Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fb0sh/pentester/pentester-gen-reportnpx skills add fb0sh/pentester --skill pentester-gen-reportgit clone --depth 1 https://github.com/fb0sh/pentesterWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00050 | $0.00442 |
| Opus 5 | $0.00025 | $0.00221 |
| Sonnet 5 | $0.00010 | $0.00088 |
| Haiku 4.5 | $0.00005 | $0.00044 |
Grade A, and why
pentester-gen-report scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
gen-report
Procedure: .agents/phases/06-reporting.md
Fill interface (sole): .agents/REPORT-SKELETON.md
Optional wording: .agents/knowledge/reporting/report-wording-depth.md
# Assemble data sections (findings table · rollup · Evidence index · coverage)
node .agents/schema/assemble-report.js ${ID} # paste under SKELETON 1.3 / 5 / 8
# Quality gate (Schema) — also fails if a Verified Vulnerability is omitted
node .agents/schema/check-report.js ${ID}
# Full contract + optional write seam
node .agents/schema/validate-target-schema.js ${ID} --strict-summary --check-report
node .agents/schema/validate-target-schema.js ${ID} --strict-summary --check-report --stamp-chain
# Client delivery bundle (attestation + index; Evidence indexed in place)
node .agents/schema/deliver.js ${ID}
# Remediation retest (when this run re-tests a prior engagement of the same Target):
# diff the baseline run → fixed / still-open / new, write retest.md
node .agents/schema/retest.js --baseline <prior-id> --current ${ID} --write
assemble-report.js→ data sections; fill SKELETON narrative in user language- Read all manifests (incl. optional 1b) for context
- Quality + validate (consistency: every Verified Vulnerability appears in the Report)
- Stamp chain only when intentionally finishing phase 6
deliver.js→delivery/for the client- Retest only:
retest.jsvs the baseline run →retest.md(see CONTEXT Retest)
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 40 lines · 50 tokens per session scan A 5d3d90287852
pentester-gen-report is a skill published in the GitHub repository fb0sh/pentester (23 stars, last pushed 1mo ago), licensed MIT. It adds 50 tokens to every session and 442 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
transilience-report-style
Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.
firewall-review
Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…
pentest-engagement
Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…
coordination
Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.
hackerone
HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.
pci-secure-software
Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation. Deterministically enumerates every applicable Test Requirement from a pinned catalog, gathers source/doc evidence, and emits an evidence-bound per-requirement verdict (MET / NOTMET /…