xAmirHamza77/PenKit51

PenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.

2Stars on the repository
66Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
customA LICENSE file GitHub cannot name, so bodies are not copied

incident-response

25

xAmirHamza77/PenKit51

Skill Claude CodeCodex

A set of methods for responding to cybersecurity incidents, such as suspected attacks or other security events. The description does not specify particular tools or procedures.

not rated 2 2mo ago A 12 tokens

katana-tooling

27

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Katana crawler syntax, depth/js/known-files behavior, and stable concurrency controls.

not rated 2 2mo ago A 22 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Kubernetes cluster security testing - RBAC, API exposure, container escapes, network policies, secrets, and supply chain.

not rated 2 2mo ago C 28 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

A guide to testing for LDAP injection vulnerabilities, where untrusted input changes a directory-service query. LDAP is a protocol commonly used to look up users and groups.

not rated 2 2mo ago A 16 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Testing LLM-backed features for prompt injection, jailbreaks, system-prompt leakage, tool/agent abuse, and unsafe output handling.

not rated 2 2mo ago B 34 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Mass assignment testing for unauthorized field binding and privilege escalation via API parameters.

not rated 2 2mo ago A 18 tokens

naabu-tooling

33

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Naabu port-scanning syntax with host input, scan-type, verification, and rate controls.

not rated 2 2mo ago B 24 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Security testing playbook for NestJS applications covering guards, pipes, decorators, module boundaries, and multi-transport auth.

not rated 2 2mo ago A 27 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

A set of methods for penetration testing, which is an authorised attempt to find security weaknesses in a computer system or network.

not rated 2 2mo ago A 17 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Security testing playbook for Next.js covering App Router, Server Actions, RSC, and Edge runtime vulnerabilities.

not rated 2 2mo ago B 26 tokens

nmap-tooling

37

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Canonical Nmap CLI syntax, two-pass scanning workflow, and sandbox-safe bounded scan patterns.

not rated 2 2mo ago A 23 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

NoSQL injection testing covering MongoDB operator injection, authentication bypass, blind extraction, GraphQL variable injection, and Redis/DynamoDB/Elasticsearch/Neo4j-specific attack surfaces.

not rated 2 2mo ago A 42 tokens

nuclei-tooling

39

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Exact Nuclei command structure, template selection, and bounded high-throughput execution controls.

not rated 2 2mo ago A 24 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

OAuth 2.0 and OIDC flow security testing covering redirect manipulation, token leakage, PKCE bypass, and client misconfiguration.

not rated 2 2mo ago A 30 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Client and server prototype pollution testing covering JavaScript object merge bugs, Node.js RCE chains, and filter bypasses.

not rated 2 2mo ago A 29 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Run Python through execcommand in the SDK sandbox. Use the image-baked caidoapi module for Caido proxy automation from Python scripts.

not rated 2 2mo ago A 33 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: