xAmirHamza77 /PenKit51
Skill Claude Code Codex
Authorized AI penetration testing assistant for web applications, APIs, and infrastructure. Performs reconnaissance, vulnerability assessment, PoC validation, exploit chaining, and professional reporting. Use when the user asks for pentest, penetration test, security assessment, vulnerability scan, bug bounty…
★ not rated 2 2mo ago A 81 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
A set of methods for testing the security of APIs, which are interfaces that let software exchange data and request actions.
★ not rated 2 2mo ago A 13 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
JWT and OIDC security testing covering token forgery, algorithm confusion, and claim manipulation.
★ not rated 2 2mo ago A 22 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
AWS cloud security testing covering IAM misconfigurations, S3 exposure, metadata abuse, and privilege escalation paths.
★ not rated 2 2mo ago C 26 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
BFLA testing for action-level authorization failures across endpoints, admin functions, and API operations.
★ not rated 2 2mo ago A 24 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Fast browser automation CLI for AI agents. Chrome/Chromium via CDP, no Playwright or Puppeteer dependency. Accessibility-tree snapshots with compact @eN refs let agents interact with pages in 200-400 tokens instead of parsing raw HTML.
★ not rated 2 2mo ago A 49 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Business logic testing for workflow bypass, state manipulation, and domain invariant violations.
★ not rated 2 2mo ago B 19 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
A set of methods for auditing cloud security, meaning checking whether systems and data hosted by cloud providers are configured safely.
★ not rated 2 2mo ago A 15 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
RCE testing covering command injection, deserialization, template injection, and code evaluation.
★ not rated 2 2mo ago B 21 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
A set of methods for testing the security of software containers, which package an application and its dependencies together.
★ not rated 2 2mo ago A 14 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
CSRF testing covering token bypass, SameSite cookies, CORS misconfigurations, and state-changing request abuse.
★ not rated 2 2mo ago B 25 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Exhaustive security assessment with maximum coverage, depth, and vulnerability chaining.
★ not rated 2 2mo ago A 20 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Insecure deserialization testing for Java, Python, PHP, .NET, Ruby, and Node.js covering gadget chains, type confusion, and safe validation.
★ not rated 2 2mo ago A 34 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Security testing playbook for Django applications covering ORM injection, middleware gaps, auth/session flaws, and template issues.
★ not rated 2 2mo ago A 25 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Rules of engagement, scope definition, and authorized penetration test planning.
★ not rated 2 2mo ago A 17 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Security testing playbook for FastAPI applications covering ASGI, dependency injection, and API vulnerabilities.
★ not rated 2 2mo ago A 23 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Skill "ffuf-tooling" from xAmirHamza77/PenKit51, covering ffuf tooling, deep exploitation guide, ffuf cli playbook, platform methodology and ffuf tooling.
★ not rated 2 2mo ago A 20 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
File upload security testing covering extension bypass, content-type manipulation, and path traversal.
★ not rated 2 2mo ago A 19 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
Firebase/Firestore security testing covering security rules, Cloud Functions, and client-side trust issues.
★ not rated 2 2mo ago A 23 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
GraphQL security testing covering introspection, resolver injection, batching attacks, and authorization bypass.
★ not rated 2 2mo ago A 21 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
HTTP header injection testing covering CRLF / response splitting, cache poisoning, Host-header confusion, cookie fixation, and proxy / forwarding header smuggling.
★ not rated 2 2mo ago A 33 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
HTTP request smuggling testing covering CL.TE, TE.CL, H2.CL, H2.TE, and HTTP/2 desync techniques with practical detection and exploitation methodology.
★ not rated 2 2mo ago A 41 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
ProjectDiscovery httpx probing syntax, exact probe flags, and automation-safe output patterns.
★ not rated 2 2mo ago A 22 tokens
xAmirHamza77 /PenKit51
Skill Claude Code Codex
IDOR/BOLA testing for object-level authorization failures and cross-account data access.
★ not rated 2 2mo ago A 18 tokens
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: