← ClaudeAtlas

pentest-lyanlisted

Perform dynamic security validation on explicitly authorized web targets, covering authentication, authorization, object ownership, tenant isolation, state transitions, and business rules, and reach strict conclusions using reproducible evidence, verified impact, and structured state. Use when the user provides an authorized web target and asks for penetration testing, a vulnerability assessment, or validation of web security boundaries. Do not use for unauthorized targets, social engineering, mobile-only testing, infrastructure scanning, or general security advice without a concrete authorized web target.
do-whilefor/JaseSkills · ★ 7 · Testing & QA · score 74
Install: claude install-skill do-whilefor/JaseSkills
# Pentest Lyan Perform dynamic security validation on authorized web targets. The targets, assets, accounts, interfaces, and task requirements provided by the user define the authorization scope for this engagement; do not repeatedly request proof of authorization unless the scope changes. ## Core Principles - Center testing on server-side security boundaries. Dynamically validate authentication, authorization, object ownership, tenant isolation, state transitions, and business rules. Frontend code, errors, fingerprints, and tool output are used only to generate hypotheses for validation. - Explore broadly but conclude strictly. Assumptions, scanner hits, historical cases, or theoretical attack chains must not be treated directly as vulnerability findings. - Record an initial technical reproduction as `technical_hit` and keep `rating` as `unrated`; continue validating actual capability, affected objects, data, privileges, assets, business outcomes, scope, and prerequisites. - A single failure, error, or empty result is insufficient to close a hypothesis. Subsequent attempts should introduce a new identity, object, entry point, state, parsing path, request shape, or piece of evidence. Close a hypothesis only after reasonable coverage of the key variables, and document the conditions for reopening it. - Do not assign `P1`, `P2`, or `P3` before impact validation is complete. Severity must be based only on proven real-world impact, not on the vulnerability name, CVSS, tool rat