pentesting skills

177 tagged pentesting, measured the same way as everything else here.

Browse within: offensive-security 82bug-bounty 67ai-security 58red-teaming 58codex-cli 33gemini-cli 33blueteaming 22incident-response 22recon 19ctf 17hackthebox 17opencode 11misc 10cybersecurity 9

metabigor

01

j3ssie/metabigor

Skill Claude CodeCodex

Use when operating the metabigor CLI for OSINT recon and infrastructure mapping without API keys. Covers finding network ranges from an ASN, org, domain, or IP (net); enumerating subdomains from certificate logs (cert); enriching IPs with ports/CVEs via Shodan InternetDB (ip); searching public GitHub code for secrets…

1.7k 23d ago A 143 tokens original MIT

bountyforge

02

Gabson0x/bountyforge

Skill Claude CodeCodex

All-round bug bounty skill covering smart contract audits (EVM/Solidity, Move/Aptos, Solana, TRON), web/API security, CI/CD pipeline attacks, LLM/AI security, and professional report generation for HackerOne, Bugcrowd, Intigriti, and Immunefi. Full pipeline — recon, pre-hunt learning from disclosed reports…

405 2d ago D 351 tokens

llm-testing

03

Eyadkelleh/awesome-skills-security

Skill Claude CodeCodex

Comprehensive LLM security testing prompts for bias detection, data leakage, alignment testing, and adversarial prompt resistance.

367 2mo ago A 27 tokens

exploit-sqli

06

crazyMarky/pentest-skills

Skill Claude CodeCodex

SQL injection detection and exploitation using sqlmap, manual techniques, and custom payloads. Use this skill when user needs to test for SQL injection vulnerabilities, extract database information, or exploit SQLi in parameters, headers, or cookies.

296 2mo ago A 51 tokens original Apache-2.0

exploit-xss

07

crazyMarky/pentest-skills

Skill Claude CodeCodex

Cross-site scripting (XSS) vulnerability detection and exploitation. Supports reflected XSS, stored XSS, DOM-based XSS, and blind XSS testing. Use this skill when user mentions XSS, cross-site scripting, script injection, or needs to test JavaScript injection in parameters, forms, headers, or DOM sources.

296 2mo ago A 71 tokens original Apache-2.0

results-storage

08

crazyMarky/pentest-skills

Skill Claude CodeCodex

SQLite-based persistent storage and reporting system for penetration testing results. Use this skill when user needs to store scan results, query vulnerabilities, generate reports, or manage pentest data across sessions.

296 2mo ago A 40 tokens original Apache-2.0

authenticating

09

Stickman230/claude-pentest

Skill Claude CodeCodex

Authentication testing skill - automates signup, login, 2FA bypass, CAPTCHA solving, and bot detection evasion using Playwright MCP. Tests authentication security controls. Includes behavioral biometrics simulation, OTP handling, and automated account creation for security assessments.

97 2mo ago A 54 tokens original MIT

mks

10

Stickman230/claude-pentest

Skill Claude CodeCodex

MKS (Metasploit-Kali Server) tool preference guide. Mount in Phase 0/1 alongside the primary skill. Provides URL resolution, REST endpoint patterns, response parsing, error handling, and fallback rules for all MKS-backed Kali tools.

97 2mo ago A 54 tokens original MIT

pentest

11

Stickman230/claude-pentest

Skill Claude CodeCodex

Penetration testing orchestrator that coordinates specialized attack agents. Provides attack indexes, methodology frameworks, and documentation. Execution delegated to specialized agents (SQL Injection, XSS, SSRF, etc.). Use for engagement planning and attack coordination.

97 2mo ago A 50 tokens original MIT

report

12

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-reporting guide for turning a confirmed vulnerability into a submission-ready DOCX report for security response or bug-bounty platforms.

66 9d ago A 183 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A specialized skill for analyzing Windows program files such as EXE, DLL, and driver files, including .NET applications. It covers examining how a program works and looking for security weaknesses.

66 9d ago A 129 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security skill for finding web vulnerabilities in user input, browser code, cross-origin settings, and rendered AI or Markdown content. XSS means injected content runs as someone else’s browser code; CSRF tricks a browser into making an unwanted request.

66 9d ago A 191 tokens original MIT

api-testing

15

ogrodev/fsociety

Skill Claude CodeCodex

Activate this skill whenever the user mentions API endpoint, REST API, RESTful, GraphQL, GraphQL introspection, GraphQL mutation, gRPC, gRPC reflection, WebSocket, WebSocket upgrade, WS endpoint, API security, API fuzzing, API enumeration, API versioning, API gateway, API rate limit, JWT, JSON Web Token, bearer token…

20 5mo ago A 366 tokens original MIT

payment-security

16

ogrodev/fsociety

Skill Claude CodeCodex

This skill should be used when the user mentions "payment", "payment gateway", "checkout", "IDOR payment", "payment bypass", "Stripe", "MercadoPago", "Binance Pay", "PIX", "PayPal", "Adyen", "Braintree", "Square", "Razorpay", "Mollie", "webhook", "payment webhook", "price manipulation", "amount tampering", "currency…

20 5mo ago A 308 tokens original MIT

reporting

17

ogrodev/fsociety

Skill Claude CodeCodex

This skill should be used when the user mentions "generate report", "pentest report", "engagement report", "findings report", "executive summary", "technical report", "vulnerability report", "remediation report", "remediation plan", "retest report", "write up findings", "document findings", "report findings", "create…

20 5mo ago A 290 tokens original MIT

huntbot

18

Matador-og/huntbot

Skill Claude CodeCodex

Autonomous offensive security pipeline. Use when the user wants to hunt bugs, run pentests, do recon, or manage huntbot targets. Triggers on security testing, bug bounty, vulnerability scanning, or any mention of huntbot commands.

10 2mo ago B 48 tokens

shangdi-w/-skills

Skill Claude CodeCodex

A toolkit for taking software apart to inspect how it works, across formats such as Android packages, Windows programs, Linux binaries, JavaScript, and firmware.

10 3mo ago A 97 tokens

redteam-av-evasion

20

shangdi-w/-skills

Skill Claude CodeCodex

A red-team security skill about avoiding antivirus detection, from basic principles to intermediate techniques. Red teams are authorised security testers who simulate attacks to find weaknesses.

10 3mo ago A 83 tokens

pentest-findings

21

jayelbotvibe-web/hermes-pentest-lab

Skill Claude CodeCodex

Pentest finding interpretation encyclopedia — maps tool output to finding severity, CVSS scoring rules, and report-ready language. Answers 'What severity is this? What's the CVSS? How do I write this up?'.

9 7d ago A 47 tokens original MIT

deep-security-audit

22

swDomass/AI_orchestrator

Skill Claude CodeCodex

Multi-agent deep security audit — 6 expert personas (pentester, architect, code auditor, supply chain, data privacy, forensics) + CISO synthesis + optional fix implementation.

5 15d ago A 41 tokens original MIT

allsmog/blackbox-claude-plugin

Skill Claude CodeCodex

This skill should be used when the user asks about "Active Directory", "Kerberoasting", "AS-REP roasting", "LDAP enumeration", "BloodHound", "DCSync", "Pass-the-Hash", "Golden Ticket", or needs guidance on attacking Windows domain environments.

5 6mo ago A 64 tokens original MIT

cacti-exploitation

24

allsmog/blackbox-claude-plugin

Skill Claude CodeCodex

This skill covers Cacti network monitoring tool exploitation including authenticated RCE via graph templates (CVE-2025-24367), unauthenticated command injection (CVE-2022-46169), and authentication bypass techniques.

5 6mo ago A 53 tokens original MIT