transilienceai/communitytools

Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research

505Stars on the repository
66Mods indexed here, across every type
1mo agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

ai-threat-testing

02

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.

not rated 505 +4 1mo ago A 55 tokens original MIT

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.

not rated 505 +4 1mo ago A 42 tokens original MIT

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. Use when the highest-value authenticated classes (BOLA/IDOR/mass-assignment/injection on the real data APIs) are blocked…

not rated 505 +4 1mo ago A 114 tokens original MIT

authentication

06

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.

not rated 505 +4 1mo ago A 32 tokens original MIT

blockchain-security

07

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Smart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testing smart contract…

not rated 505 +4 1mo ago A 58 tokens original MIT

client-side

08

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.

not rated 505 +4 1mo ago A 38 tokens original MIT

cloud-defense

10

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. Use for cloud detection engineering, hardening, remediation write-ups, or blue-team posture review of the lateral-movement ->…

not rated 505 +4 1mo ago A 82 tokens original MIT

coordination

11

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.

not rated 505 +4 1mo ago A 24 tokens original MIT

cryptography

12

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Cryptanalysis techniques — lattice attacks, padding oracles, weak-RNG exploitation, signature forgery, secret-sharing recovery.

not rated 505 +4 1mo ago A 27 tokens original MIT

cve-poc-generator

13

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

CVE research, standalone PoC script and report generation. Given a CVE ID, researches NVD and advisories, generates a safe Python PoC, and writes a detailed vulnerability report.

not rated 505 +4 1mo ago A 45 tokens original MIT

cve-risk-score

14

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Retrieve CVE risk scores from NVD. Auto-invoked whenever a CVE ID is mentioned to display CVSS score, severity, CWE, and description.

not rated 505 +4 1mo ago A 38 tokens original MIT

dfir

15

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. Use when investigating security incidents, analyzing Sherlocks, or performing threat hunting on provided evidence files.

not rated 505 +4 1mo ago A 51 tokens original MIT

essential-tools

16

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Core pentesting tools and methodology - Burp Suite usage, Playwright automation, binary analysis, testing methodology, and professional reporting standards.

not rated 505 +4 1mo ago A 30 tokens original MIT

firewall-review

17

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Evidence-safe firewall ruleset audit reference specification — 22 documented detector patterns (17 vendor-agnostic plus 5 FortiGate-specific), a 15-check semantic catalogue, CIS Fortinet FortiGate Benchmark guidance, a custom customer-policy benchmark, and consolidated network-team Excel profiles including grouped…

not rated 505 +4 1mo ago A 100 tokens original MIT

github-workflow

18

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

GitHub workflow automation — branching, committing, pushing, pull requests, issues, and code review. Use when asked to commit, push, create PRs/branches/issues, or manage git workflow.

not rated 505 +4 1mo ago A 44 tokens original MIT

hackerone

19

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.

not rated 505 +4 1mo ago A 36 tokens original MIT

hackthebox

20

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

HackTheBox platform operations and automations to solve challenges, machines and capture the flags hacking competitions.

not rated 505 +4 1mo ago A 23 tokens original MIT

infrastructure

21

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Network infrastructure testing - port scanning, DNS attacks, MITM, VLAN hopping, IPv6, SMB/NetBIOS, sniffing, and DoS assessment.

not rated 505 +4 1mo ago A 36 tokens original MIT

injection

22

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Injection vulnerability testing - SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection techniques.

not rated 505 +4 1mo ago A 28 tokens original MIT

mobile-security

23

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Mobile application security testing (Android + iOS) mapped to OWASP MASVS/MASTG — static reversing (Flutter AOT, Unity IL2CPP, React Native/Hermes, native ARM64, Mach-O/Swift), SAST (manifest/IPC, storage, crypto, signing), dynamic analysis (Frida/objection, TLS-pinning + root/jailbreak bypass, traffic interception)…

not rated 505 +4 1mo ago A 90 tokens original MIT

transilienceai/communitytools

Skill Claude CodeCodex

Part of communitytools

Offensive testing of perimeter network appliances and VPN crypto — IKE/IPsec (aggressive-mode, transform/DH enum, NAT-T), Check Point SIC/OPSEC, safe firmware/patch-level inference for FortiGate/PAN-OS/Cisco ASA/Citrix feeding CVE applicability, NTLM Type-2 target-info decode, handshake-completion TLS-version probing…

not rated 505 +4 1mo ago A 139 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: