NeoTheCapt/RedteamAgent

An AI red-team agent for authorized labs and web app pentesting workflows. Turns Claude Code / OpenCode / Codex into a structured recon → test → exploit → report workflow, with containerized tools and resumable state.

122Stars on the repository
54Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

auth-bypass

01

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses.

122 1mo ago A 22 tokens

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws.

122 1mo ago B 23 tokens

file-inclusion

08

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution.

122 1mo ago B 20 tokens

jwt-testing

13

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

JWT token attack techniques — alg bypass, key confusion, claim tampering.

122 1mo ago A 17 tokens

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains.

122 1mo ago A 25 tokens

osint-recon

15

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

Open-source intelligence gathering — CVE lookup, breach search, DNS history, social profiling.

122 1mo ago A 22 tokens

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts.

122 1mo ago A 30 tokens

sqli-testing

23

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

Detect and exploit SQL injection vulnerabilities in web application parameters.

122 1mo ago A 14 tokens

ssrf-testing

24

NeoTheCapt/RedteamAgent

Skill Claude CodeCodex

Detect and exploit server-side request forgery to access internal resources and cloud metadata.

122 1mo ago B 19 tokens