pentest skills

276 tagged pentest, measured the same way as everything else here.

Browse within: pentest-tool 100payload 61dictionary 60fuzz 60hacking 60ai-framework 58bounty-hunters 42hackerone 42security-research 42owasp 41cybersecurity 37penetration-testing 31attack-surface-management 26easm 26

wgpsec/AboutSecurity

Skill Claude CodeCodex

Use this skill whenever the user asks to add, absorb, migrate, port, update, merge, compare, or extract security knowledge into the AboutSecurity repository from any external resource such as InternalAllTheThings, blog posts, tools, docs, PRs, screenshots, notes, or URLs. This skill SOPs the full workflow: first…

1.7k 1mo ago A 0 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for moving from a compromised Azure or Entra ID cloud account into an on-premises Active Directory network. Active Directory is commonly used to manage users and computers inside an organization.

1.7k 1mo ago A 160 tokens

gcp-workspace-pivot

03

wgpsec/AboutSecurity

Skill Claude CodeCodex

A playbook for moving from Google Cloud Platform (GCP) into Google Workspace, the suite containing services such as Gmail, Drive, Calendar, and administration tools.

1.7k 1mo ago A 105 tokens

transilienceai/communitytools

Skill Claude CodeCodex

Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.

494 1mo ago A 31 tokens original MIT

firewall-review

05

transilienceai/communitytools

Skill Claude CodeCodex

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…

494 1mo ago A 100 tokens original MIT

pentest-engagement

06

transilienceai/communitytools

Skill Claude CodeCodex

Run a professional penetration engagement OR a network vulnerability scan from a scope. WEB mode (apex domains / app URLs) — mandatory surface expansion, systematic OWASP attack-class coverage, reversible active exploitation, authoritative validation, Transilience PDF. NETWORK mode (a list of IPs/CIDRs, e.g. 1500…

494 1mo ago A 140 tokens original MIT

pentest-redteam

07

0rangec3t/Black-cat

Skill Claude CodeCodex

An authorized red-team framework for testing systems through stated assumptions. Red teaming is a permitted security exercise that imitates attacks to find weaknesses.

301 29d ago A 41 tokens

oasm-platform/open-asm

Skill Claude CodeCodex

Anti-slop frontend skill for landing pages, portfolios, and redesigns. The agent reads the brief, infers the right design direction, and ships interfaces that do not look templated. Real design systems when applicable, audit-first on redesigns, strict pre-flight check.

180 2d ago A 61 tokens GPL-3.0

oasm-platform/open-asm

Skill Claude CodeCodex

Upgrades existing websites and apps to premium quality. Audits current design, identifies generic AI patterns, and applies high-end design standards without breaking functionality. Works with any CSS framework or vanilla CSS.

180 2d ago A 45 tokens GPL-3.0

shadcn

10

oasm-platform/open-asm

Skill Claude CodeCodex

Manages shadcn components and projects — adding, searching, fixing, debugging, styling, and composing UI. Provides project context, component docs, and usage examples. Applies when working with shadcn/ui, component registries, presets, --preset codes, or any project with a components.json file. Also triggers for…

180 2d ago A 90 tokens GPL-3.0

binary-analysis

11

CommonHuman-Lab/nyxstrike

Skill Claude CodeCodex

Binary analysis and reverse engineering workflow using checksec, strings, binwalk, radare2, ropgadget, and gdb for CTF and vulnerability research.

144 3d ago A 35 tokens

cloud-audit

12

CommonHuman-Lab/nyxstrike

Skill Claude CodeCodex

Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images.

144 3d ago A 38 tokens

exploitation

13

CommonHuman-Lab/nyxstrike

Skill Claude CodeCodex

Exploitation workflow using Metasploit, msfvenom payload generation, and Exploit-DB search — from vulnerability identification to shell.

144 3d ago A 30 tokens

incogbyte/android-reverse-engineering-claude-skill

Skill Claude CodeCodex

Decompile Android APK, XAPK, AAB, DEX, JAR, and AAR files using jadx or Fernflower/Vineflower. Reverse engineer Android apps, extract HTTP API endpoints (Retrofit, OkHttp, Volley, GraphQL, WebSocket), trace call flows from UI to network layer, analyze security patterns (cert pinning, exposed secrets, Android Fragment…

108 2mo ago A 196 tokens original Unlicense

pentest

16

Strategic-Automation/violin

Skill Claude CodeCodex

Supervised authorized pentest: scope, route, validate, report.

84 yesterday A 17 tokens original MIT

web-app

17

Strategic-Automation/violin

Skill Claude CodeCodex

Web application testing: injection and client-side flaws.

84 yesterday A 13 tokens original MIT

command-execution

19

iammm0/secbot

Skill Claude CodeCodex

Security-focused command execution techniques for penetration testing. Use this skill when executing system commands during authorized security assessments. Covers Windows and Linux command execution, common security testing commands, and best practices for avoiding detection.

73 16d ago A 45 tokens