PE

pentest-redteam-ops

Coordinates security testing and engagement sequences while enforcing compliance with industry standards.

Install

mkdir -p .claude/skills/pentest-redteam-ops && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/17039" && unzip -o skill.zip -d .claude/skills/pentest-redteam-ops && rm skill.zip

Installs to .claude/skills/pentest-redteam-ops

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Coordinate autonomous pentest skills with dependency enforcement, deconfliction, and emergency stop controls.
109 charsno explicit “when” trigger
Intermediate

Key capabilities

  • Validate scope before any active action
  • Run authorized security checks aligned to PTES, OWASP WSTG, NIST SP 800-115, and MITRE ATT&CK
  • Write findings in canonical finding_schema format with reproducible PoC notes
  • Honor dry-run mode and require explicit authorization for live execution
  • Export deterministic artifacts for downstream skill consumption

How it works

The skill executes a Python script with specified parameters to run authorized security testing, validate scope, and generate structured reports.

Inputs & outputs

You give it
Scope definition (scope.json), target, input path, output path, format, dry-run flag
You get back
engagement-log.json, redteam-timeline.json, orchestration-report.json

When to use pentest-redteam-ops

  • Run an authorized security assessment
  • Document security findings
  • Generate a pentest timeline
  • Validate target scope before testing

About this skill

Pentest Red Team Ops

Stage

  • PTES: all
  • MITRE: Full ATT&CK chain

Objective

Run full engagement sequencing and produce timeline and status dashboards.

Required Workflow

  1. Validate scope before any active action and reject out-of-scope targets.
  2. Run only authorized checks aligned to PTES, OWASP WSTG, NIST SP 800-115, and MITRE ATT&CK.
  3. Write findings in canonical finding_schema format with reproducible PoC notes.
  4. Honor dry-run mode and require explicit --i-have-authorization for live execution.
  5. Export deterministic artifacts for downstream skill consumption.

Execution

python skills/pentest-redteam-ops/scripts/redteam_ops.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run

Outputs

  • engagement-log.json
  • redteam-timeline.json
  • orchestration-report.json

References

  • references/tools.md
  • skills/autonomous-pentester/shared/scope_schema.json
  • skills/autonomous-pentester/shared/finding_schema.json

Legal and Ethical Notice

WARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.

When not to use it

  • When unauthorized security testing is requested
  • When the target is out of scope
  • When findings do not need to be in a canonical format

Prerequisites

scope.json filefinding_schema.json file

Limitations

  • The skill requires explicit authorization for live execution
  • The skill only runs authorized checks
  • The skill requires findings to be in a specific schema format

How it compares

This skill enforces a structured, authorized, and documented approach to pentesting, unlike ad-hoc security checks.

Compared to similar skills

pentest-redteam-ops side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
pentest-redteam-ops (this skill)05moReviewIntermediate
reverse-engineering-tools734moNo flagsAdvanced
game-hacking-techniques423moNo flagsAdvanced
solidity-security153moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

game-hacking-techniques

gmh5225

Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.

42128

solidity-security

wshobson

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

15115

1password

openclaw

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

2799

senior-security

davila7

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

3191

ghidra

mitsuhiko

Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.

16105

Search skills

Search the agent skills registry