SkillsLib.ai

Pen Testing Scope & Methodology Framework

Build defensible pen testing scopes, threat models & attack surface maps

4.0(34 reviews)
100+ downloads
Updated Sep 2026
Verified SafeSecurity VerifiedThis skill was analyzed by our AI security scanner for harmful content including data exfiltration, system manipulation, credential theft, and prompt injection. No threats were detected.

What You Can Do

You can generate detailed penetration testing scopes that integrate NIST, PTES, and ISO 27001 requirements with client business context. The framework helps you map attack surfaces across applications, infrastructure, and cloud environments; create defensible threat models for risk-based testing prioritization; develop rules of engagement documentation that prevent scope creep; and clearly delineate in-scope and out-of-scope items to reduce false findings and liability.

Features

Scope Definition

Automatically structure in-scope systems, excluded items, and testing boundaries aligned with client infrastructure topology

Threat Modeling

Generate risk-based threat models using business context to prioritize testing focus across attack vectors

Attack Surface Mapping

Inventory applications, APIs, infrastructure components, and integration points with severity classification

Rules of Engagement (ROE)

Create defensible ROE documentation covering testing hours, notification procedures, and escalation protocols

Governance Alignment

Incorporate NIST, PTES, and ISO 27001 controls into scope documentation for compliance and stakeholder confidence

Multi-Phase Planning

Structure staged scope expansion across penetration testing phases with clear progression criteria

Liability Protection

Document out-of-scope exclusions with justification to manage expectations and reduce disputed findings

Client Risk Context

Build scope based on actual business criticality, asset sensitivity, and regulatory exposure

Example Output

Example 1: E-commerce Platform Scope

  • In Scope: Web application (public facing), payment processing APIs, admin portal, database infrastructure
  • Out of Scope: Third-party payment processors (PCI-DSS certified separately), legacy reporting system (sunset Q2)
  • Threat Model: Focus on authentication bypass, injection attacks, privilege escalation
  • Testing Windows: Non-production hours, 8am-6pm EST, avoid payment processing peaks

Example 2: Hybrid Cloud Infrastructure

  • Attack Surface: AWS EC2 instances, RDS databases, on-premises Active Directory, hybrid VPN connectivity
  • Severity Classification: Database access (Critical), web application (High), internal services (Medium)
  • Rules of Engagement: Single point of contact for kill-switch activation, daily status reports, staged remediation windows
  • NIST Alignment: Maps to AC-2 (Access Control), SI-4 (Information System Monitoring), SI-6 (Security Function Verification)

What's Included

  • SKILL.md instruction file with framework overview and usage guidelines:
  • Scope Definition Template: structured format for in-scope systems, exclusions, and testing boundaries
  • Threat Model Worksheet: risk assessment grid mapping attack vectors to business assets
  • Attack Surface Inventory Checklist: comprehensive component discovery across applications, APIs, and infrastructure
  • Rules of Engagement (ROE) Template: client-facing documentation covering testing procedures, notification protocols, and escalation paths
  • Governance Alignment Matrix: NIST/PTES/ISO 27001 control mapping to scope elements

Who It's For

  • Penetration Testers/Ethical Hackers — structure engagements with defensible, detailed scopes that satisfy clients and reduce liability
  • Security Consultants — develop risk-based testing plans aligned with client governance frameworks and business context
  • Cybersecurity Managers — define testing boundaries for internal security assessments and vendor management
  • Risk & Compliance Officers — document scope boundaries that align with regulatory requirements (PCI-DSS, HIPAA, SOC 2)
  • Enterprise Security Teams — plan multi-phase penetration testing across hybrid infrastructure and complex environments

Best For

  • Initiating new external or internal penetration testing engagements
  • Mapping attack surfaces across legacy systems, cloud deployments, and hybrid infrastructure
  • Creating threat models for risk-based testing prioritization
  • Developing rules of engagement and scope boundaries with ambiguous or overlapping client requirements
  • Structuring multi-phase engagements with staged scope expansion
  • Documenting out-of-scope items to manage client expectations and reduce liability

You might also like

Athlete Performance Analyzer
$25
Athlete Performance Analyzer

Transform raw athlete metrics into actionable periodized training programs using evidence-based coaching frameworks. You can analyze performance data across multiple dimensions (strength, power, endurance, speed), identify patterns and performance gaps, generate customized training phases aligned with competition calendars, and provide data-driven performance feedback with specific recovery recommendations and injury risk assessments.

Athletic Trainer Return-to-Play Protocol Builder
$40
Athletic Trainer Return-to-Play Protocol Builder

Create structured return-to-play (RTP) protocols that incorporate evidence-based clinical frameworks, progressive loading stages, and objective outcome criteria. You'll generate injury-specific rehabilitation plans with clinical decision trees, risk stratification, and documentation templates that meet standard-of-care requirements. This accelerates protocol development from hours to minutes while ensuring consistency and clinical defensibility.

Exercise Research Protocol Design & Methodology Assessment
$25
Research3.8(5)
Exercise Research Protocol Design & Methodology Assessment

You can design rigorous exercise intervention research protocols from concept to IRB submission, ensuring alignment with peer-review standards and best practices. The skill helps you evaluate the methodological quality of exercise studies using structured frameworks, identifying potential biases, confounding variables, and design threats. You'll receive comprehensive assessments of study designs against CONSORT, STROBE, and discipline-specific standards.

Clinical Injury Assessment and Documentation Framework
$35
Clinical3.5(6)
Clinical Injury Assessment and Documentation Framework

You can systematically evaluate acute and chronic musculoskeletal injuries using validated clinical protocols and generate detailed, defensible documentation that meets professional standards. Claude structures your examination findings, produces rehabilitation recommendations grounded in current evidence, and organizes complex injury data into clear reports suitable for medical records and insurance submission.

Team Dynamics Assessment and Intervention Playbook
$30
Team Dynamics Assessment and Intervention Playbook

You can conduct comprehensive assessments of team cohesion, identify specific dysfunctional group processes like poor communication or misaligned goals, and receive tailored intervention strategies grounded in organizational psychology research. The skill generates actionable recommendations that strengthen psychological safety, improve collaboration, and boost overall team performance.

$40
Team Dynamics Assessment and Intervention Framework

This skill helps you systematically diagnose root causes of team dysfunction using structured assessment protocols, then design evidence-based interventions tailored to specific cohesion issues. You'll identify patterns across trust, communication, role clarity, and psychological safety. The result is a prioritized action plan that addresses the most impactful gaps first.

$25
Clinical3.5(4)
Clinical Assessment Documentation & Protocol Builder

You can create comprehensive clinical assessment protocols, standardized documentation templates, and regulatory-compliant procedures tailored to your specialty or department. This skill automates the development of clinical forms, assessment checklists, and protocol workflows that ensure consistent, evidence-based practice across your organization.

Industrial Workplace Injury Assessment & Prevention Protocol
$45
Industrial Workplace Injury Assessment & Prevention Protocol

Generate comprehensive injury assessments that analyze incident root causes, identify hazards, and quantify risk across your facility. Create detailed prevention protocols and return-to-work documentation that meet OSHA standards and occupational health regulations. Your plans integrate safety best practices with your specific workplace conditions to reduce incident rates and liability.

$25.00