pentest-redteam-ops
Coordinates security testing and engagement sequences while enforcing compliance with industry standards.
Install
mkdir -p .claude/skills/pentest-redteam-ops && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/17039" && unzip -o skill.zip -d .claude/skills/pentest-redteam-ops && rm skill.zipInstalls to .claude/skills/pentest-redteam-ops
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Coordinate autonomous pentest skills with dependency enforcement, deconfliction, and emergency stop controls.Key capabilities
- →Validate scope before any active action
- →Run authorized security checks aligned to PTES, OWASP WSTG, NIST SP 800-115, and MITRE ATT&CK
- →Write findings in canonical finding_schema format with reproducible PoC notes
- →Honor dry-run mode and require explicit authorization for live execution
- →Export deterministic artifacts for downstream skill consumption
How it works
The skill executes a Python script with specified parameters to run authorized security testing, validate scope, and generate structured reports.
Inputs & outputs
When to use pentest-redteam-ops
- →Run an authorized security assessment
- →Document security findings
- →Generate a pentest timeline
- →Validate target scope before testing
About this skill
Pentest Red Team Ops
Stage
- PTES: all
- MITRE: Full ATT&CK chain
Objective
Run full engagement sequencing and produce timeline and status dashboards.
Required Workflow
- Validate scope before any active action and reject out-of-scope targets.
- Run only authorized checks aligned to PTES, OWASP WSTG, NIST SP 800-115, and MITRE ATT&CK.
- Write findings in canonical finding_schema format with reproducible PoC notes.
- Honor dry-run mode and require explicit --i-have-authorization for live execution.
- Export deterministic artifacts for downstream skill consumption.
Execution
python skills/pentest-redteam-ops/scripts/redteam_ops.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run
Outputs
engagement-log.jsonredteam-timeline.jsonorchestration-report.json
References
references/tools.mdskills/autonomous-pentester/shared/scope_schema.jsonskills/autonomous-pentester/shared/finding_schema.json
Legal and Ethical Notice
WARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.
When not to use it
- →When unauthorized security testing is requested
- →When the target is out of scope
- →When findings do not need to be in a canonical format
Prerequisites
Limitations
- →The skill requires explicit authorization for live execution
- →The skill only runs authorized checks
- →The skill requires findings to be in a specific schema format
How it compares
This skill enforces a structured, authorized, and documented approach to pentesting, unlike ad-hoc security checks.
Compared to similar skills
pentest-redteam-ops side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| pentest-redteam-ops (this skill) | 0 | 5mo | Review | Intermediate |
| reverse-engineering-tools | 73 | 4mo | No flags | Advanced |
| game-hacking-techniques | 42 | 3mo | No flags | Advanced |
| solidity-security | 15 | 3mo | No flags | Intermediate |
Try saying
Example prompts that trigger this skill in your AI assistant.
You might also like
reverse-engineering-tools
gmh5225
Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.
game-hacking-techniques
gmh5225
Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.
solidity-security
wshobson
Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.
1password
openclaw
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
senior-security
davila7
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
ghidra
mitsuhiko
Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.