渗透测试工程师

Senior ethical penetration tester skilled in authorized security testing, vulnerability discovery, and hands-on exploitation validation. Covers web, network, API, mobile, cloud, and infrastructure attack surfaces with actionable remediation guidance.

Author
Jason Carter
Type
agent
Category
qa
Version
1.0.0
Tags
渗透测试, 安全, 漏洞, exploit, OWASP, 道德黑客, recon, red-team
Price
Free

README

# Penetration Tester (渗透测试工程师) ## Overview **Penetration Tester (渗透测试工程师)** is a senior ethical-hacking and offensive-security specialist. It conducts authorized security penetration tests across web, network, API, mobile, cloud, and infrastructure surfaces — validating real vulnerabilities through active exploitation and delivering actionable remediation guidance. ## Key Capabilities - ✅ **Authorization-first pentest lifecycle** — pre-engagement scope/RoE → recon → exploitation → reporting - ✅ **Multi-surface coverage** — web (OWASP Top 10), network, API, infrastructure, mobile, cloud - ✅ **Controlled exploit validation** — non-destructive PoC with impact assessment - ✅ **Evidence-based reporting** — severity, location, failure scenario, remediation fix - ✅ **Risk prioritization** — Critical→Low classification with confidence estimates ## Usage 1. Load the `penetration-tester` agent into your Markus workspace. 2. @mention `@penetration-tester` (or route via workflow), providing an authorized scope and rules of engagement. 3. It recons, tests systematically, and returns evidence-backed findings with concrete remediation guidance. ## Licensing Source Based on the **penetration-tester** subagent from [awesome-claude-code-subagents](https://github.com/VoltAgent/awesome-claude-code-subagents) (MIT). --- **Attribution:** Based on [penetration-tester subagent](https://github.com/VoltAgent/awesome-claude-code-subagents/blob/main/categories/04-quality-security/penetration-tester.md) from [awesome-claude-code-subagents](https://github.com/VoltAgent/awesome-claude-code-subagents) - Original author: VoltAgent - License: MIT