
Pen Testing Scope & Rules of Engagement Builder
Build legally defensible penetration testing scope and rules of engagement
What You Can Do
You'll create formally documented penetration testing scope and ROE frameworks that establish clear attack surface boundaries, authorization limits, and testing methodology parameters. The skill generates client-ready documents that address regulatory requirements, define in-scope/out-of-scope systems, document restraint parameters, and create decision matrices for edge cases—reducing typical scope negotiation from 8-12 hours to 2-3 hours while protecting against legal disputes and failed audits.
Features
precisely map IP ranges, systems, applications, and environments included/excluded from testing
establish explicit written consent and legal protection mechanisms for testing activities
specify testing techniques, tools, and restraint parameters clients will accept
embed PCI-DSS, HIPAA, FedRAMP, SOC 2, and industry-specific requirements into scope
pre-define how to handle uncertain scenarios (third-party systems, shared infrastructure, data handling)
document all scope agreements for compliance validation and dispute prevention
address cloud infrastructure, multi-tenant systems, and third-party dependencies
include testing constraints and client acknowledgments that reduce legal exposure
Example Output
Example 1: Scope Definition Output
In-Scope Assets:
- 10.0.0.0/16 internal network
- prod-app-01 through prod-app-05 servers
- api.client.com and api-staging.client.com
- AWS RDS databases (prod only, non-prod excluded)
Out-of-Scope:
- Payment processing systems (PCI-DSS limits)
- Third-party SaaS integrations without written consent
- VoIP/telephony infrastructure
- Physical security testing (separate engagement)
Example 2: Rules of Engagement Excerpt
Testing Window: 9 AM - 5 PM EST, Monday-Friday only
Data Handling: No extraction of PII; document presence only
DoS Testing: Strictly prohibited except isolated lab environment
Access Escalation: Testing permitted; must restore original privilege level
Client Escalation Point: Contact [Name] if unexpected system behavior occurs
What's Included
- SKILL.md instruction file with penetration testing scope methodology:
- ROE Template: standardized Rules of Engagement framework for client approval
- Scope Definition Worksheet: attack surface mapping checklist (systems, networks, environments)
- Regulatory Compliance Checklist: PCI-DSS, HIPAA, FedRAMP, SOC 2 alignment requirements
- Edge Case Decision Matrix: handling guides for third-party systems, cloud infrastructure, and ambiguous boundaries
- Legal Protection Clauses: pre-written authorization and liability limitation language
Who It's For
- Penetration testers and ethical hackers conducting client engagements
- Security consultants managing scope negotiation with enterprise clients
- GRC (Governance, Risk, Compliance) professionals formalizing security testing programs
- Chief Information Security Officers (CISOs) defining testing frameworks
- Legal and compliance teams reviewing penetration testing authorization
Best For
- Initial scope documentation for new penetration testing engagements
- Formalizing verbally agreed scope into legally defensible written agreements
- Multi-environment testing (cloud, hybrid, third-party dependencies)
- Regulatory compliance testing (PCI-DSS, HIPAA, FedRAMP, SOC 2 audits)
- Scope dispute prevention and audit trail documentation
- Social engineering, physical security, or sensitive data handling testing







