Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fb0sh/pentester/pentest-toolsnpx skills add fb0sh/pentester --skill pentest-toolsgit clone --depth 1 https://github.com/fb0sh/pentesterWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00066 | $0.00525 |
| Opus 5 | $0.00033 | $0.00262 |
| Sonnet 5 | $0.00013 | $0.00105 |
| Haiku 4.5 | $0.00007 | $0.00052 |
Grade A, and why
pentest-tools scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to pentest-tools — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
渗透工具速查 Skill
当已知测试方向,需要选型工具或回忆命令时使用本 Skill。是操作支撑层,不是方法论替代。
使用场景:
- 已确认漏洞类型,需要对应工具和命令
- 记不住某个工具的具体参数
- 需要快速筛选同一任务下的候选工具
边界:本 Skill 帮助选型和回忆工具,不替代方法论。工具选择应跟随当前工作流阶段,而不是反过来。
工具分类速查
| 分类 | 覆盖范围 |
|---|---|
| 编码解码 | Base64/URL/Hex/Unicode/HTML 编解码 |
| 反向 Shell | Bash/Python/PowerShell/Netcat/Socat |
| 红队工具 | Cobalt Strike/Metasploit/Covenant |
| 漏洞利用 | Exploit-DB/Searchsploit/自动化框架 |
| 密码攻击 | Hashcat/John/Hydra/Cewl |
| 内网渗透 | Impacket/CrackMapExec/BloodHound |
| 凭据窃取 | Mimikatz/LaZagne/Secretsdump |
| 提权 | LinPEAS/WinPEAS/PowerUp/BeRoot |
| 隧道代理 | Chisel/Ligolo/FRP/Socat/SSH |
| 系统命令 | Linux/Windows 常用命令集 |
| 信息收集 | Nmap/Masscan/Amass/Subfinder |
| 域渗透 | BloodHound/Certipy/Rubeus/Kekeo |
| Web 工具 | SQLmap/Nuclei/FFUF/Burp |
| Windows 渗透 | PowerShell/WMI/WMIC/PowerView |
参考文档
references/tools-reference-01~14-*.md— 各工具分类详细参考(14 个)references/pentest-tools-reference-skill.md— 工具参考入口references/tools-reference-index.md— 工具参考索引
What ships with it
16 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/pentest-tools-reference-openai.yaml 291 B
- references/pentest-tools-reference-skill.md 2.8 KB
- references/tools-reference-01-encoding-decoding.md 4.9 KB
- references/tools-reference-03-red-team-tools.md 729 B
- references/tools-reference-04-exploitation.md 8.7 KB
- references/tools-reference-05-password-attacks.md 7.6 KB
- references/tools-reference-06-intranet-penetration.md 12 KB
- references/tools-reference-07-credential-theft.md 1.8 KB
- references/tools-reference-08-privilege-escalation.md 1.6 KB
- references/tools-reference-09-tunneling-and-proxy.md 1.3 KB
- references/tools-reference-10-system-commands.md 6.2 KB
- references/tools-reference-11-information-gathering.md 13 KB
- references/tools-reference-12-domain-penetration.md 898 B
- references/tools-reference-13-web-penetration.md 11 KB
- references/tools-reference-14-windows-penetration.md 947 B
- references/tools-reference-index.md 860 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 41 lines · 66 tokens per session scan A 152978e80064
pentest-tools is a skill published in the GitHub repository fb0sh/pentester (23 stars, last pushed 1mo ago), licensed MIT. It adds 66 tokens to every session and 525 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to pentest-tools, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
transilience-report-style
Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.
firewall-review
Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…
pentest-engagement
Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…
attack-path-stitcher
Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.
coordination
Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.
hackerone
HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.