
Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...
A complete, searchable penetration-testing knowledge base across 23 security domains.
Live Website · PentestingChecklist · Contribute · Report an Issue
Read it online at pentesting.m14r41.in: fully searchable, with 108 documentation pages, 104 reference PDFs, and 212+ topics across 23 domains. The website turns this repository into a fast, structured, and readable knowledge base.
New in v2.0.0: the project is now a full website with instant full-text search, a filterable reference PDF library, learning paths for common engagements, and a companion checklist at checklist.m14r41.in. Full notes in the changelog.
PentestingEverything is an open-source, comprehensive penetration-testing knowledge base. It brings together methodology, checklists, payloads, commands, and field-tested references across 23 domains: web, API, mobile, network, cloud, Active Directory, OSINT, and more. The goal is simple: give you the concise, practical knowledge to assess any target, from scoping an engagement to hunting a specific vulnerability class to writing the report.
Practical companion: PentestingChecklist. This project is the knowledge base. The checklist is the hands-on, tick-as-you-go companion. A structured checklist across 23 platforms (web, API, mobile, cloud, AD and more) with progress tracking, notes, and export. Use them side by side.
Install a portable Agent Skill to use this knowledge base from Cursor and other coding agents. It grounds answers in PentestingEverything Markdown, builds scoped checklists, and drafts evidence-based notes for authorized assessments only.
Who it's for: bug hunters, security testers, and penetration testers running real engagements through an agent, not just browsing static docs. Ground rules keep autonomous use safe: authorization is confirmed before active testing, high-impact actions are gated, findings pass a false-positive check before being drafted, and automated requests are paced to respect program rate limits.
Install (project-local):
npx skills add m14r41/PentestingEverything --skill pentesting-everything
Install globally (available across projects):
npx skills add m14r41/PentestingEverything --skill pentesting-everything --global
Target a specific client (examples):
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent cursor
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent claude-code
List without installing:
npx skills add m14r41/PentestingEverything --list
Skill source: .agents/skills/pentesting-everything/.
Your ideas, suggestions, and contributions are always welcome!
Contributions and knowledge sharing are welcome from professionals experienced in Cloud and Enterprise Infrastructure Pentesting.