pentesting agents

43 tagged pentesting, measured the same way as everything else here.

Browse within: ai-pentesting 15cybersecurity 15burpsuite 14pentest 14pentest-tool 14ctf 9hackthebox 9offensive-security 5

csp-bypass-tester

01

Stickman230/claude-pentest

Agent

Inspects Content Security Policy headers for policy weaknesses and tests bypass vectors including unsafe-inline, unsafe-eval, wildcard sources, JSONP endpoints, Angular sandbox escape, and open redirects in whitelisted domains. Uses Playwright for browser-based CSP inspection and script execution testing. Follows…

97 2mo ago A 78 tokens original MIT

injection-tester

02

Stickman230/claude-pentest

Agent

Tests for SQL injection, NoSQL injection, and OS command injection across HTTP parameters, JSON bodies, and headers. Uses sqlmap for automated SQLi detection and curl for manual probing. Follows 4-phase workflow. Deployed by common-appsec-patterns skill coordinator.

97 2mo ago A 60 tokens original MIT

Pentester Executor

03

Stickman230/claude-pentest

Agent

Executes specific vulnerability tests. Follows 4-phase workflow (Recon → Experiment → Test → Verify), generates PoCs, captures evidence. Specialized by attack type.

97 2mo ago A 37 tokens original MIT

darlene

04

ogrodev/fsociety

Agent

Use this agent when the user asks to "exploit a vulnerability", "test this exploit", "generate exploit", "attack this endpoint", "run exploitation", "verify the vulnerability", or discusses actively exploiting a confirmed finding. This agent selects the right Hexstrike tool chain for the vulnerability type. Context…

20 5mo ago A 188 tokens original MIT

cleaner

05

ogrodev/fsociety

Agent

Use this agent when the user asks to "clean up traces", "remove evidence", "wipe logs", "eliminate footprint", "clean the system", "remove artifacts", "clear history", "cover tracks", "anti-forensics sweep", or discusses removing operational traces from compromised or operated-on systems. Context: User finished an…

20 5mo ago A 188 tokens original MIT

ghost

06

ogrodev/fsociety

Agent

Use this agent when the user asks to "secure a machine", "harden a server", "make a system secure", "set up opsec", "prepare infrastructure", "full security audit", "lock down the server", "run security checks", or mentions comprehensive system hardening and operational security setup. Context: User has a fresh VPS to…

20 5mo ago A 195 tokens original MIT

auth-payment-agent

07

TyrusRC/praetor

Agent Claude Code

Deep-dive OAuth/OIDC, WebAuthn/FIDO2/passkeys, Apple/Google/Samsung Pay, IAP receipt validation, 3DS 2.x bypass, SCA exemption abuse, recovery downgrades. $5k-$50k bug class.

5 11d ago A 59 tokens original Apache-2.0

finding-verifier

08

TyrusRC/praetor

Agent Claude Code

Re-verify suspected/confirmed findings and investigate anomalies. Promotes states (suspected → confirmed) or demotes (→ stale / likelyfalsepositive).

5 11d ago A 35 tokens original Apache-2.0

grow-agent

09

TyrusRC/praetor

Agent Claude Code

Session orchestrator for one domain. Owns Rule 20a session-start gate + Rule 4 goal-driven loop + Rule 22 decision compaction + Rule 21 checkpointing. Promotes confirmed cross-target patterns into KB/skill proposals. On-demand only.

5 11d ago A 56 tokens original Apache-2.0

exploit-runner

10

allsmog/blackbox-claude-plugin

Agent

Use this agent when a specific CVE is identified and you need to find and run a working exploit. This agent will search GitHub for PoC exploits, clone them, and provide execution guidance. Examples: Context: CVE-2025-32433 identified on Erlang SSH user: "Exploit the Erlang SSH" assistant: Clones…

5 6mo ago A 147 tokens original MIT

exploit-suggester

11

allsmog/blackbox-claude-plugin

Agent

Use this agent when the user asks "what exploits exist", "how do I exploit this", "suggest attack vectors", "find vulnerabilities", "searchsploit", "what's vulnerable", "how can I get a shell", or needs exploitation guidance. Examples: Context: After discovering Apache 2.4.49 user: "What exploits are there for this?"…

5 6mo ago A 167 tokens original MIT

shell-manager

12

allsmog/blackbox-claude-plugin

Agent

Use this agent when the user asks to "start a listener", "catch a shell", "manage shells", "send command to shell", "check shell output", "set up reverse shell", or needs to maintain persistent shell access during exploitation. Examples: Context: User has RCE and needs to catch reverse shell user: "Start a listener on…

5 6mo ago A 141 tokens original MIT