Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/fb0sh/pentester/rapid-checklistnpx skills add fb0sh/pentester --skill rapid-checklistgit clone --depth 1 https://github.com/fb0sh/pentesterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fb0sh/pentester/rapid-checklist)<a href="https://agentmods.dev/skills/fb0sh/pentester/rapid-checklist"><img src="https://agentmods.dev/badge/skills/fb0sh/pentester/rapid-checklist.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00042 | $0.00918 |
| Opus 5 | $0.00021 | $0.00459 |
| Sonnet 5 | $0.00008 | $0.00184 |
| Haiku 4.5 | $0.00004 | $0.00092 |
Grade A, and why
rapid-checklist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to rapid-checklist — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
渗透速查与 Payload Skill
仅在路由已明确后使用。本 Skill 用于快速查找,不替代方法论或工作流选择。
使用场景
- 快速回忆某类漏洞或阻塞点应该先看什么
- 快速筛选 Payload 家族、绕过方向和验证顺序
- 快速确认 AI、MCP、容器、WebSocket、JWT、文件、认证、SSRF 等常见测试卡片
- 从"我知道要测什么"进入"我先从哪一类验证开始"
不适用场景
- 替代场景分流 → 用
pentest-flow - 替代方法论决策 → 用对应专项 Skill
- 请求未抓到、重放未稳定时盲测 → 先用
client-reverse
CTF 专项速查
CTF 题目优先用
ctf-web/ctf-crypto/ctf-miscSkill,以下为快速卡片:
| 场景 | 快速定位 |
|---|---|
| PHP 弱比较 → 0e 开头 MD5 值 | ctf-web → php-bypass-cheatsheet.md |
| 命令注入空格绕过 → ${IFS}/$IFS$9/< | ctf-web → command-injection-bypass.md |
| eval 无回显 → 写文件/DNS 外带 | ctf-web → eval-and-rce-techniques.md |
| RSA 小指数 → 立方根/Coppersmith | ctf-crypto → rsa-attacks-cheatsheet.md |
Python Jail → __import__/func_globals |
ctf-misc → python-jail-escape.md |
| 编码链 → base64→hex→ROT13 多层 | ctf-misc → encoding-chain-reference.md |
快速路由卡片
Web 注入 / 输出执行
- SQLi →
',",), 布尔差异, 时间差异, 报错差异 - XSS →
<script>,<img onerror>,javascript:, DOM sink - 命令注入 →
;id,|id,`id`,$(id) - SSTI →
{{7*7}},${7*7},<%= 7*7 %>, 模板引擎指纹 - XXE →
<!ENTITY>, 参数实体, OOB 外带
认证 / 逻辑 / Token
- JWT → none算法, 算法篡改, 密钥爆破, jku/x5u 注入
- CSRF → 缺少 Token, Token 可预测, Referer 校验缺陷
- IDOR → 修改 ID 参数, 批量遍历
- 支付逻辑 → 金额篡改, 负数, 竞态
浏览器签名 / 反爬
- 先用
client-reverse稳定重放 - 阶段: locate → recover → runtime → validation
安卓运行态 / 签名恢复
- 先用
client-reverseruntime-first 路径 - 只有抓不到包/加密/无法重放时再逆向
AI / MCP
- Prompt 注入 → 直接/间接/CoT 干扰
- 工具滥用 → MCP 投毒/指令覆盖
- 身份逃逸 → 角色越界/权限漂移
内网 / AD
- 先用
intranet-pentest-advanced - 工具不确定时补看
pentest-tools
参考文档
references/08-rapid-checklists-and-payloads.md— 速查与 Payload 整合参考references/testing-methodology.md— 测试方法论
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 4d ago First seen · 72 lines · 42 tokens per session scan A e696e8d9dd45
rapid-checklist is a skill published in the GitHub repository fb0sh/pentester (23 stars, last pushed 1mo ago), licensed MIT. It adds 42 tokens to every session and 918 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to rapid-checklist, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
transilience-report-style
Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.
firewall-review
Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…
pentest-engagement
Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…
attack-path-stitcher
Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.
coordination
Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.
hackerone
HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.