xAmirHamza77/PenKit51

PenKit51 — Open-source AI penetration testing platform with 63 deep exploitation skills, multi-agent orchestration, PoC-validated findings, and native assistant skills for Claude, ChatGPT, and Grok. Authorized testing only.

2Stars on the repository
66Mods indexed here, across every type
2mo agoLast push, which is what freshness is scored on
customA LICENSE file GitHub cannot name, so bodies are not copied

security-automation

49

xAmirHamza77/PenKit51

Skill Claude CodeCodex

A set of methods for automating security-related work. Security automation means using software to carry out security tasks with less manual effort.

not rated 2 2mo ago A 13 tokens

semgrep-tooling

50

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Exact Semgrep CLI structure, metrics-off scanning, scoped ruleset selection, and automation-safe output patterns.

not rated 2 2mo ago A 26 tokens

source-aware-sast

51

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Practical source-aware SAST and AST playbook for semgrep, ast-grep, gitleaks, and trivy fs.

not rated 2 2mo ago A 31 tokens

sqlmap-tooling

54

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Skill "sqlmap-tooling" from xAmirHamza77/PenKit51, covering sqlmap tooling, deep exploitation guide, sqlmap cli playbook, platform methodology and sqlmap tooling.

not rated 2 2mo ago A 23 tokens

ssrf-testing

55

xAmirHamza77/PenKit51

Skill Claude CodeCodex

SSRF testing for cloud metadata access, internal service discovery, and protocol smuggling.

not rated 2 2mo ago C 20 tokens

ssti-testing

56

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Server-side template injection across Jinja / Mako / Velocity / Freemarker / Thymeleaf / Twig / Handlebars / EJS / ERB with engine fingerprinting, sandbox escape, and RCE gadget chains.

not rated 2 2mo ago D 49 tokens

subfinder-tooling

59

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Subfinder passive subdomain enumeration syntax, source controls, and pipeline-ready output patterns.

not rated 2 2mo ago A 22 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

Supabase security testing covering Row Level Security, PostgREST, Edge Functions, and service key exposure.

not rated 2 2mo ago A 25 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

A guide to vulnerability assessment, the process of finding and evaluating security weaknesses in systems or applications.

not rated 2 2mo ago A 14 tokens

xAmirHamza77/PenKit51

Skill Claude CodeCodex

A guide to testing applications that use XPath, the query language used to select data from XML documents, for injection vulnerabilities. Specially crafted input can change an XPath query's meaning.

not rated 2 2mo ago A 16 tokens

xss-testing

63

xAmirHamza77/PenKit51

Skill Claude CodeCodex

XSS testing covering reflected, stored, and DOM-based vectors with CSP bypass techniques.

not rated 2 2mo ago C 20 tokens

xxe-testing

64

xAmirHamza77/PenKit51

Skill Claude CodeCodex

XXE testing for external entity injection, file disclosure, and SSRF via XML parsers.

not rated 2 2mo ago A 22 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: