H-mmer/pentest-agents

Bug bounty agent framework for Claude Code, Codex, Gemini, Cursor, Windsurf, Copilot, and OpenClaw — 48 agents, 26 commands, 19 CLI tools, 2 MCP servers, autonomous hunt loops, exploit chain builder.

815Stars on the repository
205Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

analyze

01

H-mmer/pentest-agents

Skill Claude CodeCodex

Analyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze.

not rated 815 +2 2mo ago A 25 tokens

autopilot

02

H-mmer/pentest-agents

Skill Claude CodeCodex

Autonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine ≥25 attempts/class, wall-clock floor 90 min/target, PRE-COMPLETION GATE before any summary). No early stops, no clarifying questions, no auxiliary-agent…

not rated 815 +2 2mo ago B 105 tokens

brain

03

H-mmer/pentest-agents

Skill Claude CodeCodex

Manage the engagement brain. Subcommands: 'init' to set up, 'brief ' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.

not rated 815 +2 2mo ago A 44 tokens

chain

04

H-mmer/pentest-agents

Skill Claude CodeCodex

Build deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A).

not rated 815 +2 2mo ago A 33 tokens

correlate

05

H-mmer/pentest-agents

Skill Claude CodeCodex

Run the finding correlation engine to discover attack chains from individual findings.

not rated 815 +2 2mo ago A 17 tokens

cost

06

H-mmer/pentest-agents

Skill Claude CodeCodex

Show cost tracking and ROI for this engagement.

not rated 815 +2 2mo ago A 11 tokens

dupcheck

07

H-mmer/pentest-agents

Skill Claude CodeCodex

Check if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck e.g. /dupcheck XSS in search endpoint.

not rated 815 +2 2mo ago A 43 tokens

fullscan

08

H-mmer/pentest-agents

Skill Claude CodeCodex

Full security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.

not rated 815 +2 2mo ago A 25 tokens

hunt

09

H-mmer/pentest-agents

Skill Claude CodeCodex

Active vulnerability hunting on a target. Loads scope, reads brain, detects tech stack, runs targeted tests with concrete payloads. Usage: /hunt target.com [--vuln-class idor|xss|ssrf|sqli|ssti|oauth|rce|race|graphql|upload|business-logic|llm-ai].

not rated 815 +2 2mo ago F 73 tokens

learn

10

H-mmer/pentest-agents

Skill Claude CodeCodex

Record a platform response and update learning. Usage: /learn [--bounty 500] [--vuln-type XSS].

not rated 815 2mo ago A 37 tokens

mindmap

11

H-mmer/pentest-agents

Skill Claude CodeCodex

Generate a text-based attack surface mindmap. Shows tech stack → vuln class → endpoint relationships. Usage: /mindmap.

not rated 815 2mo ago A 30 tokens

monitor

12

H-mmer/pentest-agents

Skill Claude CodeCodex

Monitor targets for changes. Usage: /monitor baseline (first run), /monitor check (detect changes), /monitor scope (check platform for scope updates).

not rated 815 2mo ago A 33 tokens

new

13

H-mmer/pentest-agents

Skill Claude CodeCodex

Create a new engagement workspace. Usage: /new [--type web-app|api|mobile|smart-contract].

not rated 815 2mo ago A 31 tokens

pipeline

14

H-mmer/pentest-agents

Skill Claude CodeCodex

Prepare the battlefield — recon, scanning, and surface ranking. Stops before hunting. Run /hunt or /autopilot after. Usage: /pipeline or /pipeline.

not rated 815 2mo ago A 38 tokens

quality

15

H-mmer/pentest-agents

Skill Claude CodeCodex

Score a report draft before submission. Usage: /quality.

not rated 815 2mo ago A 21 tokens

quickscan

16

H-mmer/pentest-agents

Skill Claude CodeCodex

Run a quick security scan on a target. Consults the Brain first, validates scope, runs passive recon + vuln scan in parallel.

not rated 815 2mo ago A 30 tokens

remember

17

H-mmer/pentest-agents

Skill Claude CodeCodex

Log a finding or pattern to persistent brain memory. Auto-fills from session context. Usage: /remember.

not rated 815 2mo ago A 23 tokens

report

18

H-mmer/pentest-agents

Skill Claude CodeCodex

Generate submission-ready reports for all confirmed findings. Runs dedup, PoC builder, quality check, and report writer. Usage: /report bounty or /report pentest.

not rated 815 2mo ago A 36 tokens

resume

19

H-mmer/pentest-agents

Skill Claude CodeCodex

Resume a previous hunt. Shows hunt history, untested endpoints, memory-informed suggestions. Usage: /resume target.com.

not rated 815 2mo ago B 25 tokens

sast

20

H-mmer/pentest-agents

Skill Claude CodeCodex

Source code vulnerability hunting (SAST). Decomposes analysis into specialized passes: map entry points, map dangerous ops, trace flows, find gaps, adversarial validation, exploit. Usage: /sast [--lang c|cpp|rust|java|python|go|php] [--min-score 4] [--max-files 30] [--skip-static] [--best-of N].

not rated 815 2mo ago A 90 tokens

status

21

H-mmer/pentest-agents

Skill Claude CodeCodex

Show engagement dashboard with program info, scope, brain state, findings, agent activity, and cost estimate.

not rated 815 2mo ago A 23 tokens

submit

22

H-mmer/pentest-agents

Skill Claude CodeCodex

Draft and submit a vulnerability report to the bug bounty platform. Reads scope.yaml for platform/program, uses brain + findings for content. Always drafts first for review.

not rated 815 2mo ago A 34 tokens

surface

23

H-mmer/pentest-agents

Skill Claude CodeCodex

Show ranked attack surface for a target. Invokes recon-ranker agent. Usage: /surface target.com.

not rated 815 2mo ago A 23 tokens

sync

24

H-mmer/pentest-agents

Skill Claude CodeCodex

Sync program scope, policy, and hacktivity from a bug bounty platform. Usage: /sync hackerone tesla or /sync bugcrowd uber.

not rated 815 2mo ago A 33 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: