Source aware whitebox testing
Skill xAmirHamza77/PenKit51/skills/source-aware-whitebox-testing
Coordination playbook for source-aware white-box testing with static triage and dynamic validationFrom its SKILL.md
npx -y skills add xAmirHamza77/PenKit51 --skill source-aware-whitebox-testingAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
5.1 KB, ~1.1k tokens by cl100k_base, as published. Nobody here has run it
Source Aware Whitebox Testing
penkit51 AI — professional penetration testing skill pack. Authorized testing only.
Deep Exploitation Guide
Source-Aware White-Box Coordination
Use this coordination playbook when repository source code is available.
Objective
Increase white-box coverage by combining source-aware triage with dynamic validation. Source-aware tooling is expected by default when source is available.
Recommended Workflow
- Build a quick source map before deep exploitation, including at least one AST-structural pass (
sgortree-sitter) scoped to relevant paths.- For
sgbaseline, derivesg-targets.txtfromsemgrep.jsonscope first (paths.scanned, fallback to uniqueresults[].path) and runxargs ... sg runon that list. - Only fall back to path heuristics when semgrep scope is unavailable.
- For
- Run first-pass static triage to rank high-risk paths.
- Use triage outputs to prioritize dynamic PoC validation.
- Keep findings evidence-driven: no report without validation.
Source-Aware Triage Stack
semgrep: fast security-first triage and custom pattern scansast-grep(sg): structural pattern hunting and targeted repo mappingtree-sitter: syntax-aware parsing support for symbol and route extractiongitleaks+trufflehog: complementary secret detection (working tree and history coverage)trivy fs: dependency, misconfiguration, license, and secret checks
Coverage target per repository:
- one
semgreppass - one AST structural pass (
sgand/ortree-sitter) - one secrets pass (
gitleaksand/ortrufflehog) - one
trivy fspass
Agent Delegation Guidance
- Keep child agents specialized by vulnerability/component as usual.
- For source-heavy subtasks, prefer creating child agents with
source_aware_sastskill. - Use source findings to shape payloads and endpoint selection for dynamic testing.
Validation Guardrails
- Static findings are hypotheses until validated.
- Dynamic exploitation evidence is still required before vulnerability reporting.
- Keep scanner output concise, deduplicated, and mapped to concrete code locations.
Platform Methodology
Source Aware Whitebox Testing
penkit51 AI — professional penetration testing skill pack. Authorized testing only.
Deep Exploitation Guide
Source-Aware White-Box Coordination
Use this coordination playbook when repository source code is available.
Objective
Increase white-box coverage by combining source-aware triage with dynamic validation. Source-aware tooling is expected by default when source is available.
Recommended Workflow
- Build a quick source map before deep exploitation, including at least one AST-structural pass (
sgortree-sitter) scoped to relevant paths.- For
sgbaseline, derivesg-targets.txtfromsemgrep.jsonscope first (paths.scanned, fallback to uniqueresults[].path) and runxargs ... sg runon that list. - Only fall back to path heuristics when semgrep scope is unavailable.
- For
- Run first-pass static triage to rank high-risk paths.
- Use triage outputs to prioritize dynamic PoC validation.
- Keep findings evidence-driven: no report without validation.
Source-Aware Triage Stack
semgrep: fast security-first triage and custom pattern scansast-grep(sg): structural pattern hunting and targeted repo mappingtree-sitter: syntax-aware parsing support for symbol and route extractiongitleaks+trufflehog: complementary secret detection (working tree and history coverage)trivy fs: dependency, misconfiguration, license, and secret checks
Coverage target per repository:
- one
semgreppass - one AST structural pass (
sgand/ortree-sitter) - one secrets pass (
gitleaksand/ortrufflehog) - one
trivy fspass
Agent Delegation Guidance
- Keep child agents specialized by vulnerability/component as usual.
- For source-heavy subtasks, prefer creating child agents with
source_aware_sastskill. - Use source findings to shape payloads and endpoint selection for dynamic testing.
Validation Guardrails
- Static findings are hypotheses until validated.
- Dynamic exploitation evidence is still required before vulnerability reporting.
- Keep scanner output concise, deduplicated, and mapped to concrete code locations.
Validation & Reporting
- Confirm every finding with reproducible PoC before reporting
- Document: severity (CVSS), affected asset, steps, evidence, remediation
- Use
record_vulnerabilitywhen running inside the penkit51 platform - Chain low-severity findings into higher-impact attack paths
- Never report without evidence — distinguish hypothesis from confirmed vuln
Validation & Reporting
- Confirm every finding with reproducible PoC before reporting
- Document: severity (CVSS), affected asset, steps, evidence, remediation
- Use
record_vulnerabilitywhen running inside the penkit51 platform - Chain low-severity findings into higher-impact attack paths
- Never report without evidence — distinguish hypothesis from confirmed vuln
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.