Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/Stickman230/claude-pentestWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/stickman230/claude-pentest/inventory-directory-scanner)<a href="https://agentmods.dev/agents/stickman230/claude-pentest/inventory-directory-scanner"><img src="https://agentmods.dev/badge/agents/stickman230/claude-pentest/inventory-directory-scanner/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/stickman230/claude-pentest/inventory-directory-scanner"><img src="https://agentmods.dev/badge/agents/stickman230/claude-pentest/inventory-directory-scanner.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00073 | $0.02274 |
| Opus 5 | $0.00036 | $0.01137 |
| Sonnet 5 | $0.00015 | $0.00455 |
| Haiku 4.5 | $0.00007 | $0.00227 |
Grade A, and why
inventory-directory-scanner scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -sI https://TARGET/ 2>&1 | tee outputs/ENGAGEMENT/activity/baseline-TARGET.txt How it starts
The opening of the file, as written. The whole thing — 200 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Inventory Directory Scanner
Execute comprehensive active directory and file enumeration. Brute-force common paths, scan for backup and configuration file exposure, discover admin panels and hidden resources, and produce a structured inventory of discovered paths.
Workflow
Phase 1: Recon
- Mount skill files:
Read plugins/pentest/skills/web-application-mapping/SKILL.md Read plugins/pentest/skills/mks/SKILL.md - Establish baseline — check HTTP response behavior before scanning:
Record: What status code does the server return for non-existent paths? (200, 302, 404, or custom?) This baseline is critical — ffuf needs to know what "not found" looks like to filter false positives.curl -sI https://TARGET/ 2>&1 | tee outputs/ENGAGEMENT/activity/baseline-TARGET.txt curl -so /dev/null -w "%{http_code}" https://TARGET/THIS_PATH_DOES_NOT_EXIST_12345 - Check robots.txt and sitemap for disclosed paths:
curl -s https://TARGET/robots.txt | tee outputs/ENGAGEMENT/activity/robots-TARGET.txt curl -s https://TARGET/sitemap.xml | tee outputs/ENGAGEMENT/activity/sitemap-TARGET.txt - Log:
{"timestamp":"...","agent":"inventory-directory-scanner","action":"recon","target":"https://TARGET","404_behavior":"404","robots_paths_disclosed":3}
Phase 2: Experiment
- Run ffuf with common wordlist, filtering based on baseline 404 behavior:
ffuf -w /usr/share/seclists/Discovery/Web-Content/common.txt \ -u https://TARGET/FUZZ \ -mc 200,201,301,302,401,403 \ -o outputs/ENGAGEMENT/activity/ffuf-common-TARGET.json \ -of json \ 2>&1 | tee outputs/ENGAGEMENT/activity/ffuf-common-TARGET.txt - Run gobuster for additional coverage with medium wordlist:
gobuster dir \ -u https://TARGET \ -w /usr/share/seclists/Discovery/Web-Content/raft-medium-directories.txt \ -o outputs/ENGAGEMENT/activity/gobuster-dirs-TARGET.txt \ -b 404 \ 2>&1 - Run dirsearch for backup and configuration file detection:
dirsearch -u https://TARGET \ -e php,asp,aspx,jsp,html,txt,conf,config,bak,backup,swp,old,db,sql,env \ -o outputs/ENGAGEMENT/activity/dirsearch-TARGET.txt \ 2>&1 - Log:
{"timestamp":"...","agent":"inventory-directory-scanner","action":"experiment","technique":"ffuf+gobuster+dirsearch","paths_found":43,"interesting":["/.env","/.git","admin/","backup/"]}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 200 lines · 73 tokens per session scan A fd817ff79de3
inventory-directory-scanner is an agent published in the GitHub repository Stickman230/claude-pentest (100 stars, last pushed 3mo ago), licensed MIT. It adds 73 tokens to every session and 2,274 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
darlene
Use this agent when the user asks to "exploit a vulnerability", "test this exploit", "generate exploit", "attack this endpoint", "run exploitation", "verify the vulnerability", or discusses actively exploiting a confirmed finding. This agent selects the right Hexstrike tool chain for the vulnerability type. Context…
scout
Use this agent when the user asks to "run recon", "enumerate a target", "do reconnaissance", "scan subdomains", "map the attack surface", "discover endpoints", or mentions comprehensive target enumeration. This agent orchestrates multiple Hexstrike tools in parallel for maximum coverage. Context: User wants to start a…
exploit-suggester
Use this agent when the user asks "what exploits exist", "how do I exploit this", "suggest attack vectors", "find vulnerabilities", "searchsploit", "what's vulnerable", "how can I get a shell", or needs exploitation guidance. Examples: Context: After discovering Apache 2.4.49 user: "What exploits are there for this?"…
exploit-runner
Use this agent when a specific CVE is identified and you need to find and run a working exploit. This agent will search GitHub for PoC exploits, clone them, and provide execution guidance. Examples: Context: CVE-2025-32433 identified on Erlang SSH user: "Exploit the Erlang SSH" assistant: Clones…
shell-manager
Use this agent when the user asks to "start a listener", "catch a shell", "manage shells", "send command to shell", "check shell output", "set up reverse shell", or needs to maintain persistent shell access during exploitation. Examples: Context: User has RCE and needs to catch reverse shell user: "Start a listener on…
source-analyzer
Use this agent when you discover source code, backup files, or need to analyze application code for vulnerabilities. Triggers on: "analyze source", "found code", "check for vulnerabilities", "review application", "found backup", "downloaded zip/tar", "requirements.txt", "package.json".