Skill Claude CodeCodex
A set of methods for responding to cybersecurity incidents, such as suspected attacks or other security events. The description does not specify particular tools or procedures.
PenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.
Skill Claude CodeCodex
A set of methods for responding to cybersecurity incidents, such as suspected attacks or other security events. The description does not specify particular tools or procedures.
Skill Claude CodeCodex
Information disclosure testing covering error messages, debug endpoints, metadata leakage, and source exposure.
Skill Claude CodeCodex
Katana crawler syntax, depth/js/known-files behavior, and stable concurrency controls.
Skill Claude CodeCodex
Kubernetes cluster security testing - RBAC, API exposure, container escapes, network policies, secrets, and supply chain.
Skill Claude CodeCodex
A guide to testing for LDAP injection vulnerabilities, where untrusted input changes a directory-service query. LDAP is a protocol commonly used to look up users and groups.
Skill Claude CodeCodex
Testing LLM-backed features for prompt injection, jailbreaks, system-prompt leakage, tool/agent abuse, and unsafe output handling.
Skill Claude CodeCodex
Mass assignment testing for unauthorized field binding and privilege escalation via API parameters.
Skill Claude CodeCodex
A set of methods for testing the security of mobile apps, such as apps for phones and tablets.
Skill Claude CodeCodex
Naabu port-scanning syntax with host input, scan-type, verification, and rate controls.
Skill Claude CodeCodex
Security testing playbook for NestJS applications covering guards, pipes, decorators, module boundaries, and multi-transport auth.
Skill Claude CodeCodex
A set of methods for penetration testing, which is an authorised attempt to find security weaknesses in a computer system or network.
Skill Claude CodeCodex
Security testing playbook for Next.js covering App Router, Server Actions, RSC, and Edge runtime vulnerabilities.
Skill Claude CodeCodex
Canonical Nmap CLI syntax, two-pass scanning workflow, and sandbox-safe bounded scan patterns.
Skill Claude CodeCodex
NoSQL injection testing covering MongoDB operator injection, authentication bypass, blind extraction, GraphQL variable injection, and Redis/DynamoDB/Elasticsearch/Neo4j-specific attack surfaces.
Skill Claude CodeCodex
Exact Nuclei command structure, template selection, and bounded high-throughput execution controls.
Skill Claude CodeCodex
OAuth 2.0 and OIDC flow security testing covering redirect manipulation, token leakage, PKCE bypass, and client misconfiguration.
Skill Claude CodeCodex
Open redirect testing for phishing pivots, OAuth token theft, and allowlist bypass.
Skill Claude CodeCodex
Path traversal and file inclusion testing for local/remote file access and code execution.
Skill Claude CodeCodex
Orchestration layer that coordinates specialized subagents for security assessments.
Skill Claude CodeCodex
Client and server prototype pollution testing covering JavaScript object merge bugs, Node.js RCE chains, and filter bypasses.
Skill Claude CodeCodex
Run Python through execcommand in the SDK sandbox. Use the image-baked caidoapi module for Caido proxy automation from Python scripts.
Skill Claude CodeCodex
Time-boxed rapid assessment targeting high-impact vulnerabilities.
Skill Claude CodeCodex
Race condition testing for TOCTOU bugs, double-spend, and concurrent state manipulation.
Skill Claude CodeCodex
A set of methods for reviewing source code for security problems.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: