Security Penetration Testing

Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments.

How to use it

Claude Code
  1. Run the line below. It pulls the whole folder into ~/.claude/skills/security-pen-testing, including the files SKILL.md points to.
  2. Describe your job in plain words. Claude Code follows the skill from there.
Claude Code — installs the whole folder, not just SKILL.md
npx degit alirezarezvani/claude-skills/engineering-team/skills/security-pen-testing#main ~/.claude/skills/security-pen-testing

For one project only, change the path to .claude/skills/security-pen-testing. This skill also uses package.json, requirements.txt, owasp_top_10_checklist.md, attack_patterns.md, testssl.sh, findings.json — copying SKILL.md alone won't be enough. See the folder on GitHub.

Claude (web or desktop app)
  1. On this page open ⋯ → Download .md.
  2. Save it as SKILL.md in a folder, zip the folder, then Customize → Skills → + → Create skill → Upload a skill.
  3. Pick the file and Save. Claude shows the name and description and runs a security scan.
  4. Check the skill is switched on.
  5. Start a new chat and describe your job in plain words. The AI follows the skill from there.
ChatGPT or another app
  1. ChatGPT: make a Project and paste it into Instructions.
  2. Neither? Paste it at the top of a new chat — it works for that chat.
Not working?
  • Check which app you pasted it into — the steps above name the right one.
  • Some skills need the paid tier of Claude or ChatGPT.
Step-by-step guide with screenshots · Ask in the forum

Paste into Claude, ChatGPT or Cursor.

Source of Security Penetration Testing

Show the full text307 lines
namedescription
security-pen-testingUse when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report generation.

Security Penetration Testing

Hands-on offensive security testing skill for finding vulnerabilities before attackers do. This is NOT compliance checking (see senior-secops) or security policy writing (see senior-security) — this is about systematic vulnerability discovery through authorized testing.


Table of Contents


Overview

What This Skill Does

This skill provides the methodology, checklists, and automation for offensive security testing — actively probing systems to discover exploitable vulnerabilities. It covers web applications, APIs, infrastructure, and supply chain security.

Distinction from Other Security Skills
Skill Focus Approach
security-pen-testing (this) Finding vulnerabilities Offensive — simulate attacker techniques
senior-secops Security operations Defensive — monitoring, incident response, SIEM
senior-security Security policy Governance — policies, frameworks, risk registers
skill-security-auditor CI/CD gates Automated — pre-merge security checks
Prerequisites

All testing described here assumes written authorization from the system owner. Unauthorized testing is illegal under the CFAA and equivalent laws worldwide. Always obtain a signed scope-of-work or rules-of-engagement document before starting.


OWASP Top 10 Systematic Audit

Use the vulnerability scanner tool for automated checklist generation:

# Generate OWASP checklist for a web application
python scripts/vulnerability_scanner.py --target web --scope full

# Quick API-focused scan
python scripts/vulnerability_scanner.py --target api --scope quick --json
Quick Reference
# Category Key Tests
A01 Broken Access Control IDOR, vertical escalation, CORS, JWT claim manipulation, forced browsing
A02 Cryptographic Failures TLS version, password hashing, hardcoded keys, weak PRNG
A03 Injection SQLi, NoSQLi, command injection, template injection, XSS
A04 Insecure Design Rate limiting, business logic abuse, multi-step flow bypass
A05 Security Misconfiguration Default credentials, debug mode, security headers, directory listing
A06 Vulnerable Components Dependency audit (npm/pip/go), EOL checks, known CVEs
A07 Auth Failures Brute force, session cookie flags, session invalidation, MFA bypass
A08 Integrity Failures Unsafe deserialization, SRI checks, CI/CD pipeline integrity
A09 Logging Failures Auth event logging, sensitive data in logs, alerting thresholds
A10 SSRF Internal IP access, cloud metadata endpoints, DNS rebinding
# Audit dependencies
python scripts/dependency_auditor.py --file package.json --severity high
python scripts/dependency_auditor.py --file requirements.txt --json

See owasp_top_10_checklist.md for detailed test procedures, code patterns to detect, remediation steps, and CVSS scoring guidance for each category.


Static Analysis

Recommended tools: CodeQL (custom queries for project-specific patterns), Semgrep (rule-based scanning with auto-fix), ESLint security plugins (eslint-plugin-security, eslint-plugin-no-unsanitized).

Key patterns to detect: SQL injection via string concatenation, hardcoded JWT secrets, unsafe YAML/pickle deserialization, missing security middleware (e.g., Express without Helmet).

See attack_patterns.md for code patterns and detection payloads across injection types.


Dependency Vulnerability Scanning

Ecosystem commands: npm audit, pip audit, govulncheck ./..., bundle audit check

CVE Triage Workflow:

  1. Collect — Run ecosystem audit tools, aggregate findings
  2. Deduplicate — Group by CVE ID across direct and transitive deps
  3. Prioritize — Critical + exploitable + reachable = fix immediately
  4. Remediate — Upgrade, patch, or mitigate with compensating controls
  5. Verify — Rerun audit to confirm fix, update lock files
python scripts/dependency_auditor.py --file package.json --severity critical --json

Secret Scanning

Tools: TruffleHog (git history + filesystem), Gitleaks (regex-based with custom rules).

# Scan git history for verified secrets
trufflehog git file://. --only-verified --json

# Scan filesystem
trufflehog filesystem . --json

Integration points: Pre-commit hooks (gitleaks, trufflehog), CI/CD gates (GitHub Actions with trufflesecurity/trufflehog@main). Configure .gitleaks.toml for custom rules (AWS keys, API keys, private key headers) and allowlists for test fixtures.


API Security Testing

Authentication Bypass
  • JWT manipulation: Change alg to none, RS256-to-HS256 confusion, claim modification (role: "admin", exp: 9999999999)
  • Session fixation: Check if session ID changes after authentication
Authorization Flaws
  • IDOR/BOLA: Change resource IDs in every endpoint — test read, update, delete across users
  • BFLA: Regular user tries admin endpoints (expect 403)
  • Mass assignment: Add privileged fields (role, is_admin) to update requests
Rate Limiting & GraphQL
  • Rate limiting: Rapid-fire requests to auth endpoints; expect 429 after threshold
  • GraphQL: Test introspection (should be disabled in prod), query depth attacks, batch mutations bypassing rate limits

See attack_patterns.md for complete JWT manipulation payloads, IDOR testing methodology, BFLA endpoint lists, GraphQL introspection/depth/batch attack patterns, and rate limiting bypass techniques.


Web Vulnerability Testing

Vulnerability Key Tests
XSS Reflected (script/img/svg payloads), Stored (persistent fields), DOM-based (innerHTML + location.hash)
CSRF Replay without token (expect 403), cross-session token replay, check SameSite cookie attribute
SQL Injection Error-based (' OR 1=1--), union-based enumeration, time-based blind (SLEEP(5)), boolean-based blind
SSRF Internal IPs, cloud metadata endpoints (AWS/GCP/Azure), IPv6/hex/decimal encoding bypasses
Path Traversal ../../../etc/passwd, URL encoding, double encoding bypasses

See attack_patterns.md for complete test payloads (XSS filter bypasses, context-specific XSS, SQL injection per database engine, SSRF bypass techniques, and DOM-based XSS source/sink pairs).


Infrastructure Security

Key checks:

  • Cloud storage: S3 bucket public access (aws s3 ls s3://bucket --no-sign-request), bucket policies, ACLs
  • HTTP security headers: HSTS, CSP (no unsafe-inline/unsafe-eval), X-Content-Type-Options, X-Frame-Options, Referrer-Policy
  • TLS configuration: nmap --script ssl-enum-ciphers -p 443 target.com or testssl.sh — reject TLS 1.0/1.1, RC4, 3DES, export-grade ciphers
  • Port scanning: nmap -sV target.com — flag dangerous open ports (FTP/21, Telnet/23, Redis/6379, MongoDB/27017)

Pen Test Report Generation

Generate professional reports from structured findings:

# Generate markdown report from findings JSON
python scripts/pentest_report_generator.py --findings findings.json --format md --output report.md

# Generate JSON report
python scripts/pentest_report_generator.py --findings findings.json --format json --output report.json
Findings JSON Format
[
  {
    "title": "SQL Injection in Login Endpoint",
    "severity": "critical",
    "cvss_score": 9.8,
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "category": "A03:2021 - Injection",
    "description": "The /api/login endpoint is vulnerable to SQL injection via the email parameter.",
    "evidence": "Request: POST /api/login {\"email\": \"' OR 1=1--\", \"password\": \"x\"}\nResponse: 200 OK with admin session token",
    "impact": "Full database access, authentication bypass, potential remote code execution",
    "remediation": "Use parameterized queries. Replace string concatenation with prepared statements.",
    "references": ["https://cwe.mitre.org/data/definitions/89.html"]
  }
]
Report Structure
  1. Executive Summary: Business impact, overall risk level, top 3 findings
  2. Scope: What was tested, what was excluded, testing dates
  3. Methodology: Tools used, testing approach (black/gray/white box)
  4. Findings Table: Sorted by severity with CVSS scores
  5. Detailed Findings: Each with description, evidence, impact, remediation
  6. Remediation Priority Matrix: Effort vs. impact for each fix
  7. Appendix: Raw tool output, full payload lists

Responsible Disclosure Workflow

Responsible disclosure is mandatory for any vulnerability found during authorized testing. Standard timeline: report on day 1, follow up at day 7, status update at day 30, public disclosure at day 90.

Key principles: Never exploit beyond proof of concept, encrypt all communications, do not access real user data, document everything with timestamps.

See responsible_disclosure.md for full disclosure timelines (standard 90-day, accelerated 30-day, extended 120-day), communication templates, legal considerations, bug bounty program integration, and CVE request process.


Workflows

Workflow 1: Quick Security Check (15 Minutes)

For pre-merge reviews or quick health checks:

# 1. Generate OWASP checklist
python scripts/vulnerability_scanner.py --target web --scope quick

# 2. Scan dependencies
python scripts/dependency_auditor.py --file package.json --severity high

# 3. Check for secrets in recent commits
# (Use gitleaks or trufflehog as described in Secret Scanning section)

# 4. Review HTTP security headers
curl -sI https://target.com | grep -iE "(strict-transport|content-security|x-frame|x-content-type)"

Decision: If any critical or high findings, block the merge.

Workflow 2: Full Penetration Test (Multi-Day Assessment)

Day 1 — Reconnaissance:

  1. Map the attack surface: endpoints, authentication flows, third-party integrations
  2. Run automated OWASP checklist (full scope)
  3. Run dependency audit across all manifests
  4. Run secret scan on full git history

Day 2 — Manual Testing:

  1. Test authentication and authorization (IDOR, BOLA, BFLA)
  2. Test injection points (SQLi, XSS, SSRF, command injection)
  3. Test business logic flaws
  4. Test API-specific vulnerabilities (GraphQL, rate limiting, mass assignment)

Day 3 — Infrastructure and Reporting:

  1. Check cloud storage permissions
  2. Verify TLS configuration and security headers
  3. Port scan for unnecessary services
  4. Compile findings into structured JSON
  5. Generate pen test report
# Generate final report
python scripts/pentest_report_generator.py --findings findings.json --format md --output pentest-report.md
Workflow 3: CI/CD Security Gate

Automated security checks on every PR: secret scanning (TruffleHog), dependency audit (npm audit, pip audit), SAST (Semgrep with p/security-audit, p/owasp-top-ten), and security headers check on staging.

Gate Policy: Block merge on critical/high findings. Warn on medium. Log low/info.


Anti-Patterns

  1. Testing in production without authorization — Always get written permission and use staging/test environments when possible
  2. Ignoring low-severity findings — Low findings compound; a chain of lows can become a critical exploit path
  3. Skipping responsible disclosure — Every vulnerability found must be reported through proper channels
  4. Relying solely on automated tools — Tools miss business logic flaws, chained exploits, and novel attack vectors
  5. Testing without a defined scope — Scope creep leads to legal liability; document what is and isn't in scope
  6. Reporting without remediation guidance — Every finding must include actionable remediation steps
  7. Storing evidence insecurely — Pen test evidence (screenshots, payloads, tokens) is sensitive; encrypt and restrict access
  8. One-time testing — Security testing must be continuous; integrate into CI/CD and schedule periodic assessments

Cross-References

Skill Relationship
senior-secops Defensive security operations — monitoring, incident response, SIEM configuration
senior-security Security policy and governance — frameworks, risk registers, compliance
dependency-auditor Deep supply chain security — SBOMs, license compliance, transitive risk
code-reviewer Code review practices — includes security review checklist
1---
2name: "security-pen-testing"
3description: "Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report generation."
4---
5 
6# Security Penetration Testing
7 
8Hands-on offensive security testing skill for finding vulnerabilities before attackers do. This is NOT compliance checking (see senior-secops) or security policy writing (see senior-security) — this is about systematic vulnerability discovery through authorized testing.
9 
10---
11 
12## Table of Contents
13 
14- [Overview](#overview)
15- [OWASP Top 10 Systematic Audit](#owasp-top-10-systematic-audit)
16- [Static Analysis](#static-analysis)
17- [Dependency Vulnerability Scanning](#dependency-vulnerability-scanning)
18- [Secret Scanning](#secret-scanning)
19- [API Security Testing](#api-security-testing)
20- [Web Vulnerability Testing](#web-vulnerability-testing)
21- [Infrastructure Security](#infrastructure-security)
22- [Pen Test Report Generation](#pen-test-report-generation)
23- [Responsible Disclosure Workflow](#responsible-disclosure-workflow)
24- [Workflows](#workflows)
25- [Anti-Patterns](#anti-patterns)
26- [Cross-References](#cross-references)
27 
28---
29 
30## Overview
31 
32### What This Skill Does
33 
34This skill provides the methodology, checklists, and automation for **offensive security testing** — actively probing systems to discover exploitable vulnerabilities. It covers web applications, APIs, infrastructure, and supply chain security.
35 
36### Distinction from Other Security Skills
37 
38| Skill | Focus | Approach |
39|-------|-------|----------|
40| **security-pen-testing** (this) | Finding vulnerabilities | Offensive — simulate attacker techniques |
41| senior-secops | Security operations | Defensive — monitoring, incident response, SIEM |
42| senior-security | Security policy | Governance — policies, frameworks, risk registers |
43| skill-security-auditor | CI/CD gates | Automated — pre-merge security checks |
44 
45### Prerequisites
46 
47All testing described here assumes **written authorization** from the system owner. Unauthorized testing is illegal under the CFAA and equivalent laws worldwide. Always obtain a signed scope-of-work or rules-of-engagement document before starting.
48 
49---
50 
51## OWASP Top 10 Systematic Audit
52 
53Use the vulnerability scanner tool for automated checklist generation:
54 
55```bash
56# Generate OWASP checklist for a web application
57python scripts/vulnerability_scanner.py --target web --scope full
58 
59# Quick API-focused scan
60python scripts/vulnerability_scanner.py --target api --scope quick --json
61```
62 
63### Quick Reference
64 
65| # | Category | Key Tests |
66|---|----------|-----------|
67| A01 | Broken Access Control | IDOR, vertical escalation, CORS, JWT claim manipulation, forced browsing |
68| A02 | Cryptographic Failures | TLS version, password hashing, hardcoded keys, weak PRNG |
69| A03 | Injection | SQLi, NoSQLi, command injection, template injection, XSS |
70| A04 | Insecure Design | Rate limiting, business logic abuse, multi-step flow bypass |
71| A05 | Security Misconfiguration | Default credentials, debug mode, security headers, directory listing |
72| A06 | Vulnerable Components | Dependency audit (npm/pip/go), EOL checks, known CVEs |
73| A07 | Auth Failures | Brute force, session cookie flags, session invalidation, MFA bypass |
74| A08 | Integrity Failures | Unsafe deserialization, SRI checks, CI/CD pipeline integrity |
75| A09 | Logging Failures | Auth event logging, sensitive data in logs, alerting thresholds |
76| A10 | SSRF | Internal IP access, cloud metadata endpoints, DNS rebinding |
77 
78```bash
79# Audit dependencies
80python scripts/dependency_auditor.py --file package.json --severity high
81python scripts/dependency_auditor.py --file requirements.txt --json
82```
83 
84See [owasp_top_10_checklist.md](references/owasp_top_10_checklist.md) for detailed test procedures, code patterns to detect, remediation steps, and CVSS scoring guidance for each category.
85 
86---
87 
88## Static Analysis
89 
90**Recommended tools:** CodeQL (custom queries for project-specific patterns), Semgrep (rule-based scanning with auto-fix), ESLint security plugins (`eslint-plugin-security`, `eslint-plugin-no-unsanitized`).
91 
92Key patterns to detect: SQL injection via string concatenation, hardcoded JWT secrets, unsafe YAML/pickle deserialization, missing security middleware (e.g., Express without Helmet).
93 
94See [attack_patterns.md](references/attack_patterns.md) for code patterns and detection payloads across injection types.
95 
96---
97 
98## Dependency Vulnerability Scanning
99 
100**Ecosystem commands:** `npm audit`, `pip audit`, `govulncheck ./...`, `bundle audit check`
101 
102**CVE Triage Workflow:**
1031. **Collect** — Run ecosystem audit tools, aggregate findings
1042. **Deduplicate** — Group by CVE ID across direct and transitive deps
1053. **Prioritize** — Critical + exploitable + reachable = fix immediately
1064. **Remediate** — Upgrade, patch, or mitigate with compensating controls
1075. **Verify** — Rerun audit to confirm fix, update lock files
108 
109```bash
110python scripts/dependency_auditor.py --file package.json --severity critical --json
111```
112 
113---
114 
115## Secret Scanning
116 
117**Tools:** TruffleHog (git history + filesystem), Gitleaks (regex-based with custom rules).
118 
119```bash
120# Scan git history for verified secrets
121trufflehog git file://. --only-verified --json
122 
123# Scan filesystem
124trufflehog filesystem . --json
125```
126 
127**Integration points:** Pre-commit hooks (gitleaks, trufflehog), CI/CD gates (GitHub Actions with `trufflesecurity/trufflehog@main`). Configure `.gitleaks.toml` for custom rules (AWS keys, API keys, private key headers) and allowlists for test fixtures.
128 
129---
130 
131## API Security Testing
132 
133### Authentication Bypass
134 
135- **JWT manipulation:** Change `alg` to `none`, RS256-to-HS256 confusion, claim modification (`role: "admin"`, `exp: 9999999999`)
136- **Session fixation:** Check if session ID changes after authentication
137 
138### Authorization Flaws
139 
140- **IDOR/BOLA:** Change resource IDs in every endpoint — test read, update, delete across users
141- **BFLA:** Regular user tries admin endpoints (expect 403)
142- **Mass assignment:** Add privileged fields (`role`, `is_admin`) to update requests
143 
144### Rate Limiting & GraphQL
145 
146- **Rate limiting:** Rapid-fire requests to auth endpoints; expect 429 after threshold
147- **GraphQL:** Test introspection (should be disabled in prod), query depth attacks, batch mutations bypassing rate limits
148 
149See [attack_patterns.md](references/attack_patterns.md) for complete JWT manipulation payloads, IDOR testing methodology, BFLA endpoint lists, GraphQL introspection/depth/batch attack patterns, and rate limiting bypass techniques.
150 
151---
152 
153## Web Vulnerability Testing
154 
155| Vulnerability | Key Tests |
156|--------------|-----------|
157| **XSS** | Reflected (script/img/svg payloads), Stored (persistent fields), DOM-based (innerHTML + location.hash) |
158| **CSRF** | Replay without token (expect 403), cross-session token replay, check SameSite cookie attribute |
159| **SQL Injection** | Error-based (`' OR 1=1--`), union-based enumeration, time-based blind (`SLEEP(5)`), boolean-based blind |
160| **SSRF** | Internal IPs, cloud metadata endpoints (AWS/GCP/Azure), IPv6/hex/decimal encoding bypasses |
161| **Path Traversal** | `../../../etc/passwd`, URL encoding, double encoding bypasses |
162 
163See [attack_patterns.md](references/attack_patterns.md) for complete test payloads (XSS filter bypasses, context-specific XSS, SQL injection per database engine, SSRF bypass techniques, and DOM-based XSS source/sink pairs).
164 
165---
166 
167## Infrastructure Security
168 
169**Key checks:**
170- **Cloud storage:** S3 bucket public access (`aws s3 ls s3://bucket --no-sign-request`), bucket policies, ACLs
171- **HTTP security headers:** HSTS, CSP (no `unsafe-inline`/`unsafe-eval`), X-Content-Type-Options, X-Frame-Options, Referrer-Policy
172- **TLS configuration:** `nmap --script ssl-enum-ciphers -p 443 target.com` or `testssl.sh` — reject TLS 1.0/1.1, RC4, 3DES, export-grade ciphers
173- **Port scanning:** `nmap -sV target.com` — flag dangerous open ports (FTP/21, Telnet/23, Redis/6379, MongoDB/27017)
174 
175---
176 
177## Pen Test Report Generation
178 
179Generate professional reports from structured findings:
180 
181```bash
182# Generate markdown report from findings JSON
183python scripts/pentest_report_generator.py --findings findings.json --format md --output report.md
184 
185# Generate JSON report
186python scripts/pentest_report_generator.py --findings findings.json --format json --output report.json
187```
188 
189### Findings JSON Format
190 
191```json
192[
193 {
194 "title": "SQL Injection in Login Endpoint",
195 "severity": "critical",
196 "cvss_score": 9.8,
197 "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
198 "category": "A03:2021 - Injection",
199 "description": "The /api/login endpoint is vulnerable to SQL injection via the email parameter.",
200 "evidence": "Request: POST /api/login {\"email\": \"' OR 1=1--\", \"password\": \"x\"}\nResponse: 200 OK with admin session token",
201 "impact": "Full database access, authentication bypass, potential remote code execution",
202 "remediation": "Use parameterized queries. Replace string concatenation with prepared statements.",
203 "references": ["https://cwe.mitre.org/data/definitions/89.html"]
204 }
205]
206```
207 
208### Report Structure
209 
2101. **Executive Summary**: Business impact, overall risk level, top 3 findings
2112. **Scope**: What was tested, what was excluded, testing dates
2123. **Methodology**: Tools used, testing approach (black/gray/white box)
2134. **Findings Table**: Sorted by severity with CVSS scores
2145. **Detailed Findings**: Each with description, evidence, impact, remediation
2156. **Remediation Priority Matrix**: Effort vs. impact for each fix
2167. **Appendix**: Raw tool output, full payload lists
217 
218---
219 
220## Responsible Disclosure Workflow
221 
222Responsible disclosure is **mandatory** for any vulnerability found during authorized testing. Standard timeline: report on day 1, follow up at day 7, status update at day 30, public disclosure at day 90.
223 
224**Key principles:** Never exploit beyond proof of concept, encrypt all communications, do not access real user data, document everything with timestamps.
225 
226See [responsible_disclosure.md](references/responsible_disclosure.md) for full disclosure timelines (standard 90-day, accelerated 30-day, extended 120-day), communication templates, legal considerations, bug bounty program integration, and CVE request process.
227 
228---
229 
230## Workflows
231 
232### Workflow 1: Quick Security Check (15 Minutes)
233 
234For pre-merge reviews or quick health checks:
235 
236```bash
237# 1. Generate OWASP checklist
238python scripts/vulnerability_scanner.py --target web --scope quick
239 
240# 2. Scan dependencies
241python scripts/dependency_auditor.py --file package.json --severity high
242 
243# 3. Check for secrets in recent commits
244# (Use gitleaks or trufflehog as described in Secret Scanning section)
245 
246# 4. Review HTTP security headers
247curl -sI https://target.com | grep -iE "(strict-transport|content-security|x-frame|x-content-type)"
248```
249 
250**Decision**: If any critical or high findings, block the merge.
251 
252### Workflow 2: Full Penetration Test (Multi-Day Assessment)
253 
254**Day 1 — Reconnaissance:**
2551. Map the attack surface: endpoints, authentication flows, third-party integrations
2562. Run automated OWASP checklist (full scope)
2573. Run dependency audit across all manifests
2584. Run secret scan on full git history
259 
260**Day 2 — Manual Testing:**
2611. Test authentication and authorization (IDOR, BOLA, BFLA)
2622. Test injection points (SQLi, XSS, SSRF, command injection)
2633. Test business logic flaws
2644. Test API-specific vulnerabilities (GraphQL, rate limiting, mass assignment)
265 
266**Day 3 — Infrastructure and Reporting:**
2671. Check cloud storage permissions
2682. Verify TLS configuration and security headers
2693. Port scan for unnecessary services
2704. Compile findings into structured JSON
2715. Generate pen test report
272 
273```bash
274# Generate final report
275python scripts/pentest_report_generator.py --findings findings.json --format md --output pentest-report.md
276```
277 
278### Workflow 3: CI/CD Security Gate
279 
280Automated security checks on every PR: secret scanning (TruffleHog), dependency audit (`npm audit`, `pip audit`), SAST (Semgrep with `p/security-audit`, `p/owasp-top-ten`), and security headers check on staging.
281 
282**Gate Policy**: Block merge on critical/high findings. Warn on medium. Log low/info.
283 
284---
285 
286## Anti-Patterns
287 
2881. **Testing in production without authorization** — Always get written permission and use staging/test environments when possible
2892. **Ignoring low-severity findings** — Low findings compound; a chain of lows can become a critical exploit path
2903. **Skipping responsible disclosure** — Every vulnerability found must be reported through proper channels
2914. **Relying solely on automated tools** — Tools miss business logic flaws, chained exploits, and novel attack vectors
2925. **Testing without a defined scope** — Scope creep leads to legal liability; document what is and isn't in scope
2936. **Reporting without remediation guidance** — Every finding must include actionable remediation steps
2947. **Storing evidence insecurely** — Pen test evidence (screenshots, payloads, tokens) is sensitive; encrypt and restrict access
2958. **One-time testing** — Security testing must be continuous; integrate into CI/CD and schedule periodic assessments
296 
297---
298 
299## Cross-References
300 
301| Skill | Relationship |
302|-------|-------------|
303| [senior-secops](../senior-secops/SKILL.md) | Defensive security operations — monitoring, incident response, SIEM configuration |
304| [senior-security](../senior-security/SKILL.md) | Security policy and governance — frameworks, risk registers, compliance |
305| [dependency-auditor](engineering/skills/dependency-auditor/SKILL.md) | Deep supply chain security — SBOMs, license compliance, transitive risk |
306| [code-reviewer](../code-reviewer/SKILL.md) | Code review practices — includes security review checklist |
307 

Discussion

Alternatives

Also in SecuritySee all 533 in Development →