pilot-penetration-testing-setupDeploy an automated penetration testing pipeline with 4 agents. Use this skill when: 1. User wants to set up a penetration testing or security assessment pip...
Install via ClawdBot CLI:
clawdbot install teoslayer/pilot-penetration-testing-setupGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
report → https://reports.example.com/pentest-2026-042Calls external URL not in known-safe list
https://pilotprotocol.networkAudited Apr 23, 2026 · audit v1.0
Generated Jul 28, 2026
A SaaS company deploys the 4-agent pipeline to continuously scan their cloud infrastructure for new vulnerabilities after each deployment. Recon discovers exposed services, scanner checks for CVEs, exploiter validates critical findings, and reporter generates compliance reports for SOC 2 audits.
An enterprise IT security team sets up the pipeline to perform quarterly internal network penetration tests. The recon agent maps the internal network, scanner identifies misconfigurations and missing patches, exploiter safely tests exploitability, and reporter creates executive summaries for management.
A manufacturer of IoT devices uses the pipeline to audit their product firmware and cloud backend before release. The recon agent scans open ports and services on the device, scanner checks for known vulnerabilities in libraries, exploiter validates proof-of-concept exploits, and reporter documents remediation steps.
An MSSP deploys the pipeline as a value-added service for multiple clients, using a separate prefix for each client. They automate periodic pentesting, generating per-client reports with risk ratings and remediation guidance, enhancing their security portfolio.
A development team integrates the pipeline into their CI/CD pipeline to perform security testing on staging environments before production releases. The pipeline scans container images, APIs, and infrastructure-as-code, providing rapid feedback to developers.
Offer the basic pipeline setup for free with usage limits (e.g., max number of agents or scan frequency). Premium tiers unlock advanced features like custom reporting, priority support, and integration with external tools.
Provide paid consulting to customize and deploy the pipeline for enterprise clients, including training, integration with existing security tools, and ongoing maintenance. This ensures effective use while generating high-value revenue.
Offer a fully managed penetration testing pipeline where the provider hosts, monitors, and updates the pipeline for clients. Clients pay a monthly fee for continuous security assessment and receive regular reports without managing infrastructure.
💬 Integration Tip
Integrate with existing SIEM or ticketing systems by configuring webhooks from the reporter agent to send findings and alerts. For CI/CD integration, trigger the pipeline execution via API calls after deployments.
Scored May 30, 2026
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.
Use when writing tests, creating test strategies, or building automation frameworks. Invoke for unit tests, integration tests, E2E, coverage analysis, performance testing, security testing.