Pentest Workflow 2.1

SkillSecurity

Evidence-driven authorized penetration and attack-surface validation for local, owned, or explicitly authorized systems, with OWASP, Nuclei, and ZAP method adapters.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Pentest Workflow 2.1 skill

What this skill tells your AI

The instructions your AI receives, as published by alicewe1/alice_skill in _modules/eni-pentest-workflow/SKILL.md and read by ahel’s review.

Persist the operator scope declaration and target inventory. Start in eni-solo-direct-v4: take the fastest high-signal inventory, fingerprint, trust-map, and broad template-driven validation route at the highest intensity recorded in the task ledger, then move immediately into deep manual reproduction of the strongest hypotheses. Combine OWASP WSTG/ASVS coverage, Nuclei-style breadth, and proxy/browser depth. Treat scanner output as a hypothesis until reproduced. Continue through evidence, impact, root cause, remediation, re-test, and delivery; use the smallest connected detail pack for each confirmed class.

Signals

GitHub stars
26
Forks
4
Last commit
Sep 2026
Advanced
Item type
skill
Key
eni-pentest-workflow
Source
github.com/alicewe1/alice_skill