Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/unclecheng-li/deepsec/pentest-toolsnpx skills add Unclecheng-li/DeepSec --skill pentest-toolsgit clone --depth 1 https://github.com/Unclecheng-li/DeepSecWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/unclecheng-li/deepsec/pentest-tools)<a href="https://agentmods.dev/skills/unclecheng-li/deepsec/pentest-tools"><img src="https://agentmods.dev/badge/skills/unclecheng-li/deepsec/pentest-tools.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00066 | $0.00525 |
| Opus 5 | $0.00033 | $0.00262 |
| Sonnet 5 | $0.00013 | $0.00105 |
| Haiku 4.5 | $0.00007 | $0.00052 |
Grade A, and why
pentest-tools scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to pentest-tools — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
What it actually says
渗透工具速查 Skill
当已知测试方向,需要选型工具或回忆命令时使用本 Skill。是操作支撑层,不是方法论替代。
使用场景:
- 已确认漏洞类型,需要对应工具和命令
- 记不住某个工具的具体参数
- 需要快速筛选同一任务下的候选工具
边界:本 Skill 帮助选型和回忆工具,不替代方法论。工具选择应跟随当前工作流阶段,而不是反过来。
工具分类速查
| 分类 | 覆盖范围 |
|---|---|
| 编码解码 | Base64/URL/Hex/Unicode/HTML 编解码 |
| 反向 Shell | Bash/Python/PowerShell/Netcat/Socat |
| 红队工具 | Cobalt Strike/Metasploit/Covenant |
| 漏洞利用 | Exploit-DB/Searchsploit/自动化框架 |
| 密码攻击 | Hashcat/John/Hydra/Cewl |
| 内网渗透 | Impacket/CrackMapExec/BloodHound |
| 凭据窃取 | Mimikatz/LaZagne/Secretsdump |
| 提权 | LinPEAS/WinPEAS/PowerUp/BeRoot |
| 隧道代理 | Chisel/Ligolo/FRP/Socat/SSH |
| 系统命令 | Linux/Windows 常用命令集 |
| 信息收集 | Nmap/Masscan/Amass/Subfinder |
| 域渗透 | BloodHound/Certipy/Rubeus/Kekeo |
| Web 工具 | SQLmap/Nuclei/FFUF/Burp |
| Windows 渗透 | PowerShell/WMI/WMIC/PowerView |
参考文档
references/tools-reference-01~14-*.md— 各工具分类详细参考(14 个)references/pentest-tools-reference-skill.md— 工具参考入口references/tools-reference-index.md— 工具参考索引
What ships with it
16 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
- references/pentest-tools-reference-openai.yaml 291 B
- references/pentest-tools-reference-skill.md 2.8 KB
- references/tools-reference-01-encoding-decoding.md 4.9 KB
- references/tools-reference-03-red-team-tools.md 729 B
- references/tools-reference-04-exploitation.md 8.7 KB
- references/tools-reference-05-password-attacks.md 7.6 KB
- references/tools-reference-06-intranet-penetration.md 12 KB
- references/tools-reference-07-credential-theft.md 1.8 KB
- references/tools-reference-08-privilege-escalation.md 1.6 KB
- references/tools-reference-09-tunneling-and-proxy.md 1.3 KB
- references/tools-reference-10-system-commands.md 6.2 KB
- references/tools-reference-11-information-gathering.md 13 KB
- references/tools-reference-12-domain-penetration.md 898 B
- references/tools-reference-13-web-penetration.md 11 KB
- references/tools-reference-14-windows-penetration.md 947 B
- references/tools-reference-index.md 860 B
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 41 lines · 66 tokens per session scan A 152978e80064
pentest-tools is a skill published in the GitHub repository Unclecheng-li/DeepSec (386 stars, last pushed 11d ago), licensed MIT. It adds 66 tokens to every session and 525 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to pentest-tools, differing in 0 lines, and is treated as a copy.
Other skills, from other repositories
defense-evasion
Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.
final-report
Final engagement report generation — executive summary, technical report, findings aggregation, attack path narrative, detection gap matrix, remediation roadmap.
exploit-reporting
Exploitation finding documentation — initial access reports, exploit chain documentation, CVSS v4.0 scoring, shell/credential inventory, detection gap analysis.
ti-ioc-extraction
Automated IOC extraction from threat reports, logs, and unstructured text — parse hashes, IPs, domains, URLs, email addresses, and CVEs. Covers regex-based extraction, defanging/refanging, bulk hash lookup, IOC deduplication, YARA rule generation from IOCs, and STIX/TAXII formatting for sharing.
ti-yara-hunting
YARA rule writing from behavioral observations and TI report analysis — sample-to-rule conversion, condition optimization, performance tuning, and retrohunting on VirusTotal and ANY.RUN. Covers YARA/YARA-X syntax, yarGen automated generation, and production rule deployment.
m365-mailbox-compromise
Microsoft 365 mailbox compromise chain — OAuth consent phishing, delegate access abuse, mail rule persistence, and token theft via device code phishing. Full kill chain from initial access to persistent email collection.