Suzu-Testing

61 mods across 1 repository, 3 stars between them.

Suzu-Testing/metasploit-cursor-harness

Agent Cursor

Master Metasploit engagement orchestrator. Use when the user says "start testing", "run recon", "exploit targets", or gives broad multi-phase instructions. Drives the phase/gate/subgate workflow and coordinates specialized subagents.

3 7d ago A 53 tokens original MIT

msf-exploit-agent

02

Suzu-Testing/metasploit-cursor-harness

Agent Cursor

Metasploit exploitation specialist. Use for vulnerability checks, exploit execution, handler setup, and session verification. Only operates against targets approved by the orchestrator and within ROE.

3 7d ago A 41 tokens original MIT

msf-post-agent

03

Suzu-Testing/metasploit-cursor-harness

Agent Cursor

Metasploit post-exploitation specialist. Use for session interaction, running post modules, credential harvesting, loot collection, and session cleanup.

3 7d ago C 32 tokens original MIT

msf-recon-agent

04

Suzu-Testing/metasploit-cursor-harness

Agent Cursor

Reconnaissance and scanning specialist. Runs nmap, enumerates services, queries the MSF database, searches modules, and profiles targets. NEVER exploits -- only observes and reports.

3 7d ago A 42 tokens original MIT

msf-reviewer

05

Suzu-Testing/metasploit-cursor-harness

Agent Cursor

Read-only security reviewer for Metasploit engagement plans. Use before any destructive operation to validate targets, modules, and ROE compliance. Enforces G4 hard gate (SG4.1-reviewer-gate). Does not execute any actions.

3 7d ago A 54 tokens original MIT

ai-llm-pentest

09

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides AI and LLM application security testing including prompt injection, system prompt extraction, tool/function abuse, MCP server testing, and data exfiltration via LLM features. Use for chatbots, agents, and AI-integrated apps.

3 7d ago F 55 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides binary exploitation including stack overflow, ROP, format strings, heap basics, pwntools, and GDB analysis. Use when engagement ROE explicitly authorizes custom exploit development beyond Metasploit modules.

3 7d ago A 49 tokens original MIT

blockchain-pentest

11

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides blockchain and smart contract security testing with reentrancy, flash loan, and access control analysis using Slither and EVM tooling. Use when auditing Solidity contracts, DeFi protocols, EVM dApps, or Web3 signing workflows in engagement scope.

3 7d ago A 57 tokens original MIT

cloud-pentest

12

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides cloud penetration testing for AWS, Azure, and GCP enumeration, credential abuse, metadata SSRF, storage misconfigurations, IAM privilege escalation, and cloud lateral movement from web or internal footholds.

3 7d ago B 46 tokens original MIT

cmdi-pentest

13

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides OS command injection testing with shell metacharacter probes, blind exfiltration, filter bypass, and OS-specific syntax. Use when inputs reach shell commands such as ping, nslookup, file conversion, or when shell metacharacters alter application behavior.

3 7d ago A 57 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides container and DevOps penetration testing for Docker escape, Kubernetes abuse, CI/CD pipeline secrets, package manager poisoning, and secrets enumeration from footholds or exposed services.

3 7d ago B 40 tokens original MIT

database-pentest

15

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides database penetration testing for MSSQL, MySQL, PostgreSQL, MongoDB, Redis, and Elasticsearch. Use when database ports are open, SQL injection yields DB access, or linked-server abuse is suspected.

3 7d ago A 47 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides insecure deserialization testing with format identification, language-specific gadget chains, and ysoserial/phpggc tooling. Use when Java, .NET, PHP, Python, or Ruby serialized objects appear in cookies, headers, APIs, or base64-encoded parameters including ViewState.

3 7d ago A 62 tokens original MIT

dns-pentest

17

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides DNS name resolution service penetration testing. Use when port 53 is discovered during scanning or when DNS is identified on a target.

3 7d ago A 31 tokens original MIT

forensics-pentest

18

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides digital forensics methodology for disk images, memory dumps, pcaps, and artifact analysis. Use when analyzing evidence to support incident response, malware triage, or pentest finding validation.

3 7d ago A 44 tokens original MIT

ftp-pentest

19

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides FTP file transfer service penetration testing. Use when port 21 is discovered during scanning or when FTP is identified on a target.

3 7d ago B 31 tokens original MIT

graphql-pentest

20

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides GraphQL injection and authorization testing with introspection, field enumeration, batch attacks, and nested query abuse. Use when GraphQL endpoints, introspection, or query syntax are discovered.

3 7d ago A 42 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides network and service penetration testing after port discovery. Provides port-to-skill routing, per-service quick reference, and general enumeration methodology for services with and without dedicated harness skills.

3 7d ago A 42 tokens original MIT

hardware-pentest

22

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides hardware and physical access penetration testing with UART/JTAG/SPI analysis, firmware extraction, and logic analyzer techniques. Use when engagement ROE includes firmware extraction, debug interface access, or physical device compromise.

3 7d ago A 46 tokens original MIT

idor-pentest

23

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides Insecure Direct Object Reference testing with ID manipulation, parameter pollution, and horizontal/vertical privilege escalation techniques. Use when predictable IDs in URLs, sequential numbers, UUIDs, or authorization bypass indicators appear.

3 7d ago A 46 tokens original MIT

Suzu-Testing/metasploit-cursor-harness

Skill Claude CodeCodexCursor

Guides initial access techniques including external attack surface mapping, credential abuse, phishing delivery chains, and client-side payload planning. Use during external engagement phases before exploitation.

3 7d ago A 37 tokens original MIT