fb0sh

61 mods across 2 repositories, 23 stars between them.

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized file operation vulnerability testing, including path traversal, arbitrary file read/write/upload, and LFI/RFI. Use when a task belongs to the file vulnerability domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 56 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized general injection testing outside SQL injection, including NoSQL, LDAP, XPath, and expression language injection. Use when a task belongs to the general injection domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 56 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized business logic vulnerability testing, including race conditions, flow bypass, price tampering, permission logic errors, and bulk operation abuse. Use when a task belongs to the logic testing domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 61 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized mobile application security testing, including insecure storage, certificate pinning bypass, exposed components, and binary reverse engineering. Use when a task belongs to the mobile testing domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 57 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized network-layer security testing, including exposed services, protocol downgrade, man-in-the-middle risks, and segmentation bypasses. Use when a task belongs to the network testing domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 58 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized open redirect testing, including parameter redirects, meta or JavaScript redirects, and OAuth redirecturi abuse. Use when a task belongs to the open redirect domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 57 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized payload construction and weaponization analysis, including shellcode, file format payloads, phishing payloads, and staged or stageless payload choices. Use when a task belongs to the payload construction domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 64 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized post-exploitation testing after initial access, including privilege escalation, persistence, lateral movement, data collection, and cleanup considerations. Use when a task belongs to the post-exploitation domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 61 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized reconnaissance and information gathering, including subdomain enumeration, port scanning, directory discovery, fingerprinting, and OSINT. Use when a task belongs to the recon domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 58 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Recon intake skill for first contact with a bare domain, URL, or IP address. Use to build an initial reconprofile and provide factual inputs for CVE lookup and attack-path routing.

23 1mo ago A 44 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized reverse engineering analysis, including decompilation, debugging, protocol reversing, firmware extraction, and deobfuscation. Use when a task belongs to the reverse engineering domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 59 tokens copy · 100% MIT

fb0sh/pentester

Skill Claude CodeCodex

Domain routing and boundary guidance for authorized SQL injection testing, including union-based, blind, error-based, stacked query, and second-order SQL injection variants. Use when a task belongs to the SQL injection domain and needs scope, evidence, pivot, or exit criteria.

23 1mo ago A 59 tokens copy · 100% MIT

mcptools

61

fb0sh/mcptools

MCP server Claude CodeCodexCursor

MCP server "mcptools" as configured in fb0sh/mcptools. Runs locally from the mcptools Python package.

0 2mo ago A tokens not measured