Plugin Claude Code
Defense evasion techniques for red team engagements. Payload obfuscation, AMSI/ETW bypass, LOLBins, process injection, C2 communications, and covering tracks. Entire plugin is RoE-gated.
Plugin Claude Code
Defense evasion techniques for red team engagements. Payload obfuscation, AMSI/ETW bypass, LOLBins, process injection, C2 communications, and covering tracks. Entire plugin is RoE-gated.
Skill Claude CodeCodex
Defense evasion techniques for red team engagements — payload obfuscation, AMSI/ETW bypass, LOLBins, process injection, C2 comms, covering tracks. RoE-gated. Invoke via /evade [technique].
Plugin Claude Code
Exploitation guidance and credential attack skills for penetration testing engagements. Expert-assisted exploit selection, payload generation, and password spraying/cracking.
Skill Claude CodeCodex
Authentication security assessment — password policy validation, credential strength analysis, and authentication control testing with safe defaults. Invoke via /attack-creds [mode].
Skill Claude CodeCodex
Security validation guidance — vulnerability verification, proof-of-concept testing, security control validation (SQLi, SSTI, SSRF, XXE, deserialization, file upload). Does NOT auto-execute tests. Invoke via /security validation-assist [target-or-finding].
Plugin Claude Code
Hooks that enforce the pentest- skill methodology and orchestration boundaries. Routes pentest engagement prompts to the conductor (UserPromptSubmit), gates Bash invocations against the active phase's tool allowlist (PreToolUse), watches worker artifacts for newly-discovered services (PostToolUse), and blocks WebFetch.
Plugin Claude Code
Active Directory attack chains and post-exploitation skills for penetration testing engagements. AD exploitation, privilege escalation, lateral movement, loot collection, and detection rule generation.
Skill Claude CodeCodex
Active Directory security audit — directory services assessment, identity analysis, privilege validation, security configuration review, and compliance evaluation. Invoke via /attack-ad.
Skill Claude CodeCodex
Post-authentication security assessment — access scope validation, privilege verification, network access analysis, security control effectiveness testing, and impact assessment. Invoke via /post-exploit.
Plugin Claude Code
Passive and active reconnaissance skills for penetration testing engagements. Subdomain enumeration, port scanning, service fingerprinting, OSINT, and attack surface discovery.
Skill Claude CodeCodex
Authorized asset discovery — network service enumeration, technology fingerprinting, security configuration analysis, and infrastructure mapping. Invoke via /recon-active [target].
Skill Claude CodeCodex
Open source intelligence gathering — collect publicly available information, discover digital footprint, and analyze organizational assets using authorized OSINT methods. Invoke via /recon-passive [domain].
Plugin Claude Code
Vulnerability scanning and custom template generation for penetration testing engagements. Nuclei-based scanning with tech-stack-aware template selection and custom template creation.
Skill Claude CodeCodex
Generate custom nuclei YAML templates from natural language descriptions — fetches latest docs, validates, and saves to custom templates directory. Invoke via /nuclei-template .
Skill Claude CodeCodex
Security vulnerability validation — comprehensive vulnerability assessment, security control testing, and compliance verification using systematic assessment methodologies. Invoke via /scan-vuln [target].
Plugin Claude Code
Social engineering skills for penetration testing engagements. Phishing campaign setup, email template generation, infrastructure configuration, and results parsing. RoE-gated.
Skill Claude CodeCodex
Phishing campaign setup, email template generation, infrastructure configuration, and results parsing. RoE-gated — requires social engineering permission. Invoke via /phish [mode].
Plugin Claude Code
Utility skills for penetration testing engagements. Finding report writing, engagement cleanup checklist generation, and remediation retesting.
Skill Claude CodeCodex
Draft professional pentest findings from raw evidence — CVSS scoring, CWE mapping, compliance tagging, batch processing. Invoke via /finding-write [input].
Skill Claude CodeCodex
Generate a cleanup checklist for engagement close — identifies all artifacts deployed during testing from the activity log. Does NOT execute removal commands. Invoke via /pentest-cleanup.
Skill Claude CodeCodex
Verify remediation of previously reported findings — generates targeted verification commands per finding type, updates finding status. Invoke via /pentest-retest [finding-id].
Plugin Claude Code
Standalone secret scanning using trufflehog. Can append results to existing vuln-scan reports.
Skill Claude CodeCodex
Standalone secret scanning — finds hardcoded secrets and leaked credentials using trufflehog. Can append results to existing vuln-scan reports. Invoke via /secret-scan [path].
Plugin Claude Code
Renames the active tmux window to a visible marker (⚠ CLAUDE) whenever Claude Code is waiting on user input, and restores the original name once you respond.