pentest-verification
SkillSecurityYour AI records only evidence-backed findings during penetration tests and keeps unproven leads marked as tentative. pentest-verification is a skill that sets these strict verification rules for security testing work. It also blocks vague speculation and saves negative results, so the record reflects what was actually proven.
Available today. Use it from your connected AI after setup.
No other account needed.
After adding it, have your AI write project facts, validate findings, or run security tests as usual. The rules apply each time it records a result, so anything without evidence stays tentative instead of confirmed.
Then ask your AI: use the pentest-verification skill
What your AI can do with it
- Require evidence before marking any finding as confirmed
- Keep unproven leads separate as tentative
- Treat search matches as leads, not confirmed vulnerabilities
- Reject vague speculation when recording results
- Record negative results alongside confirmed ones
- Apply the same verification rules when writing project facts
What this skill tells your AI
The instructions your AI receives, as published by aipentest/cyberstrikeai in skills/pentest-verification/SKILL.md and read by ahel’s review.
验证铁律(全系统最高规则,违反即幻觉)
1. 搜索结果 ≠ 漏洞。公开情报/PoC线索不可直接 record_vulnerability,也不可写 confidence=confirmed;
可写 tentative 的 note/finding 线索,或只留本轮待验证方向,验证后再落库。
2. 每个 confirmed Fact 必须在 body(或关联漏洞 POC)附验证证据:命令输出/HTTP响应/文件内容/回连记录。
3. 禁止"可能/疑似/推测XX" —— 要么确认+证据写 Fact/漏洞,要么 tentative 标明线索,要么不报。
4. 验证失败 → 写负结果 Fact("测了XX,无可利用漏洞"),用 upsert_project_fact 落库,防止重复尝试。
5. 想象力拉满(敢想全网没人串过的链),单步验证零容忍(每段用真实证据钉死后再 confirmed)。
与黑板工具对齐见 pentest-blackboard。
Signals
- GitHub stars
- 7k
- Forks
- 1k
- Last commit
- Sep 2026
Others that do the same job
Advanced
- Catalog kind
- skill
- Gateway key
pentest-verification- Source
- github.com/aipentest/cyberstrikeai