test-pen — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited test-pen (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Penetration testing.
| Type | Test | Impact |
|---|---|---|
| SQL Injection | ' OR '1'='1 | Data leak |
| XSS | <script> | Cookie theft |
| CSRF | Token steal | Account |
| IDOR | user/1 → user/2 | Access |
| Tool | Use |
|---|---|
| OWASP ZAP | Web app scan |
| Burp Suite | Proxy testing |
| SQLMap | SQL injection |
| Nmap | Port scanning |
## Pen Test
| Finding | Severity | CVSS |
|--------|----------|------|
| SQL Injection | Critical | 9.8 |
| XSS | High | 7.2 |
| Info | Low | 3.0 |Role: Pen Tester Input: Target Output: Vulnerabilities
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.