pentest-coordinator
Coordinate Authorized Lab Penetration Tests
Penetration testing labs require careful state tracking across reconnaissance, exploitation, and privilege escalation. This skill coordinates an authorized lab workflow with structured notes, attempts, and completion criteria.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "pentest-coordinator" from https://skillstore.io/skills/charleskozel-pentest-coordinator.md and its manifest at https://skillstore.io/api/skills/charleskozel-pentest-coordinator/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "pentest-coordinator". Start a scoped lab test for a provided training target.
Expected outcome:
The skill creates a phase plan, records the target scope, lists initial reconnaissance goals, and defines when to pause.
Using "pentest-coordinator". I found a web upload form and several failed password attempts.
Expected outcome:
The skill separates web testing from credential testing, records failed attempts, and recommends a scoped next hypothesis.
Using "pentest-coordinator". Review my Active Directory lab findings for privilege escalation ideas.
Expected outcome:
The skill groups findings by user permissions, Kerberos indicators, certificate services, and password policy evidence.
Security Audit
CriticalThe scanner produced some markdown-fence false positives, but the skill intent is clearly high risk. It coordinates autonomous network scanning, exploitation, credential attacks, privilege escalation, and anti-stop behavior until user and root flags are captured. The skill should not be published without major safety controls and removal of autonomous offensive execution.
Confirmed security concerns (13)
Show all 13 confirmed findings
Capability review items (100)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
⚙️ External commands (105)
🌐 Network access (7)
📁 Filesystem access (2)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/charleskozel-pentest-coordinator/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/charleskozel-pentest-coordinator?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/charleskozel-pentest-coordinator?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/charleskozel-pentest-coordinator/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/charleskozel-pentest-coordinator.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA · BibTeX · CFF)
APA citation
CharlesKozel. (2026). pentest-coordinator security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/charleskozel-pentest-coordinator/audits/8BibTeX citation
@techreport{charleskozel-charleskozel-pentest-coordinator-2026,
author = {CharlesKozel},
title = {pentest-coordinator security audit report (audit version 8)},
institution = {Skillstore},
year = {2026},
number = {8},
url = {https://skillstore.io/skills/charleskozel-pentest-coordinator/audits/8},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "pentest-coordinator security audit report (audit version 8)"
version: "unspecified"
type: report
authors:
- name: "CharlesKozel"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/charleskozel-pentest-coordinator/audits/8"
identifiers:
- type: other
value: "skillstore:charleskozel-pentest-coordinator:audit:8"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Run CTF Lab Exercises
Guide a learner through structured notes and phase tracking during a permitted capture-the-flag target.
Organize Internal Red Team Labs
Track attack hypotheses, failed attempts, and escalation paths inside a controlled corporate lab.
Teach Penetration Test Methodology
Demonstrate how reconnaissance findings connect to exploitation and privilege escalation decisions.
Try These Prompts
Start an authorized lab assessment for target [target]. Record scope, assumptions, initial phase, and safe stop conditions.
Review my current lab notes. Summarize known services, failed paths, likely next vectors, and any safety concerns.
Given these authorized Active Directory lab findings, create a prioritized investigation plan with evidence needed for each hypothesis.
Evaluate this lab workflow for repeated methods, unsafe assumptions, missing authorization checks, and better defensive documentation.
Best Practices
- Use the skill only against systems where written authorization and scope are clear.
- Add human approval before every network, exploitation, credential, or privilege escalation action.
- Keep a defensible audit trail of findings, commands, timestamps, and decisions.
Avoid
- Do not use the skill on public or third-party targets without explicit permission.
- Do not allow autonomous execution without user confirmation and rate limits.
- Do not treat flag capture as more important than safety, legality, or scope boundaries.
Frequently Asked Questions
Is this skill safe to use on real systems?
Does it execute commands by itself?
Can it help with defensive training?
Does it support Active Directory labs?
What should users prepare first?
Why is marketplace review important for this skill?
Developer Details
Author
CharlesKozelLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
dd4a3ef9f20ddf38830950b4bb713df96b431fd6
Maintenance freshness
7/18/2026
Usage
7 downloads · 203 views
File structure