humaidhahm/opencode-pentester

Full-spectrum security assessment tool for opencode — defensive code audit (17 vulnerability categories) + offensive penetration testing (63 attack categories, 15 agents, 11 domains). AI-powered AppSec, red teaming, and pentesting for vibe-coded apps.

21Stars on the repository
20Mods indexed here, across every type
6d agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

security-auditor

03

humaidhahm/opencode-pentester

Agent

Use this agent when you need to audit the security of a vibe-coded application, identify vulnerabilities, and provide remediation guidance. This agent is designed for projects where code may have been developed rapidly with less formal security review. It is particularly useful after implementing new features…

21 6d ago A 255 tokens

humaidhahm/opencode-pentester

Agent

AWS/Azure/GCP security audit, S3 bucket enumeration, container image scanning, Kubernetes RBAC review, IaC misconfiguration detection. 4-phase workflow with approval gate.

21 6d ago B 40 tokens

csrf-tester

05

humaidhahm/opencode-pentester

Agent

Tests for CSRF vulnerabilities: missing tokens, SameSite bypass, token reuse, method override. Generates browser-loadable PoC HTML. 4-phase workflow with approval gate.

21 6d ago A 0 tokens

cve-tester

06

humaidhahm/opencode-pentester

Agent

Identifies tech stacks, researches NVD/Exploit-DB/GitHub, adapts PoC exploits, validates exploitability live. 4-phase workflow with approval gate.

21 6d ago A 41 tokens

domain-assessment

07

humaidhahm/opencode-pentester

Agent

Subdomain discovery, port scanning, service enumeration, certificate transparency. Builds attack surface inventory. 4-phase workflow with approval gate.

21 6d ago A 30 tokens

injection-tester

08

humaidhahm/opencode-pentester

Agent

Tests SQLi, NoSQLi, and OS command injection. Uses sqlmap for automated SQLi detection and curl for manual probing. 4-phase workflow with approval gate.

21 6d ago A 40 tokens

humaidhahm/opencode-pentester

Agent

Online brute force (SSH, FTP, HTTP, SMB, RDP), offline hash cracking (hashcat, john), credential spraying, wordlist optimization, and rule-based attacks. 4-phase workflow with approval gate.

21 6d ago C 49 tokens

pentester-executor

11

humaidhahm/opencode-pentester

Agent

Executes specific vulnerability tests. Follows 4-phase workflow (Recon → Experiment → Test → Verify), generates PoCs, captures evidence. Specialized by attack type.

21 6d ago A 38 tokens

humaidhahm/opencode-pentester

Agent

Penetration-test PLANNER. Reads confirmed scope and recon results, returns a structured deployment plan (which executors, against which surfaces, in what order, with time allocation and escalation directives). Does NOT deploy executors.

21 6d ago A 51 tokens

humaidhahm/opencode-pentester

Agent

Privilege escalation (Linux/Windows), lateral movement, persistence, AD post-exploitation, hash extraction, and tunnel pivoting. 4-phase workflow with approval gate.

21 6d ago E 38 tokens

recon-agent

14

humaidhahm/opencode-pentester

Agent

OSINT, subdomain enumeration, port scanning, service discovery, tech fingerprinting, web crawling, directory enumeration, parameter discovery, and screenshots. Builds comprehensive attack surface inventory. 4-phase workflow with approval gate.

21 6d ago A 47 tokens

xss-tester

15

humaidhahm/opencode-pentester

Agent

Tests for reflected, stored, and DOM-based XSS. Covers framework-specific sinks (React, Vue, Angular), WAF evasion, and CSP bypass. Uses Playwright for browser-based evidence capture. 4-phase workflow with approval gate.

21 6d ago A 54 tokens