ai-penetration-testing skills

233 tagged ai-penetration-testing, measured the same way as everything else here.

Browse within: ai-hacking 169aws 169cis 169ai-pentesting 100cis-database 58cis-compute 54compute 54iam 390x4m4 31appsecco 31asyncio 31kali 31cis-iam 25ec2 25

usestrix/strix

Skill Claude CodeCodex

Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object…

not rated 60k +541 changed yesterday A 144 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Fix security vulnerabilities found by a Strix pentest (open-source CLI or app.strix.ai cloud) — triage by severity, patch the root cause rather than the symptom, and re-run Strix to prove each fix actually closes the exploit. Handles injection, XSS, SSRF, broken access control, IDOR, and other validated findings. Use…

not rated 60k +541 changed yesterday A 124 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Test an application against the OWASP Top 10 with Strix — autonomous AI agents that attempt real exploits for each category of the current OWASP Top 10:2025 (broken access control including SSRF, security misconfiguration, software supply chain failures, cryptographic failures, injection, insecure design…

not rated 60k +541 changed yesterday A 151 tokens original Apache-2.0

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

A skill for examining Android packages, Windows executables, native libraries, and some cross-platform app binaries to understand how they work.

not rated 6.2k +151 8d ago A 70 tokens original Apache-2.0

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

A method for finding attack chains by combining smaller capabilities such as reading files, writing files, making server requests, or using credentials. It treats a serious outcome as a sequence of separately gained abilities.

not rated 6.2k +151 8d ago A 67 tokens original Apache-2.0

Ed1s0nZ/CyberStrikeAI

Skill Claude CodeCodex

A collection of cybersecurity playbooks for investigating and exploiting specific systems, including GoEdge CDN, ARP man-in-the-middle attacks, BT Panel, OCS, MinIO, and CDN-to-S3 access chains.

not rated 6.2k +151 8d ago A 91 tokens original Apache-2.0

api-canvas

10

wallieinformal201/pentest-mcp-server

Skill Claude CodeCodex

Part of @cyanheads/pentest-mcp-server

DataCanvas primitive reference — a Tier 3 SQL/analytical workspace for tabular MCP servers, backed by DuckDB. Use when registering tables from upstream APIs, running ad-hoc SQL across them, and exporting results. Covers the acquire → register → query → export flow, the token-sharing pattern for multi-agent…

not rated 2 3d ago A 81 tokens original Apache-2.0

api-context

11

wallieinformal201/pentest-mcp-server

Skill Claude CodeCodex

Part of @cyanheads/pentest-mcp-server

Canonical reference for the unified Context object passed to every tool and resource handler in @cyanheads/mcp-ts-core. Covers the full interface, all sub-APIs (ctx.log, ctx.state, ctx.elicit, ctx.sample, ctx.progress, ctx.enrich), and when to use each.

not rated 2 3d ago A 72 tokens original Apache-2.0

api-telemetry

12

wallieinformal201/pentest-mcp-server

Skill Claude CodeCodex

Part of @cyanheads/pentest-mcp-server

Catalog of OpenTelemetry instrumentation built into framework @cyanheads/mcp-ts-core — spans, metrics, completion logs, env config, runtime caveats, custom instrumentation patterns, and cardinality rules. Use when enabling OTel export, adding custom spans or metrics in services, debugging missing telemetry, looking up…

not rated 2 3d ago A 85 tokens original Apache-2.0

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: