit v1.0
Generated Oct 6, 2026
A development team runs this interactive pentest skill before each major release to verify authentication, authorization, and header configurations on staging environments. The agent guides reviewers through the 7 phases manually, interpreting curl and openssl outputs to catch misconfigurations before production.
A fintech security team uses the structured checklists to document quarterly assessments of customer-facing APIs and payment flows. Findings from IDOR, session handling, and business logic phases are compiled into audit evidence for regulators and internal risk committees.
Individual bug bounty hunters and small research teams use the read-safe probes and fingerprinting templates to map a target's attack surface before deeper manual testing. The methodology keeps reconnaissance organized across DNS, SSL, headers, and exposed paths without triggering aggressive tooling.
An independent pentest consultancy standardizes its engagement workflow around this skill, ensuring every client scope covers recon, auth, authorization, injection, API, infrastructure, and business logic. The agent prompts for target details and walks consultants through consistent, auditable testing phases.
Early-stage startups with limited security budgets use the skill as a lightweight self-assessment before onboarding enterprise customers. Engineers follow the checklists to spot missing security headers, weak JWTs, and verbose login errors in their MVP stack.
The skill package is released freely to build community trust and contributions, with optional paid support, custom checklists, or curated command libraries for enterprise teams. Revenue comes from sponsorships, consulting upsells, and premium content rather than the core artifact.
Security firms wrap the interactive methodology into subscription-driven assessments where human analysts or AI agents execute the phases on client infrastructure on a recurring schedule. Clients pay monthly for continuous audit coverage rather than one-off engagements.
The skill is bundled into AI agent platforms, developer IDEs, or CI/CD security marketplaces as a free or tiered capability. The platform monetizes through agent usage credits, enterprise seats, or premium integrations that connect findings to ticketing and vulnerability management systems.
💬 Integration Tip
Wire this skill into an agent framework that can prompt for target URLs, run the read-safe commands in a sandboxed terminal, and parse HTTP responses into structured findings while enforcing a confirmation gate before any intrusive phase.
Scored Oct 6, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...