Agent skill

Takeover

by PentesterFlow in PentesterFlow/agent

Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…

Apache-2.0Auto-check passedBackend & APIs

Install Takeover

skills CLI
$ npx skills add PentesterFlow/agent --skill takeover -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install PentesterFlow/agent takeover --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/PentesterFlow/agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/takeover .claude/skills/takeover && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
takeover
GitHub stars
1.4k
Token cost
~3.3k tokens
SKILL.md length
1,359 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
Apache-2.0

At a glance

Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…

  • Works in 8 steps: Enumerate every subdomain → Resolve each name — CNAME first, then… → Match HTTP fingerprints → …
  • Enumerating subdomains for dangling CNAME/NS records pointing at unclaimed third-party services
  • SKILL.md covers 1. Enumerate every subdomain, 2. Resolve each name — CNAME…, 3. Match HTTP fingerprints and 4. Confirm before reporting, plus 4 more sections
  • Calls curl and jq; reaches wishpond.com and crt.sh

What it does

Takeover is an agent skill from PentesterFlow/agent. Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the engine's HTTP fingerprint, then prove impact by claiming the resource in scope. Use when enumerating subdomains for dangling CNAME/NS records pointing at unclaimed third-party services.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `payloads/fingerprints.json`).

It sits in Backend & APIs, covering File uploads and storage. It works with Microsoft Azure, Netlify, GitHub and Shopify. The repository describes itself as: Agentic offensive-security in your terminal. The licence is Apache-2.0.

When your agent uses it

  • Enumerating subdomains for dangling CNAME/NS records pointing at unclaimed third-party services
  • Tasks that involve File uploads and storage

Example prompts

  • “/takeover”

Requirements

  • Pre-approved tools (allowed-tools): http, shell, read_payloads, file_write

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Enumerate every subdomain
  2. Resolve each name — CNAME first, then A/AAAA
  3. Match HTTP fingerprints
  4. Confirm before reporting
  5. NS takeover (variant)
  6. Key engines (quick reference — full DB in payloads)
  7. Tooling shortcuts (when available)
  8. Reporting

What it can do on your machine

Read from SKILL.md and the folder at commit 0759d87. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • http
    • shell
    • read_payloads
    • file_write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • wishpond.com
    • crt.sh
    • jldc.me
    • api.hackertarget.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Takeover loads about 3.3k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 1,359 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from PentesterFlow/agent at commit 0759d87, republished under its Apache-2.0 licence (© PentesterFlow). 1,359 words, ~3,300 tokens.

Download SKILL.mdSave it as .claude/skills/takeover/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
takeover
description
Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the engine's HTTP fingerprint, then prove impact by claiming the resource in scope. Use when enumerating subdomains for dangling CNAME/NS records pointing at unclaimed third-party services.
allowed-tools
http, shell, read_payloads, file_write

Subdomain takeover playbook

A subdomain points (via CNAME, NS, or an A record on a shared host) at a third-party service. The resource on that service was deleted, expired, or never claimed — but the DNS record still exists. An attacker registers the same resource on the provider and serves arbitrary content on the victim's hostname. Severity is usually high to critical because the takeover puts the attacker inside the victim's origin (cookie scope, CSP allowlists, OAuth redirect_uri allowlists, SAML SP entity IDs, email DKIM/SPF includes, ...).

Stay in scope. Only test takeovers against domains the program explicitly authorizes. A successful takeover is serving content on someone else's host — drop a benign HTML file (takeover proof for <handle>, contact <email>) and stop.

Execution rule: operate on real subdomains and provider fingerprints from the scoped program. Never write literal placeholders such as <provider>, <handle>, or <email> to files; ask once for proof text if a provider requires a claim page.

1. Enumerate every subdomain

Use whatever recon you have. Curl-first sources you can hit without extra tooling:

sh
# CT logs via crt.sh
curl -s 'https://crt.sh/?q=%25.target.example.com&output=json' \
  | jq -r '.[].name_value' | sed 's/^\*\.//' | sort -u > subs.txt

# Anubis-DB
curl -s 'https://jldc.me/anubis/subdomains/target.example.com' \
  | jq -r '.[]' >> subs.txt

# Hackertarget (rate-limited)
curl -s 'https://api.hackertarget.com/hostsearch/?q=target.example.com' \
  | cut -d, -f1 >> subs.txt

sort -u subs.txt -o subs.txt

If [[recon]] is loaded, prefer those flows for the enumeration step.

2. Resolve each name — CNAME first, then A/AAAA

sh
# Pull CNAMEs in one batch (works on macOS/Linux with dig)
while read -r sub; do
  cname=$(dig +short CNAME "$sub" | head -n1)
  if [ -n "$cname" ]; then printf '%s\tCNAME\t%s\n' "$sub" "$cname"; fi
done < subs.txt > resolved.tsv

# NS delegation (rare but high-severity)
while read -r sub; do
  ns=$(dig +short NS "$sub")
  if [ -n "$ns" ]; then printf '%s\tNS\t%s\n' "$sub" "$(echo "$ns" | tr '\n' ',')"; fi
done < subs.txt >> resolved.tsv

You're looking for:

  • CNAME → third-party provider (e.g. app.target.com → app.elasticbeanstalk.com) where the resource at that provider is unclaimed.
  • NS → vanished zone (zone.target.com NS ns1.dnsmadeeasy.com where the zone no longer exists on dnsmadeeasy).
  • CNAME → NXDOMAIN — the cleanest signal: the CNAME target itself doesn't resolve. Always investigate.
sh
# Find CNAMEs whose target doesn't resolve at all
awk -F'\t' '$2=="CNAME" {print $3}' resolved.tsv | while read -r t; do
  dig +short "$t" >/dev/null 2>&1 || echo "$t (NXDOMAIN target)"
done

3. Match HTTP fingerprints

Pull the full fingerprint database:

read_payloads(skill="takeover", file="fingerprints.json")

The JSON Lines file lists, for each provider:

  • service — human label.
  • cname — regex of the target hostname.
  • status — vulnerable / edge-case / not-vulnerable.
  • fingerprint — string to grep for in the HTTPS response body.
  • http_status — typical status code (404, 200, etc.).
  • notes — claim-flow gotchas.

For each CNAME match, fetch the response and grep:

sh
# Example: subdomain points at GitHub Pages
curl -sk -H "Host: lost.target.com" https://lost.target.com/ \
  | grep -F "There isn't a GitHub Pages site here."

A hit on status: vulnerable plus the fingerprint in the response body is the takeover signal. Don't trust the fingerprint alone — many providers serve the same string on a legitimately-not-yet-deployed site that's still claimed by the owner. Confirm-step (4) is mandatory.

4. Confirm before reporting

The trap: the resource may be unclaimed by anyone visible to you, but the legitimate owner may still hold it via an account you can't see (e.g. the Heroku app exists in their account but is paused). False-positive report rates on subdomain takeover are notorious.

Confirmation paths, in order of preference:

  1. Out-of-band canary. Attempt to register the resource (e.g. create a Heroku app named lost-target). If the provider says "name taken" without serving you the fingerprint, it's a false positive — someone has it.

  2. Successful claim + benign content. When the registration succeeds, serve a static HTML file proving ownership:

    html
    <!doctype html>
    <title>Subdomain Takeover PoC</title>
    <h1>Subdomain Takeover</h1>
    <p>This subdomain (<code>lost.target.com</code>) was claimable on
       <em>&lt;provider&gt;</em> by anyone. Reported by &lt;handle&gt;
       to &lt;program&gt;. Contact: &lt;email&gt;.</p>

    Fetch the subdomain again over HTTPS — your content must come back.

  3. Screenshot + curl response in the report.

Do NOT:

  • Serve real-looking content (login forms, fake updates).
  • Run any script in the page.
  • Hold the resource beyond what's needed for the PoC; release it after the report is triaged.
  • Use takeovers to phish, even for "research."

5. NS takeover (variant)

If a subdomain delegates DNS to a third-party provider via NS records and the zone is unclaimed on that provider, you control all records under the subdomain — far more dangerous than a single CNAME takeover. Common providers seen here: DNSMadeEasy, Bizland, EasyDNS, Yahoo Small Business, NS1, Hurricane Electric, MyDomain, Domain.com.

Detection: dig NS sub.target.com returns a provider's nameservers, but querying those nameservers for the zone returns REFUSED or SERVFAIL.

sh
for ns in $(dig +short NS sub.target.com); do
  echo "=== $ns ==="
  dig @"$ns" sub.target.com SOA
done

A REFUSED/SERVFAIL from all of the listed nameservers, combined with the provider being one that lets you create zones with arbitrary names, is the takeover primitive.

6. Key engines (quick reference — full DB in payloads)

ServiceCNAME patternFingerprint substringStatus
GitHub Pages*.github.ioThere isn't a GitHub Pages site here.vulnerable
Heroku*.herokuapp.com, *.herokudns.comNo such app / There's nothing here, yet.vulnerable
AWS S3 (website)*.s3-website-*.amazonaws.com, *.s3.amazonaws.comNoSuchBucketvulnerable
Azure App Service*.azurewebsites.net404 Web Site not found.vulnerable
Azure Cloud Service*.cloudapp.net, *.cloudapp.azure.com404 Web Site not found.vulnerable
Azure Traffic Manager*.trafficmanager.netNXDOMAIN on profilevulnerable
Azure Storage*.blob.core.windows.netNXDOMAINvulnerable
Azure CDN*.azureedge.netNXDOMAIN / Bad Requestedge-case
Netlify*.netlify.app, *.netlify.comNot Found - Request IDvulnerable
Heroku SSL endpoint*.herokussl.comvariesedge-case
Vercel / Now*.vercel.app, cname.vercel-dns.com404: NOT_FOUND / The deployment could not be foundedge-case
Shopify*.myshopify.comSorry, this shop is currently unavailable.vulnerable
Tumblr*.tumblr.com (custom domain)Whatever you were looking for doesn't currently exist at this address.vulnerable
Surge.sh*.surge.shproject not foundvulnerable
Ghost*.ghost.ioThe thing you were looking for is no longer here, or never wasvulnerable
Pantheon*.pantheonsite.ioThe gods are wise, but do not know of the site which you seek.vulnerable
SquarespacevariousNo Such Account / Squarespace - No Such Accountedge-case
Tilda*.tilda.wsPlease renew your subscriptionvulnerable
Unbounce*.unbouncepages.comThe requested URL was not found on this server.vulnerable
UserVoice*.uservoice.comThis UserVoice subdomain is currently available!vulnerable
Strikingly*.s.strikinglydns.comPAGE NOT FOUND.vulnerable
Helpjuice*.helpjuice.comWe could not find what you're looking for.vulnerable
HelpScout*.helpscoutdocs.comNo settings were found for this company:vulnerable
Bitbucket*.bitbucket.ioRepository not foundvulnerable
Cargo Collective*.cargocollective.comIf you're moving your domain away from Cargovulnerable
Statuspage*.statuspage.ioYou are being redirected. (302 to statuspage 404)edge-case
Acquia*.acquia-sites.comThe site you are looking for could not be found.vulnerable
Aha*.aha.ioThere is no portal here ... sending you back to Aha!vulnerable
Anima*.animaapp.ioIf this is your website and you've just created itvulnerable
Brightcovevarious<p class="bc-gallery-error-code">Error Code: 404</p>vulnerable
Campaign Monitorcreatesend.comTrying to access your account?vulnerable
Canny*.canny.ioCompany Not Foundvulnerable
Fastly*.fastly.netFastly error: unknown domainedge-case
Frontify*.frontify.comBrand not foundvulnerable
Gemfury*.fury.site404: This page could not be found.vulnerable
GetResponsevariesWith GetResponse Landing Pages, lead generation has never been easiervulnerable
Hatena Bloghatenablog.comJapanese error stringvulnerable
HelpRescue*.helprace.comHelp Center Closededge-case
JetBrains*.youtrack.cloudis not a registered InCloud YouTrackvulnerable
Kinsta*.kinsta.cloudNo Site For Domainedge-case
LaunchRock*.launchrock.comIt looks like you may have taken a wrong turn somewhere.vulnerable
Mashery*.mashery.comUnrecognized domainedge-case
Pingdom*.stats.pingdom.compingdom pageedge-case
Proposify*.proposify.comIf you need immediate assistancevulnerable
Readme*.readme.ioProject doesnt exist... yet!vulnerable
SendGridvariesparked landingedge-case
ShortIO*.shortio.app404, please check the URL.vulnerable
Smartling*.smartling.comDomain is not configuredvulnerable
Thinkific*.thinkific.comYou may have mistyped the address or the page may have moved.vulnerable
Uberflip*.uberflip.comThe page you are looking for is not foundvulnerable
Vend*.vendecommerce.comLooks like you've traveled too far into cyberspace.vulnerable
Webflowproxy-ssl.webflow.comThe page you are looking for doesn't exist or has been moved.vulnerable
Wishpondvarieshttps://www.wishpond.com/404?campaign=vulnerable
Wordpress*.wordpress.comDo you want to registeredge-case
WP Engine*.wpengine.comThe site you were looking for couldn't be found.edge-case
WorksitesvariesHello! Sorry, but the website you’re looking for doesn’t exist.vulnerable
Cloudfront*.cloudfront.netThe request could not be satisfiededge-case
Google Cloud Storage*.storage.googleapis.comNoSuchBucketvulnerable
Show full SKILL.md (202 more words)Show less

The full database — including HTTP status codes, claim notes, and edge-case explanations for every entry — is in payloads/fingerprints.json (see the read_payloads invocation in section 3).

7. Tooling shortcuts (when available)

If you have these installed, they automate sections 1–3:

  • subjack — Go scanner with built-in fingerprints. subjack -w subs.txt -t 100 -timeout 30 -ssl -c fingerprints.json -v
  • subzy — newer alternative.
  • nuclei — nuclei -l subs.txt -tags takeover runs the community templates.
  • tko-subs — also script-based.
  • aquatone — screenshots + detection in one pass.

You do not need any of these to do the work; sections 2–4 are do-able with dig + curl + the JSON fingerprint file.

8. Reporting

For each confirmed takeover:

  • Vulnerable subdomain (lost.target.com).
  • DNS resolution path (lost.target.com CNAME bucket.s3.amazonaws.com → unclaimed).
  • The exact provider + service.
  • HTTP response showing the fingerprint (curl one-liner + body excerpt).
  • PoC: your claimed resource serving a benign proof file.
  • Impact paragraph specific to the engagement: which cookies, CSP rules, OAuth redirect_uri lists, SAML entity IDs, mail SPF/DKIM, or session domains include the parent — that's where the severity comes from.
  • Remediation: remove the dangling DNS record OR re-claim the resource.
  • Suggested severity: critical when the parent's auth cookies / SSO / payment flows reach the subdomain; high otherwise.

Release the claimed resource after the program triages.

© PentesterFlow, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/takeover of PentesterFlow/agent.

  • SKILL.md
  • payloads/fingerprints.json

Open the folder on GitHubat commit 0759d87

Compare with similar skills

Takeover next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Takeover compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Takeover this skillPentesterFlow/agent1.4k—~3.3kAutomated safety check: PassApache-2.0
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
Kql ValidatorAzure/azqr794—~703Automated safety check: PassMIT
Maplibre Pmtiles Patternsmaplibre/maplibre-agent-skills151—~4.6kAutomated safety check: PassCustom licence
Authmicrosoft/apm4k—~756Automated safety check: PassMIT
Azure Storage Blob Pymicrosoft/skills3.1k—~2.3kAutomated safety check: PassMIT

Similar skills

  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Kql Validator

    Azure/azqr

    Official

    Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

    794 GitHub stars~703 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Maplibre Pmtiles Patterns

    maplibre/maplibre-agent-skills

    Serverless vector and raster tiles with PMTiles for MapLibre GL JS — single-file format, HTTP range requests, hosting on S3/R2/GitHub Pages, generating with Planetiler or tippecanoe, and the pmtiles…

    151 GitHub stars~4.6k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Auth

    microsoft/apm

    Official

    Activate when code touches token management, credential resolution, git auth flows, GITHUBAPMPAT, ADOAPMPAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth'…

    4k GitHub stars~756 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Azure Storage Blob Py

    microsoft/skills

    Official

    Azure Blob Storage SDK for Python. An agent skill from microsoft/skills.

    3.1k GitHub stars~2.3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Azure Storage Blob Rust

    microsoft/skills

    Official

    Azure Blob Storage library for Rust. An agent skill from microsoft/skills.

    3.1k GitHub stars~2.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from PentesterFlow/agent

  • Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

    1.4k GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check passed
  • External Recon Playbook

    PentesterFlow/agent

    Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Ssti

    PentesterFlow/agent

    Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Webvuln

    PentesterFlow/agent

    Web vulnerability hunting playbook. An agent skill from PentesterFlow/agent.

    1.4k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Takeover

What does Takeover do?

Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the…. Takeover is an agent skill from PentesterFlow/agent.), confirm with the engine's HTTP fingerprint, then prove impact by claiming the resource in scope.

When should I use Takeover?

Takeover fits situations like: enumerating subdomains for dangling CNAME/NS records pointing at unclaimed third-party services; tasks that involve File uploads and storage.

How do I install Takeover in Claude Code?

Run `npx skills add PentesterFlow/agent --skill takeover -a claude-code`. Or copy the skill folder (skills/takeover in PentesterFlow/agent) into .claude/skills/takeover in your project. Claude Code loads it when a task matches its description.

How do I install Takeover in Codex?

Run `npx skills add PentesterFlow/agent --skill takeover -a codex`. Or copy the skill folder (skills/takeover in PentesterFlow/agent) into .agents/skills/takeover in your project. Codex loads it when a task matches its description.

Can I use Takeover in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add PentesterFlow/agent --skill takeover -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/takeover, .gemini/skills/takeover, .github/skills/takeover and .opencode/skills/takeover in your project.

What does Takeover need to run?

Going by SKILL.md and its folder, Takeover needs the command-line tools its instructions call (curl and jq). Its frontmatter pre-approves these tools: http, shell, read_payloads, file_write.

Does Takeover access the network?

SKILL.md names 4 domains. In commands or code: wishpond.com, crt.sh, jldc.me and api.hackertarget.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Takeover safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Takeover use?

Takeover is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Takeover use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Takeover?

Skills that share tags, products or a category with Takeover: Foundatio (FoundatioFx/Foundatio, 2.1k stars), Kql Validator (Azure/azqr, 794 stars), Maplibre Pmtiles Patterns (maplibre/maplibre-agent-skills, 151 stars) and Auth (microsoft/apm, 4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Takeover?

PentesterFlow (a GitHub user) maintains it in PentesterFlow/agent, which has 1,389 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on August 31, 2026.

Source: PentesterFlow/agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.