
Penetration Testing Planner
Generate structured penetration testing plans aligned with OWASP methodology
What You Can Do
You can generate formal penetration testing plans that transform vague security testing requests into actionable documents. The skill defines clear scope boundaries, maps test cases to OWASP Top 10 and industry frameworks, recommends appropriate tools and methodologies, and specifies deliverable formats—ensuring consistent, defensible testing approaches that stakeholders and development teams can understand and act on.
Features
Establish in/out of scope targets, testing windows, constraints, and business objectives
Generate specific attack vectors mapped to OWASP Top 10, CVSS scoring, and industry standards
Recommend tools, techniques, and testing phases (reconnaissance, scanning, exploitation, reporting)
Tailor plans to PCI-DSS, HIPAA, SOC 2, and other compliance requirements
Define proof-of-concept requirements, remediation timelines, and report structure
Map test cases to identified threats and business risks
Create sign-off templates and risk-rating frameworks for non-technical audiences
Example Output
Example 1: Web Application Penetration Test Plan
Scope: E-commerce platform (web UI, REST API, authentication system)
Out of Scope: Third-party payment processors, legacy batch systems
Test Window: 2 weeks, off-peak hours (11 PM–6 AM EST)
Phase 1: Reconnaissance & Enumeration
- Identify entry points, tech stack, API endpoints
- Tools: Burp Suite, OWASP ZAP
Phase 2: Vulnerability Testing
- OWASP A01:2021 Broken Access Control → Test privilege escalation, horizontal/vertical access
- OWASP A03:2021 Injection → SQL/NoSQL/LDAP injection payloads
- OWASP A07:2021 Cross-Site Scripting → Stored/reflected XSS vectors
Deliverables: Executive summary, detailed findings (CVSS scored), remediation roadmap, raw evidence (screenshots, logs, payloads)
Example 2: API Security Test Plan
Target: RESTful GraphQL API (v2.1)
Test Focus: Authentication bypass, rate limiting, data exposure, business logic flaws
Test Cases:
- Missing authentication on /admin endpoints
- JWT token manipulation and expiration bypass
- GraphQL query depth exploitation (DoS)
- Unauthorized cross-tenant data access
Expected Output: API security report with exploit proof-of-concepts and remediation priority matrix
What's Included
- penetration-testing-planner.md: Core skill instructions and prompt templates
- Penetration Test Plan Template: Structured markdown outline with scope, methodology, and deliverable sections
- OWASP Test Case Checklist: Pre-built mapping of OWASP Top 10 to specific test cases and tools
- Scope Definition Worksheet: Questions to clarify in/out of scope, stakeholder requirements, and regulatory drivers
- Risk Rating & Remediation Matrix: CVSS scoring framework and prioritization for reporting
Who It's For
- Security Engineers & Penetration Testers — Structure engagements and ensure consistent, defensible methodologies
- QA/Test Engineers — Plan security-focused test phases alongside functional testing
- Security Consultants — Generate formal scope documents and statements of work for client sign-off
- AppSec & DevSecOps Leads — Define internal security testing programs aligned with compliance requirements
- Development Managers — Understand what's being tested, why, and what remediation looks like
Best For
- Planning new penetration test engagements for web applications or APIs
- Defining scope and methodology for regulatory compliance assessments (PCI-DSS, HIPAA, SOC 2)
- Creating actionable test plans from high-level security requirements
- Documenting testing rationale and evidence requirements for stakeholder sign-off
- Standardizing penetration testing approaches across internal security teams or consulting practices







