Zen Pentesting Workflow Skill

SkillSecurity

Runs penetration tests against targets by chaining reconnaissance, vulnerability scanning, exploitation, and report steps.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Zen Pentesting Workflow Skill skill

About this skill

πŸ›‘βš”οΈAI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reportingπŸ›‘βš”οΈ

What this skill tells your AI

The instructions your AI receives, as published by shadd0wtaka/zen-ai-pentest in skills/zen-workflow/SKILL.md and read by ahel’s review.

Complete end-to-end pentesting workflow using the Zen-Ai-Pentest platform.

Quick Start

# 1. Start all services
docker compose up -d
# or: ./scripts/start-zen.sh

# 2. Run full audit via CLI
deep-audit --target example.com --phases recon,scan,exploit,report

# 3. View dashboard at http://localhost:8501
# 4. Export report: deep-report --scan-id wf-abc123 --format pdf

Multi-Phase Workflow

Phase 1: Reconnaissance

deep-recon --target example.com --output recon.json

# What happens:
# - Subdomain enumeration (subfinder, amass, dnsx)
# - Port scanning (nmap, masscan)
# - Technology fingerprinting (whatweb, wappalyzer)
# - Screenshot (gowitness, aquatone)
# - OSINT (shodan, censys integration)

Phase 2: Scanning & Vulnerability Detection

deep-audit --target example.com --phases scan

# Tools engaged:
# - nuclei (community + custom templates)
# - web vulnerability (sqlmap, nikto, zap)
# - network (netexec, crackmapexec)
# - cloud (scoutsuite, prowler)

Phase 3: Exploitation (requires --force)

deep-audit --target example.com --phases exploit

# Metasploit: auto-match CVEs to modules
# Custom payload generation (msfvenom)
# Credential testing via netexec

Phase 4: Reporting

deep-report --scan-id YOUR-ID --format pdf
deep-report --scan-id YOUR-ID --format html

Custom Workflow Script

#!/usr/bin/env bash
# custom-audit.sh
set -euo pipefail

TARGET="$1"
WORKSPACE="./workspace/${TARGET}"

mkdir -p "$WORKSPACE"

echo "=== Phase 1: Network Discovery ==="
nmap -sV -sC -oA "$WORKSPACE/nmap" "$TARGET"

echo "=== Phase 2: Web Recon ==="
gobuster dir -u "https://$TARGET" -w wordlist.txt -o "$WORKSPACE/gobuster.txt"

echo "=== Phase 3: Vulnerability Scan ==="
nuclei -u "https://$TARGET" -o "$WORKSPACE/nuclei.txt"

echo "=== Phase 4: AI Analysis ==="
python -c "
from agents.react_agent import ReActAgent
agent = ReActAgent(max_iterations=5)
print(agent.run(target='$TARGET', objective='Analyze findings in $WORKSPACE'))
"

Docker Service Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚                   Zen Network                    β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚  β”‚ Terminal  β”‚  β”‚ WhatsApp Bot β”‚  β”‚ OmniRoute β”‚ β”‚
β”‚  β”‚ :23000   β”‚  β”‚ :23001       β”‚  β”‚ :20128    β”‚ β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β”‚  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚
β”‚  β”‚ Hermes   β”‚  β”‚ VPN Proxy    β”‚  β”‚ WG Proxy  β”‚ β”‚
β”‚  β”‚ :23002   β”‚  β”‚ :23003       β”‚  β”‚ :23004    β”‚ β”‚
β”‚  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Runbook: Web Application Pentest

  1. Scope definition: agent_coordinator.create_workflow(target, phases=["recon"])
  2. Passive recon: WHOIS, DNS, Shodan, certificate transparency
  3. Active recon: subdomain brute-force, port scan, tech fingerprint
  4. Vulnerability scan: nuclei, custom template matching
  5. Manual testing: ReAct agent-driven follow-up on findings
  6. Exploitation: Metasploit + custom payloads (--force + admin approval)
  7. Reporting: risk_engine scoring β†’ PDF/HTML report generation
  8. Remediation: CVSS-prioritized fix recommendations

Signals

GitHub stars
469
Forks
81
Last commit
Sep 2026
Advanced
Item type
skill
Key
zen-workflow
Source
github.com/shadd0wtaka/zen-ai-pentest