pentestlisted
Install: claude install-skill gonimar/claude-web-studio
# Pentest (the project's own application)
Reply in the project conversation language (CLAUDE.md → Language); code, identifiers, paths and commit messages stay in English.
Template `templates/pentest-report.md`; reference `stack-reference/security-standards.md`. **The scope is fixed before the first request**: only the project's own hosts/domains from technical-preferences/deployment docs; production only with an explicit "yes" and in an agreed window. Targets outside the project are refused.
## Phase 1: Scope and confirmation
`AskUserQuestion`: target (URL), environment, window, accounts for authenticated checks, exclusions (payments, e-mails). Record the scope as the report's first section.
## Phase 2: Tools (whatever is installed; otherwise docker images with consent)
ZAP baseline → full/API scan (OpenAPI or GraphQL introspection on dev); Nuclei (web/misconfig templates); Schemathesis on OpenAPI / GraphQL fuzzing; `testssl.sh`; `nmap -sV` on the project's own host; manual checks: IDOR (two accounts), GraphQL field permissions, depth/batching limits, login rate limit, password reset, uploads, CSRF/CORS, headers.
`--quick` — ZAP baseline + headers + testssl only.
## Phase 3: Findings
Severity/CVSS, steps, evidence (no secrets), fix (code/config), verification after the fix; "clean" areas listed.
## Phase 4: Write
"May I write `docs/security/pentest-<date>.md`?" — one `AskUserQuestion`: write (Recommended) · show the draft/diff first · not now. Stories for High+. After t