pentest-tools

A quick reference for choosing penetration-testing tools and recalling their commands. Penetration testing is authorized security testing used to find weaknesses in systems.

In plain words
What is it for?
It is for encoding and decoding, reverse shells, vulnerability testing, password testing, network and domain assessment, credential recovery, privilege escalation, tunneling, and Linux or Windows tools.
Why use it?
It reduces the time spent searching for a suitable tool or remembering its options after the testing direction is already known.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/fb0sh/pentester/pentest-tools
Any agent
npx skills add fb0sh/pentester --skill pentest-tools
Clone the repo
git clone --depth 1 https://github.com/fb0sh/pentester

Made for: Claude Code, Codex.

Per session 66 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 525 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00066 $0.00525
Opus 5 $0.00033 $0.00262
Sonnet 5 $0.00013 $0.00105
Haiku 4.5 $0.00007 $0.00052

Measured 3d ago against content hash 152978e80064, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

pentest-tools scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to pentest-tools — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.agents/skills/third-party/pentest-tools/SKILL.md · 41 lines

What it actually says

渗透工具速查 Skill

当已知测试方向,需要选型工具或回忆命令时使用本 Skill。是操作支撑层,不是方法论替代。

使用场景

  • 已确认漏洞类型,需要对应工具和命令
  • 记不住某个工具的具体参数
  • 需要快速筛选同一任务下的候选工具

边界:本 Skill 帮助选型和回忆工具,不替代方法论。工具选择应跟随当前工作流阶段,而不是反过来。

工具分类速查

分类 覆盖范围
编码解码 Base64/URL/Hex/Unicode/HTML 编解码
反向 Shell Bash/Python/PowerShell/Netcat/Socat
红队工具 Cobalt Strike/Metasploit/Covenant
漏洞利用 Exploit-DB/Searchsploit/自动化框架
密码攻击 Hashcat/John/Hydra/Cewl
内网渗透 Impacket/CrackMapExec/BloodHound
凭据窃取 Mimikatz/LaZagne/Secretsdump
提权 LinPEAS/WinPEAS/PowerUp/BeRoot
隧道代理 Chisel/Ligolo/FRP/Socat/SSH
系统命令 Linux/Windows 常用命令集
信息收集 Nmap/Masscan/Amass/Subfinder
域渗透 BloodHound/Certipy/Rubeus/Kekeo
Web 工具 SQLmap/Nuclei/FFUF/Burp
Windows 渗透 PowerShell/WMI/WMIC/PowerView

参考文档

  • references/tools-reference-01~14-*.md — 各工具分类详细参考(14 个)
  • references/pentest-tools-reference-skill.md — 工具参考入口
  • references/tools-reference-index.md — 工具参考索引
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 41 lines · 66 tokens per session scan A 152978e80064

Subscribe to this mod's changes

pentest-tools is a skill published in the GitHub repository fb0sh/pentester (23 stars, last pushed 1mo ago), licensed MIT. It adds 66 tokens to every session and 525 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to pentest-tools, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

transilience-report-style

Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.

transilienceai/communitytools · 31 tokens

firewall-review

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…

transilienceai/communitytools · 100 tokens

pentest-engagement

Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…

transilienceai/communitytools · 140 tokens

attack-path-stitcher

Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.

transilienceai/communitytools · 42 tokens

coordination

Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.

transilienceai/communitytools · 24 tokens

hackerone

HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.

transilienceai/communitytools · 36 tokens