Skip to content
Back to skills

Pen Tester

ASecurity

Port-scan, deps, permissions, network, password hygiene.

  • 5 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 4, 2026
ai-agentspythongobashapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned October 4, 2026

npx -y skills add openamer/openamer --skill pen-tester --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Pen Tester?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Pen Tester
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/openamer-pen-tester/badge)](https://www.skillsdirectory.com/skills/openamer-pen-tester)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: pen-tester
description: 'Port-scan, deps, permissions, network, password hygiene.'
category: security
version: 1.0.0
---

# pen-tester — Automatisierter Security-Audit

Führt vollständigen Security-Audit durch: Port-Scan, Dependency-Audit, File-Permissions, Network-Exposure, Password-Hygiene. Erzeugt HTML + JSON Reports mit CVSS-ähnlichem Scoring.

## CLI

```bash
# Quick-Modus (Port + Permissions) — ideal für Cron alle 4h
python scripts/pen-tester.py --quick

# Full-Modus (alle Checks)
python scripts/pen-tester.py --full

# Mit Report-Speicherung
python scripts/pen-tester.py --full --report reports/

# Nur Console (keine Dateien)
python scripts/pen-tester.py --quick --stdout
```

## Exit-Codes

| Code | Bedeutung |
|------|-----------|
| 0 | Sicher / keine Funde |
| 1 | Warnungen (low/medium) |
| 2 | Kritisch (high/critical) |

## Checks

1. **Port-Scan** — 30+ Common Ports (22,80,443,3306,5432,6379,27017,…) auf localhost + LAN-IP. Threaded parallel (50 Worker), ~4s.
2. **Dependency-Audit** — `pip-audit` (falls installiert) sonst `pip list --outdated`. Erkennt CVEs.
3. **File-Permissions** — `.env`, `config.yaml`, `.backup_key` auf korrekte Berechtigungen. Windows: Everyone/Users. Unix: group/other Bits.
4. **Network-Exposure** — `netstat -ano` auf 0.0.0.0/[::]-Bindungen. Warnt bei externer Erreichbarkeit.
5. **Password-Hygiene** — Scannt Configs auf Standard-Passwörter (admin, password, 123456, your-api-key) + API-Key-Zählung.

## Reports

- **HTML**: Dark-Theme mit Risk-Score-Ring, Summary-Cards, Findings-Tabelle.
- **JSON**: Maschinenlesbar mit CVSS-Scoring und Severity-Zählung.

## Pfad

Script: `$OPENAMER_HOME/scripts/pen-tester.py` (Default: `~/AppData/Local/openamer-laptop/scripts/`)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…