Zen Pentesting Workflow Skill
SkillSecurityLets your agent run automated penetration tests, scan for vulnerabilities, and produce compliance reports.
Use Zen Pentesting Workflow Skill in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Zen Pentesting Workflow Skill and connect your AI. About a minute.
Also: Claude Code Β· Cursor Β· Codex
Then ask your AI: use the Zen Pentesting Workflow Skill skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
About this skill
π‘βοΈAI-Powered Penetration Testing Framework with automated vulnerability scanning, multi-agent system, and compliance reportingπ‘βοΈ
What this skill tells your AI
The instructions your AI receives, as published by shadd0wtaka/zen-ai-pentest in skills/zen-workflow/SKILL.md and read by ahelβs review.
Complete end-to-end pentesting workflow using the Zen-Ai-Pentest platform.
Quick Start
# 1. Start all services
docker compose up -d
# or: ./scripts/start-zen.sh
# 2. Run full audit via CLI
deep-audit --target example.com --phases recon,scan,exploit,report
# 3. View dashboard at http://localhost:8501
# 4. Export report: deep-report --scan-id wf-abc123 --format pdf
Multi-Phase Workflow
Phase 1: Reconnaissance
deep-recon --target example.com --output recon.json
# What happens:
# - Subdomain enumeration (subfinder, amass, dnsx)
# - Port scanning (nmap, masscan)
# - Technology fingerprinting (whatweb, wappalyzer)
# - Screenshot (gowitness, aquatone)
# - OSINT (shodan, censys integration)
Phase 2: Scanning & Vulnerability Detection
deep-audit --target example.com --phases scan
# Tools engaged:
# - nuclei (community + custom templates)
# - web vulnerability (sqlmap, nikto, zap)
# - network (netexec, crackmapexec)
# - cloud (scoutsuite, prowler)
Phase 3: Exploitation (requires --force)
deep-audit --target example.com --phases exploit
# Metasploit: auto-match CVEs to modules
# Custom payload generation (msfvenom)
# Credential testing via netexec
Phase 4: Reporting
deep-report --scan-id YOUR-ID --format pdf
deep-report --scan-id YOUR-ID --format html
Custom Workflow Script
#!/usr/bin/env bash
# custom-audit.sh
set -euo pipefail
TARGET="$1"
WORKSPACE="./workspace/${TARGET}"
mkdir -p "$WORKSPACE"
echo "=== Phase 1: Network Discovery ==="
nmap -sV -sC -oA "$WORKSPACE/nmap" "$TARGET"
echo "=== Phase 2: Web Recon ==="
gobuster dir -u "https://$TARGET" -w wordlist.txt -o "$WORKSPACE/gobuster.txt"
echo "=== Phase 3: Vulnerability Scan ==="
nuclei -u "https://$TARGET" -o "$WORKSPACE/nuclei.txt"
echo "=== Phase 4: AI Analysis ==="
python -c "
from agents.react_agent import ReActAgent
agent = ReActAgent(max_iterations=5)
print(agent.run(target='$TARGET', objective='Analyze findings in $WORKSPACE'))
"
Docker Service Architecture
ββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Zen Network β
β ββββββββββββ ββββββββββββββββ βββββββββββββ β
β β Terminal β β WhatsApp Bot β β OmniRoute β β
β β :23000 β β :23001 β β :20128 β β
β ββββββββββββ ββββββββββββββββ βββββββββββββ β
β ββββββββββββ ββββββββββββββββ βββββββββββββ β
β β Hermes β β VPN Proxy β β WG Proxy β β
β β :23002 β β :23003 β β :23004 β β
β ββββββββββββ ββββββββββββββββ βββββββββββββ β
ββββββββββββββββββββββββββββββββββββββββββββββββββββ
Runbook: Web Application Pentest
- Scope definition:
agent_coordinator.create_workflow(target, phases=["recon"]) - Passive recon: WHOIS, DNS, Shodan, certificate transparency
- Active recon: subdomain brute-force, port scan, tech fingerprint
- Vulnerability scan: nuclei, custom template matching
- Manual testing: ReAct agent-driven follow-up on findings
- Exploitation: Metasploit + custom payloads (--force + admin approval)
- Reporting: risk_engine scoring β PDF/HTML report generation
- Remediation: CVSS-prioritized fix recommendations
Signals
- GitHub stars
- 470
- Forks
- 82
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
zen-workflow- Source
- github.com/shadd0wtaka/zen-ai-pentest
github.com/shadd0wtaka/zen-ai-pentest
Related picks
Skill Β· nvidia
The pick for Infrahttp-to-https
Skill Β· thedaviddias
The pick for Infraowasp-security
Skill Β· davila7
The pick for Web (OWASP)security-and-hardening
Skill Β· addyosmani
The pick for Web (OWASP)docker-agent-run
Skill Β· docker
The pick for Dockerdocker-sandbox
Skill Β· joelhooks
The pick for Docker