🛡️
QualityPython

Penetration Testing Checklist

by ThamJiaHe

Penetration Testing Checklist is a Quality skill for Claude Code, published by ThamJiaHe in claude-code-handbook.

201 stars22 forkson ThamJiaHe/claude-code-handbookAdded 2026/09/05Repository updated 2026/04/19
aianthropic-claudeclaudeclaude-aiclaude-codeclaude-skillsllmmcpprompt-engineering
Install in seconds
Install Penetration Testing Checklist
Copy Penetration Testing Checklist into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/ThamJiaHe/claude-code-handbook/tree/main/skills/examples ~/.claude/skills/examples

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/ThamJiaHe/claude-code-handbook.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
skills/examples/penetration-testing-skill.md in ThamJiaHe/claude-code-handbook
Installs to
~/.claude/skills/examples
Collection
One of 25 skills cataloged from this repository
Category
Quality1662 skills

What Penetration Testing Checklist does

Penetration Testing Checklist provides a structured workflow for authorized web application security testing, including recon, scanning, exploitation validation, and reporting. Use it for pentests, bug bounties, or pre-deployment security checks.

Penetration Testing Checklist is cataloged under Quality on DirSkills. Penetration Testing Checklist comes from a repository tagged ai, anthropic-claude, claude, claude-ai and claude-code.

Documentation

README

Penetration Testing Checklist

Systematic methodology for authorized web application security testing.

IMPORTANT: Only use this skill for authorized security testing — pentesting engagements, bug bounty programs, CTF challenges, or testing your own applications.

Overview

This skill provides a structured pentest workflow:

  1. Reconnaissance — Gather information about the target
  2. Scanning — Identify attack surface and vulnerabilities
  3. Exploitation — Validate vulnerabilities (with permission)
  4. Post-Exploitation — Assess impact and lateral movement
  5. Reporting — Document findings with remediation guidance

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Penetration Testing Checklist

  • What else does ThamJiaHe publish alongside Penetration Testing Checklist?

    Penetration Testing Checklist is one of 25 skills that DirSkills catalogs from ThamJiaHe/claude-code-handbook, the repository it ships in. Its siblings there include API Development, API Security Hardening and AWS Cloud Infrastructure. Each one is a separate skill with its own page in this directory, installs the same way Penetration Testing Checklist does, and is maintained by ThamJiaHe in that same repository. The rest of the collection is listed on the ThamJiaHe/claude-code-handbook page.

  • How does Penetration Testing Checklist compare to other Quality skills?

    Penetration Testing Checklist ranks #1528 by stars among the 1662 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Penetration Testing Checklist against them. Open each page to compare what they document and how they install.

More from ThamJiaHe/claude-code-handbook

Penetration Testing Checklist is one of 25 skills cataloged on DirSkills from ThamJiaHe/claude-code-handbook.

See all 25 skills
🔌
48m ago

API Development

API Development enforces REST API practices like proper status codes, RFC 7807 error responses, input validation, and centralized error handling. Use it when building routes, handling failures, or shaping consistent JSON responses.
Automation
20122
🛡️
48m ago

API Security Hardening

API Security Hardening helps secure REST and GraphQL APIs against common attack vectors. Use it when adding authentication, validating input, rate limiting, handling uploads, or exposing endpoints to outside consumers.
AI Engineering
20122
☁️
48m ago

AWS Cloud Infrastructure

AWS Cloud Infrastructure deploys Node.js apps on AWS with EC2, RDS, IAM, security groups, and monitoring. Use it when setting up cloud infrastructure, databases, secrets, or cost-conscious production hosting.
DevOps
20122
🛠️
48m ago

Build Error Resolver

Build Error Resolver fixes build failures, TypeScript errors, and lint issues with minimal diffs. Use it when CI breaks or a build needs to be made green quickly.
Quality
20122
🛡️
48m ago

Cybersecurity Threat Modeling

Cybersecurity Threat Modeling applies STRIDE to application architecture to identify spoofing, tampering, disclosure, DoS, and privilege risks. Use it when designing systems, reviewing architecture, or assessing security posture.
Quality
20122
🐳
48m ago

Docker Containerization

Docker Containerization provides patterns for multi-stage Dockerfiles, compose setups, and container security hardening. Use it when building, optimizing, or deploying containerized apps.
DevOps
20122