pentester-src-hunter

A local security-testing playbook that maps signals such as SQL injection or cross-site scripting to approved testing references and commands. It is an adapter for an existing testing framework, not a separate end-to-end security process.

In plain words
What is it for?
Use it to resolve security-testing signals, read the matching payload or test corpus, inspect signal mappings and dictionaries, run supported self-tests, and cite available high-priority cases.
Why use it?
It provides a controlled way to find the relevant test procedure instead of relying on remembered attack examples. The playbook requires evidence before reporting a security finding.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/fb0sh/pentester/pentester-src-hunter
Any agent
npx skills add fb0sh/pentester --skill pentester-src-hunter
Clone the repo
git clone --depth 1 https://github.com/fb0sh/pentester

Made for: Claude Code, Codex.

Per session 70 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 535 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00070 $0.00535
Opus 5 $0.00035 $0.00267
Sonnet 5 $0.00014 $0.00107
Haiku 4.5 $0.00007 $0.00053

Measured 2d ago against content hash c530e11a39fd, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

pentester-src-hunter scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (playbook.js), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.agents/skills/pentester-src-hunter/SKILL.md · 51 lines

What it actually says

src-hunter — playbook adapter

In this framework: corpus + executable resolve only.
Execution authority: .agents/phases/. Never run an independent Intake→Report pipeline.
Not runtime authority: README.md (upstream product marketing / provenance only).

Interface

node .agents/skills/pentester-src-hunter/playbook.js --signal "sqli,idor"
node .agents/skills/pentester-src-hunter/playbook.js --signal xss --json
node .agents/skills/pentester-src-hunter/playbook.js --list
node .agents/skills/pentester-src-hunter/playbook.js --stuck
node .agents/skills/pentester-src-hunter/playbook.js --cite-h1 xss   # tier-2 H1 only
node .agents/skills/pentester-src-hunter/playbook.js --selftest

Map of record: references/signal-map.json.
Shared handoff keywords: .agents/knowledge/signal-aliases.json (LOOKUP + playbook).

playbook(signal) → path under references/playbooks/
dictionary(fingerprint) → path under references/dictionaries/ | industry/

Hard rules

  1. No memorized payloads — resolve then Read the playbook file.
  2. No invented H1 case ids — only via --cite-h1 when local raw exists (often external/gitignored).
  3. No finding without Evidence — HTTP/screenshot/video or mark “待验证”.
  4. Stay in Scope — Phase 0 scope.md.
  5. Do not preload h1-reports/ or payloader/ trees — playbooks + dictionaries first (archive-locality.md).

Default bag

  • Top hits from playbook.js --signal …
  • On stuck: playbook.js --stuck
  • Fingerprints: resolve includes dictionary hits when keywords match

Not this skill’s job

PTES phase order, Docker bootstrap, Report template, knowledge import — phases / other skills.

Files

What ships with it

60 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 51 lines · 70 tokens per session scan A c530e11a39fd

Subscribe to this mod's changes

pentester-src-hunter is a skill published in the GitHub repository fb0sh/pentester (23 stars, last pushed 1mo ago), licensed MIT. It adds 70 tokens to every session and 535 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

transilience-report-style

Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.

transilienceai/communitytools · 31 tokens

firewall-review

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…

transilienceai/communitytools · 100 tokens

pentest-engagement

Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…

transilienceai/communitytools · 140 tokens

attack-path-stitcher

Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.

transilienceai/communitytools · 42 tokens

coordination

Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.

transilienceai/communitytools · 24 tokens

hackerone

HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.

transilienceai/communitytools · 36 tokens