pentest-tools

pentest-tools is a skill for Claude Code, Codex from Unclecheng-li/DeepSec. It costs 66 tokens per session (525 once invoked), scanned A, a copy of pentest-tools, MIT.

A quick reference for tools and commands used in authorised penetration testing, which checks systems for security weaknesses.

In plain words
What is it for?
Choosing or recalling tools for encoding, reverse shells, vulnerability testing, password attacks, network discovery, internal-network testing, credential collection, privilege escalation, tunnelling, web testing, and Windows testing.
Why use it?
It reduces the time spent remembering tool names, command options, and which tool fits a known testing task.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/unclecheng-li/deepsec/pentest-tools
Any agent
npx skills add Unclecheng-li/DeepSec --skill pentest-tools
Clone the repo
git clone --depth 1 https://github.com/Unclecheng-li/DeepSec

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for pentest-tools

README.md
[![agentmods](https://agentmods.dev/badge/skills/unclecheng-li/deepsec/pentest-tools.svg)](https://agentmods.dev/skills/unclecheng-li/deepsec/pentest-tools)
Your own site
<a href="https://agentmods.dev/skills/unclecheng-li/deepsec/pentest-tools"><img src="https://agentmods.dev/badge/skills/unclecheng-li/deepsec/pentest-tools.svg" alt="Measured on agentmods" height="20"></a>
Per session 66 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 525 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00066 $0.00525
Opus 5 $0.00033 $0.00262
Sonnet 5 $0.00013 $0.00105
Haiku 4.5 $0.00007 $0.00052

Measured 5d ago against content hash 152978e80064, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

pentest-tools scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to pentest-tools — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

deepsec/spear/skills/specialized/pentest-tools/SKILL.md · 41 lines

What it actually says

渗透工具速查 Skill

当已知测试方向,需要选型工具或回忆命令时使用本 Skill。是操作支撑层,不是方法论替代。

使用场景

  • 已确认漏洞类型,需要对应工具和命令
  • 记不住某个工具的具体参数
  • 需要快速筛选同一任务下的候选工具

边界:本 Skill 帮助选型和回忆工具,不替代方法论。工具选择应跟随当前工作流阶段,而不是反过来。

工具分类速查

分类 覆盖范围
编码解码 Base64/URL/Hex/Unicode/HTML 编解码
反向 Shell Bash/Python/PowerShell/Netcat/Socat
红队工具 Cobalt Strike/Metasploit/Covenant
漏洞利用 Exploit-DB/Searchsploit/自动化框架
密码攻击 Hashcat/John/Hydra/Cewl
内网渗透 Impacket/CrackMapExec/BloodHound
凭据窃取 Mimikatz/LaZagne/Secretsdump
提权 LinPEAS/WinPEAS/PowerUp/BeRoot
隧道代理 Chisel/Ligolo/FRP/Socat/SSH
系统命令 Linux/Windows 常用命令集
信息收集 Nmap/Masscan/Amass/Subfinder
域渗透 BloodHound/Certipy/Rubeus/Kekeo
Web 工具 SQLmap/Nuclei/FFUF/Burp
Windows 渗透 PowerShell/WMI/WMIC/PowerView

参考文档

  • references/tools-reference-01~14-*.md — 各工具分类详细参考(14 个)
  • references/pentest-tools-reference-skill.md — 工具参考入口
  • references/tools-reference-index.md — 工具参考索引
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 41 lines · 66 tokens per session scan A 152978e80064

Subscribe to this mod's changes

pentest-tools is a skill published in the GitHub repository Unclecheng-li/DeepSec (386 stars, last pushed 11d ago), licensed MIT. It adds 66 tokens to every session and 525 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to pentest-tools, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

defense-evasion

Endpoint defense bypass — AMSI/ETW patching, ScareCrow framework, custom loaders, direct/indirect syscalls, LOLBAS execution, process injection.

PurpleAILAB/Decepticon · 40 tokens

final-report

Final engagement report generation — executive summary, technical report, findings aggregation, attack path narrative, detection gap matrix, remediation roadmap.

PurpleAILAB/Decepticon · 28 tokens

exploit-reporting

Exploitation finding documentation — initial access reports, exploit chain documentation, CVSS v4.0 scoring, shell/credential inventory, detection gap analysis.

PurpleAILAB/Decepticon · 35 tokens

ti-ioc-extraction

Automated IOC extraction from threat reports, logs, and unstructured text — parse hashes, IPs, domains, URLs, email addresses, and CVEs. Covers regex-based extraction, defanging/refanging, bulk hash lookup, IOC deduplication, YARA rule generation from IOCs, and STIX/TAXII formatting for sharing.

PurpleAILAB/Decepticon · 75 tokens

ti-yara-hunting

YARA rule writing from behavioral observations and TI report analysis — sample-to-rule conversion, condition optimization, performance tuning, and retrohunting on VirusTotal and ANY.RUN. Covers YARA/YARA-X syntax, yarGen automated generation, and production rule deployment.

PurpleAILAB/Decepticon · 58 tokens

m365-mailbox-compromise

Microsoft 365 mailbox compromise chain — OAuth consent phishing, delegate access abuse, mail rule persistence, and token theft via device code phishing. Full kill chain from initial access to persistent email collection.

PurpleAILAB/Decepticon · 45 tokens