crazyMarky/pentest-skills

💬 🚀 告别繁琐命令行,用自然语言驱动专业级渗透测试。 ⚡ 让安全测试从未如此简单、高效。Forget complex command lines. 🛡️ Professional penetration testing, powered by natural language.

301Stars on the repository
11Mods indexed here, across every type
3mo agoLast push, which is what freshness is scored on
Apache-2.0Licence, which decides whether bodies are shown

crazyMarky/pentest-skills

Skill Claude CodeCodex

An authorised security-testing tool for finding and demonstrating arbitrary file-download and local file inclusion (LFI) vulnerabilities. LFI is a flaw where a web application reads or includes a file path supplied by the user.

not rated 301 +3 3mo ago C 79 tokens original Apache-2.0

crazyMarky/pentest-skills

Skill Claude CodeCodex

Arbitrary file download vulnerability detection and exploitation using path traversal techniques, bypass methods, and sensitive file discovery. Use this skill when user needs to test for file download vulnerabilities, path traversal, or read sensitive files on target systems.

not rated 301 +3 3mo ago B 50 tokens original Apache-2.0

exploit-lfi

03

crazyMarky/pentest-skills

Skill Claude CodeCodex

A security-testing procedure for finding and exploiting local file inclusion, a web flaw where user input controls which server file is loaded. It covers path traversal, PHP stream wrappers, sensitive-file reading, and possible code execution.

not rated 301 +3 3mo ago B 79 tokens original Apache-2.0

exploit-sqli

04

crazyMarky/pentest-skills

Skill Claude CodeCodex

SQL injection detection and exploitation using sqlmap, manual techniques, and custom payloads. Use this skill when user needs to test for SQL injection vulnerabilities, extract database information, or exploit SQLi in parameters, headers, or cookies.

not rated 301 +3 3mo ago A 51 tokens original Apache-2.0

exploit-xss

05

crazyMarky/pentest-skills

Skill Claude CodeCodex

Cross-site scripting (XSS) vulnerability detection and exploitation. Supports reflected XSS, stored XSS, DOM-based XSS, and blind XSS testing. Use this skill when user mentions XSS, cross-site scripting, script injection, or needs to test JavaScript injection in parameters, forms, headers, or DOM sources.

not rated 301 +3 3mo ago A 71 tokens original Apache-2.0

pentest-report

06

crazyMarky/pentest-skills

Skill Claude CodeCodex

A skill for producing penetration-testing reports, which document authorized security checks and their findings, in a specified standard format.

not rated 301 +3 3mo ago A 92 tokens original Apache-2.0

recon-dir-scan

07

crazyMarky/pentest-skills

Skill Claude CodeCodex

Directory and file enumeration using ffuf, gobuster, dirsearch, and feroxbuster. Use this skill when user needs to discover hidden directories, enumerate files, find backup files, or map application structure through path fuzzing.

not rated 301 +3 3mo ago A 52 tokens original Apache-2.0

recon-fingerprint

08

crazyMarky/pentest-skills

Skill Claude CodeCodex

Web fingerprinting and WAF detection using wafw00f, whatweb, nuclei, and httpx. Use this skill when user needs to identify web technologies, detect WAF/CDN, analyze server headers, or fingerprint web applications and frameworks.

not rated 301 +3 3mo ago A 55 tokens original Apache-2.0

recon-port-scan

09

crazyMarky/pentest-skills

Skill Claude CodeCodex

Port scanning and service identification using nmap, masscan, and rustscan. Use this skill when user needs to discover open ports, identify running services, detect service versions, or fingerprint operating systems on target hosts.

not rated 301 +3 3mo ago B 49 tokens original Apache-2.0

recon-subdomain

10

crazyMarky/pentest-skills

Skill Claude CodeCodex

Subdomain enumeration and DNS reconnaissance using subfinder, amass, dnsx, and other tools. Use this skill when user needs to discover subdomains, perform DNS enumeration, gather DNS records, or find hidden subdomains of a target domain.

not rated 301 +3 3mo ago A 54 tokens original Apache-2.0

results-storage

11

crazyMarky/pentest-skills

Skill Claude CodeCodex

SQLite-based persistent storage and reporting system for penetration testing results. Use this skill when user needs to store scan results, query vulnerabilities, generate reports, or manage pentest data across sessions.

not rated 301 +3 3mo ago A 40 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: