Agent skill

Security Pen Testing

by alirezarezvani in alirezarezvani/claude-skills

A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments.

MITAuto-check passedSecurity

Install Security Pen Testing

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill security-pen-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills security-pen-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering-team/skills/security-pen-testing .claude/skills/security-pen-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-pen-testing
GitHub stars
28k
Token cost
~3.5k tokens
SKILL.md length
1,236 words
Files
7 (incl. scripts, references)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments.

  • Works in 5 steps: Collect — Run ecosystem audit tools,… → Deduplicate — Group by CVE ID across… → Prioritize — Critical + exploitable +… → …
  • The user asks to perform security audits
  • SKILL.md covers Table of Contents, Overview, OWASP Top 10 Systematic Audit and Static Analysis, plus 10 more sections
  • Runs Python scripts from its folder; calls python, npm and pip; reaches cwe.mitre.org

What it does

Security Pen Testing is an agent skill from alirezarezvani/claude-skills. Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report generation.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/attack_patterns.md`, `references/owasp_top_10_checklist.md` and `references/responsible_disclosure.md`).

It sits in Security, covering Penetration testing, Web application vulnerabilities and Vulnerability scanning. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • The user asks to perform security audits
  • Penetration testing
  • Vulnerability scanning
  • OWASP Top 10 checks

Example prompts

  • “/security-pen-testing”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Collect — Run ecosystem audit tools, aggregate findings
  2. Deduplicate — Group by CVE ID across direct and transitive deps
  3. Prioritize — Critical + exploitable + reachable = fix immediately
  4. Remediate — Upgrade, patch, or mitigate with compensating controls
  5. Verify — Rerun audit to confirm fix, update lock files

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • npm
    • pip
    • curl
    • bundle
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cwe.mitre.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Pen Testing loads about 3.5k tokens when it runs, and up to ~15k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 1,236 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~15k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 1,236 words, ~3,467 tokens.

Download SKILL.mdSave it as .claude/skills/security-pen-testing/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
security-pen-testing
description
Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, and pen test report generation.

Security Penetration Testing

Hands-on offensive security testing skill for finding vulnerabilities before attackers do. This is NOT compliance checking (see senior-secops) or security policy writing (see senior-security) — this is about systematic vulnerability discovery through authorized testing.


Table of Contents


Overview

What This Skill Does

This skill provides the methodology, checklists, and automation for offensive security testing — actively probing systems to discover exploitable vulnerabilities. It covers web applications, APIs, infrastructure, and supply chain security.

Distinction from Other Security Skills
SkillFocusApproach
security-pen-testing (this)Finding vulnerabilitiesOffensive — simulate attacker techniques
senior-secopsSecurity operationsDefensive — monitoring, incident response, SIEM
senior-securitySecurity policyGovernance — policies, frameworks, risk registers
skill-security-auditorCI/CD gatesAutomated — pre-merge security checks
Prerequisites

All testing described here assumes written authorization from the system owner. Unauthorized testing is illegal under the CFAA and equivalent laws worldwide. Always obtain a signed scope-of-work or rules-of-engagement document before starting.


OWASP Top 10 Systematic Audit

Use the vulnerability scanner tool for automated checklist generation:

bash
# Generate OWASP checklist for a web application
python scripts/vulnerability_scanner.py --target web --scope full

# Quick API-focused scan
python scripts/vulnerability_scanner.py --target api --scope quick --json
Quick Reference
#CategoryKey Tests
A01Broken Access ControlIDOR, vertical escalation, CORS, JWT claim manipulation, forced browsing
A02Cryptographic FailuresTLS version, password hashing, hardcoded keys, weak PRNG
A03InjectionSQLi, NoSQLi, command injection, template injection, XSS
A04Insecure DesignRate limiting, business logic abuse, multi-step flow bypass
A05Security MisconfigurationDefault credentials, debug mode, security headers, directory listing
A06Vulnerable ComponentsDependency audit (npm/pip/go), EOL checks, known CVEs
A07Auth FailuresBrute force, session cookie flags, session invalidation, MFA bypass
A08Integrity FailuresUnsafe deserialization, SRI checks, CI/CD pipeline integrity
A09Logging FailuresAuth event logging, sensitive data in logs, alerting thresholds
A10SSRFInternal IP access, cloud metadata endpoints, DNS rebinding
bash
# Audit dependencies
python scripts/dependency_auditor.py --file package.json --severity high
python scripts/dependency_auditor.py --file requirements.txt --json

See owasp_top_10_checklist.md for detailed test procedures, code patterns to detect, remediation steps, and CVSS scoring guidance for each category.


Static Analysis

Recommended tools: CodeQL (custom queries for project-specific patterns), Semgrep (rule-based scanning with auto-fix), ESLint security plugins (eslint-plugin-security, eslint-plugin-no-unsanitized).

Key patterns to detect: SQL injection via string concatenation, hardcoded JWT secrets, unsafe YAML/pickle deserialization, missing security middleware (e.g., Express without Helmet).

See attack_patterns.md for code patterns and detection payloads across injection types.


Dependency Vulnerability Scanning

Ecosystem commands: npm audit, pip audit, govulncheck ./..., bundle audit check

CVE Triage Workflow:

  1. Collect — Run ecosystem audit tools, aggregate findings
  2. Deduplicate — Group by CVE ID across direct and transitive deps
  3. Prioritize — Critical + exploitable + reachable = fix immediately
  4. Remediate — Upgrade, patch, or mitigate with compensating controls
  5. Verify — Rerun audit to confirm fix, update lock files
bash
python scripts/dependency_auditor.py --file package.json --severity critical --json

Secret Scanning

Tools: TruffleHog (git history + filesystem), Gitleaks (regex-based with custom rules).

bash
# Scan git history for verified secrets
trufflehog git file://. --only-verified --json

# Scan filesystem
trufflehog filesystem . --json

Integration points: Pre-commit hooks (gitleaks, trufflehog), CI/CD gates (GitHub Actions with trufflesecurity/trufflehog@main). Configure .gitleaks.toml for custom rules (AWS keys, API keys, private key headers) and allowlists for test fixtures.


API Security Testing

Authentication Bypass
  • JWT manipulation: Change alg to none, RS256-to-HS256 confusion, claim modification (role: "admin", exp: 9999999999)
  • Session fixation: Check if session ID changes after authentication
Authorization Flaws
  • IDOR/BOLA: Change resource IDs in every endpoint — test read, update, delete across users
  • BFLA: Regular user tries admin endpoints (expect 403)
  • Mass assignment: Add privileged fields (role, is_admin) to update requests
Rate Limiting & GraphQL
  • Rate limiting: Rapid-fire requests to auth endpoints; expect 429 after threshold
  • GraphQL: Test introspection (should be disabled in prod), query depth attacks, batch mutations bypassing rate limits

See attack_patterns.md for complete JWT manipulation payloads, IDOR testing methodology, BFLA endpoint lists, GraphQL introspection/depth/batch attack patterns, and rate limiting bypass techniques.


Web Vulnerability Testing

VulnerabilityKey Tests
XSSReflected (script/img/svg payloads), Stored (persistent fields), DOM-based (innerHTML + location.hash)
CSRFReplay without token (expect 403), cross-session token replay, check SameSite cookie attribute
SQL InjectionError-based (' OR 1=1--), union-based enumeration, time-based blind (SLEEP(5)), boolean-based blind
SSRFInternal IPs, cloud metadata endpoints (AWS/GCP/Azure), IPv6/hex/decimal encoding bypasses
Path Traversal../../../etc/passwd, URL encoding, double encoding bypasses

See attack_patterns.md for complete test payloads (XSS filter bypasses, context-specific XSS, SQL injection per database engine, SSRF bypass techniques, and DOM-based XSS source/sink pairs).


Infrastructure Security

Key checks:

  • Cloud storage: S3 bucket public access (aws s3 ls s3://bucket --no-sign-request), bucket policies, ACLs
  • HTTP security headers: HSTS, CSP (no unsafe-inline/unsafe-eval), X-Content-Type-Options, X-Frame-Options, Referrer-Policy
  • TLS configuration: nmap --script ssl-enum-ciphers -p 443 target.com or testssl.sh — reject TLS 1.0/1.1, RC4, 3DES, export-grade ciphers
  • Port scanning: nmap -sV target.com — flag dangerous open ports (FTP/21, Telnet/23, Redis/6379, MongoDB/27017)

Pen Test Report Generation

Generate professional reports from structured findings:

bash
# Generate markdown report from findings JSON
python scripts/pentest_report_generator.py --findings findings.json --format md --output report.md

# Generate JSON report
python scripts/pentest_report_generator.py --findings findings.json --format json --output report.json
Show full SKILL.md (494 more words)Show less
Findings JSON Format
json
[
  {
    "title": "SQL Injection in Login Endpoint",
    "severity": "critical",
    "cvss_score": 9.8,
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "category": "A03:2021 - Injection",
    "description": "The /api/login endpoint is vulnerable to SQL injection via the email parameter.",
    "evidence": "Request: POST /api/login {\"email\": \"' OR 1=1--\", \"password\": \"x\"}\nResponse: 200 OK with admin session token",
    "impact": "Full database access, authentication bypass, potential remote code execution",
    "remediation": "Use parameterized queries. Replace string concatenation with prepared statements.",
    "references": ["https://cwe.mitre.org/data/definitions/89.html"]
  }
]
Report Structure
  1. Executive Summary: Business impact, overall risk level, top 3 findings
  2. Scope: What was tested, what was excluded, testing dates
  3. Methodology: Tools used, testing approach (black/gray/white box)
  4. Findings Table: Sorted by severity with CVSS scores
  5. Detailed Findings: Each with description, evidence, impact, remediation
  6. Remediation Priority Matrix: Effort vs. impact for each fix
  7. Appendix: Raw tool output, full payload lists

Responsible Disclosure Workflow

Responsible disclosure is mandatory for any vulnerability found during authorized testing. Standard timeline: report on day 1, follow up at day 7, status update at day 30, public disclosure at day 90.

Key principles: Never exploit beyond proof of concept, encrypt all communications, do not access real user data, document everything with timestamps.

See responsible_disclosure.md for full disclosure timelines (standard 90-day, accelerated 30-day, extended 120-day), communication templates, legal considerations, bug bounty program integration, and CVE request process.


Workflows

Workflow 1: Quick Security Check (15 Minutes)

For pre-merge reviews or quick health checks:

bash
# 1. Generate OWASP checklist
python scripts/vulnerability_scanner.py --target web --scope quick

# 2. Scan dependencies
python scripts/dependency_auditor.py --file package.json --severity high

# 3. Check for secrets in recent commits
# (Use gitleaks or trufflehog as described in Secret Scanning section)

# 4. Review HTTP security headers
curl -sI https://target.com | grep -iE "(strict-transport|content-security|x-frame|x-content-type)"

Decision: If any critical or high findings, block the merge.

Workflow 2: Full Penetration Test (Multi-Day Assessment)

Day 1 — Reconnaissance:

  1. Map the attack surface: endpoints, authentication flows, third-party integrations
  2. Run automated OWASP checklist (full scope)
  3. Run dependency audit across all manifests
  4. Run secret scan on full git history

Day 2 — Manual Testing:

  1. Test authentication and authorization (IDOR, BOLA, BFLA)
  2. Test injection points (SQLi, XSS, SSRF, command injection)
  3. Test business logic flaws
  4. Test API-specific vulnerabilities (GraphQL, rate limiting, mass assignment)

Day 3 — Infrastructure and Reporting:

  1. Check cloud storage permissions
  2. Verify TLS configuration and security headers
  3. Port scan for unnecessary services
  4. Compile findings into structured JSON
  5. Generate pen test report
bash
# Generate final report
python scripts/pentest_report_generator.py --findings findings.json --format md --output pentest-report.md
Workflow 3: CI/CD Security Gate

Automated security checks on every PR: secret scanning (TruffleHog), dependency audit (npm audit, pip audit), SAST (Semgrep with p/security-audit, p/owasp-top-ten), and security headers check on staging.

Gate Policy: Block merge on critical/high findings. Warn on medium. Log low/info.


Anti-Patterns

  1. Testing in production without authorization — Always get written permission and use staging/test environments when possible
  2. Ignoring low-severity findings — Low findings compound; a chain of lows can become a critical exploit path
  3. Skipping responsible disclosure — Every vulnerability found must be reported through proper channels
  4. Relying solely on automated tools — Tools miss business logic flaws, chained exploits, and novel attack vectors
  5. Testing without a defined scope — Scope creep leads to legal liability; document what is and isn't in scope
  6. Reporting without remediation guidance — Every finding must include actionable remediation steps
  7. Storing evidence insecurely — Pen test evidence (screenshots, payloads, tokens) is sensitive; encrypt and restrict access
  8. One-time testing — Security testing must be continuous; integrate into CI/CD and schedule periodic assessments

Cross-References

SkillRelationship
senior-secopsDefensive security operations — monitoring, incident response, SIEM configuration
senior-securitySecurity policy and governance — frameworks, risk registers, compliance
dependency-auditorDeep supply chain security — SBOMs, license compliance, transitive risk
code-reviewerCode review practices — includes security review checklist

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in engineering-team/skills/security-pen-testing of alirezarezvani/claude-skills.

  • SKILL.md
  • references/attack_patterns.md
  • references/owasp_top_10_checklist.md
  • references/responsible_disclosure.md
  • scripts/dependency_auditor.py
  • scripts/pentest_report_generator.py
  • scripts/vulnerability_scanner.py

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Security Pen Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Pen Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Pen Testing this skillalirezarezvani/claude-skills28k—~3.5kAutomated safety check: PassMIT
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT
Secknowledge SkillPa55w0rd/secknowledge-skill423—~2.7kAutomated safety check: PassNone
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT
Security ReviewerAratKruglik/claude-laravel1551 repos~1.1kAutomated safety check: NotesNone

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 22 days ago
    SecurityAuto-check: notes
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    423 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Security Reviewer

    AratKruglik/claude-laravel

    A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

    155 GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check: notes
  • Semgrep Rule Creator

    skrun-dev/skrun

    Generate a complete Semgrep rule bundle (rule.yml + tests.md + README.md) from a CVE description and a bad-code example.

    210 GitHub stars~1.3k tokensUpdated 14 days ago
    SecurityAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Categories

Questions about Security Pen Testing

What does Security Pen Testing do?

A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Security Pen Testing is an agent skill from alirezarezvani/claude-skills. Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments.

When should I use Security Pen Testing?

Security Pen Testing fits situations like: the user asks to perform security audits; penetration testing; vulnerability scanning; OWASP Top 10 checks.

How do I install Security Pen Testing in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill security-pen-testing -a claude-code`. Or copy the skill folder (engineering-team/skills/security-pen-testing in alirezarezvani/claude-skills) into .claude/skills/security-pen-testing in your project. Claude Code loads it when a task matches its description.

How do I install Security Pen Testing in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill security-pen-testing -a codex`. Or copy the skill folder (engineering-team/skills/security-pen-testing in alirezarezvani/claude-skills) into .agents/skills/security-pen-testing in your project. Codex loads it when a task matches its description.

Can I use Security Pen Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill security-pen-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-pen-testing, .gemini/skills/security-pen-testing, .github/skills/security-pen-testing and .opencode/skills/security-pen-testing in your project.

What does Security Pen Testing need to run?

Going by SKILL.md and its folder, Security Pen Testing needs Python for the scripts in its folder and the command-line tools its instructions call (python, npm, pip, curl, bundle and aws). Our summary lists: Python 3.

Does Security Pen Testing access the network?

SKILL.md names 1 domain. In commands or code: cwe.mitre.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Security Pen Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Pen Testing use?

Security Pen Testing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Security Pen Testing use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Security Pen Testing?

Skills that share tags, products or a category with Security Pen Testing: Code Audit (3stoneBrother/code-audit, 893 stars), Security Verification Gate (fengshao1227/ccg-workflow, 5.9k stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 423 stars) and Cyber Neo (Hainrixz/cyber-neo, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Pen Testing?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,788 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.