penetration testing skills

302 tagged penetration testing, measured the same way as everything else here.

Browse within: bugbounty 72web-security 69reverse-engineering 62fuzzing 61reconnaissance 60mcp-tools 59cybersecurity 57pentest 31api-security 27incident-response 27mitre-attack 27postgresql 24offensive-security 19owasp 18

usestrix/strix

Skill Claude CodeCodex

Security-test a REST, GraphQL, or gRPC API with Strix — autonomous agents that enumerate endpoints from an OpenAPI/GraphQL schema (or by crawling), then actually exploit the API-specific vulnerability classes in the OWASP API Security Top 10 (2023) — broken object-level authorization (BOLA/IDOR), broken object…

59k 3d ago A 144 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Fix security vulnerabilities found by a Strix pentest (open-source CLI or app.strix.ai cloud) — triage by severity, patch the root cause rather than the symptom, and re-run Strix to prove each fix actually closes the exploit. Handles injection, XSS, SSRF, broken access control, IDOR, and other validated findings. Use…

59k 3d ago A 124 tokens original Apache-2.0

usestrix/strix

Skill Claude CodeCodex

Run a managed pentest of a web app or API through the app.strix.ai REST API — no local Docker, LLM key, or install needed. Create an API token, register domain/repository assets, launch and poll scans, triage vulnerabilities, export SARIF, download PDF/DOCX pentest reports for SOC 2 and other compliance evidence…

59k 3d ago A 139 tokens original Apache-2.0

mukul975/Anthropic-Cybersecurity-Skills

Skill Claude CodeCodex

Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback domains, dead drops). Use after reverse engineering reveals network traffic needing protocol analysis or when building…

32k 8d ago A 81 tokens original Apache-2.0

GreyDGL/PentestGPT

Skill Claude CodeCodex

Configure this repo for the engineering skills — set up its issue tracker, triage label vocabulary, and domain doc layout. Run once before first use of the other engineering skills.

15k 1mo ago A 44 tokens original MIT

tdd

06

GreyDGL/PentestGPT

Skill Claude CodeCodex

Test-driven development. Use when the user wants to build features or fix bugs test-first, mentions "red-green-refactor", or wants integration tests.

15k 1mo ago A 33 tokens original MIT

GreyDGL/PentestGPT

Skill Claude CodeCodex

Reference for writing and editing skills well — the vocabulary and principles that make a skill predictable.

15k 1mo ago A 24 tokens original MIT

graphql

08

PentesterFlow/agent

Skill Claude CodeCodex

GraphQL pentest playbook — find the endpoint, dump the schema (introspection or field-suggestion fallback), then test for authorization gaps, query batching, alias overload, depth-based DoS, and SQLi/NoSQLi in resolver arguments. Use when the target exposes a /graphql endpoint, GraphiQL, Apollo, or accepts GraphQL…

1.3k 2mo ago A 75 tokens original Apache-2.0

jwt

09

PentesterFlow/agent

Skill Claude CodeCodex

JWT attack playbook — algorithm confusion (alg=none, HS/RS confusion), kid path traversal/SQLi, jku/x5u SSRF, weak HS256 cracking, and embedded JWK trickery. Use when the target uses JWTs for auth (header.payload.signature).

1.3k 2mo ago A 60 tokens original Apache-2.0

supabase

10

PentesterFlow/agent

Skill Claude CodeCodex

Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked servicerole) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse (insert/update/delete — e.g. forging…

1.3k 2mo ago A 120 tokens original Apache-2.0

chAng-L19/codex-redteam-mode

Skill Claude CodeCodex

Compact operational boundary policy for durable red-team workflows. It does not route domains or decide workflow completion.

1.0k 8d ago A 26 tokens original MIT

kali-pentest-zh

13

x-glacier/kali-pentest

Skill Claude CodeCodex

A Chinese-language guide for carrying out authorized penetration tests with Kali Linux command-line tools through a local system, SSH, or Docker.

101 2mo ago A 87 tokens original Apache-2.0

kali-pentest

14

x-glacier/kali-pentest

Skill Claude CodeCodex

Execute authorized penetration testing via Kali Linux CLI tools over SSH or Docker. Covers: information gathering, vulnerability analysis, sniffing & spoofing, web/API testing, exploitation, password attacks, wireless, cloud-native security, RFID/NFC, VoIP/ICS, reverse engineering, forensics, post-exploitation/C2, and…

101 2mo ago A 73 tokens original Apache-2.0

pentest

16

Strategic-Automation/violin

Skill Claude CodeCodex

Supervised authorized pentest: scope, route, validate, report.

84 yesterday A 17 tokens original MIT

web-app

17

Strategic-Automation/violin

Skill Claude CodeCodex

Web application testing: injection and client-side flaws.

84 yesterday A 13 tokens original MIT

cwe

18

0dayInc/pwn

Skill Claude CodeCodex

Exhaustively test a target against every applicable CWE.

76 3d ago A 14 tokens original MIT

osint

19

0dayInc/pwn

Skill Claude CodeCodex

Drive extroosint with the right kind, feeds, pivots, and keys.

76 3d ago A 21 tokens original MIT

penetration-testing

20

0dayInc/pwn

Skill Claude CodeCodex

Run a scoped pentest with NmapIt, Burp, Metasploit, and a written report.

76 3d ago A 26 tokens original MIT