Topic · Security
Best penetration testing skills for Claude Code, Codex and other agents.
- skills
- 183
- official
- 3
Penetration testing skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 2 | Professional code security audit skill covering 55+ vulnerability types. | 3stoneBrother/ | 893 | 1 repo | ~2.7k | Automated safety check: Pass | No licence | 7 mo ago |
| 3 | Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works. | usestrix/ | 67k | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys. | j3ssie/ | 1.8k | — | ~2.4k | Automated safety check: Pass | MIT | 2 mo ago |
| 5 | WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws… | tanweai/ | 1.8k | — | ~1.9k | Automated safety check: Pass | Unknown | 2 mo ago |
| 6 | Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept. | usestrix/ | 67k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | today |
| 7 | Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet. | awarexone/ | 5.3k | — | ~4.7k | Automated safety check: Pass | MIT | 2 days ago |
| 8 | A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization. | tradecatlabs/ | 17k | 2 repos | ~3.9k | Automated safety check: Warn | MIT | 6 days ago |
| 9 | Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt. | samugit83/ | 2.9k | — | ~775 | Automated safety check: Pass | MIT | yesterday |
| 10 | Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research. | lingbol088-spec/ | 222 | — | ~1.8k | Automated safety check: Pass | MIT | 2 mo ago |
| 11 | Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back. | samugit83/ | 2.9k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 12 | Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization. | PentesterFlow/ | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data. | trailofbits/ | 7.4k | 3 repos | ~4.2k | Automated safety check: Notes | CC-BY-SA-4.0 | 5 days ago |
| 14 | Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in… | samugit83/ | 2.9k | — | ~1.3k | Automated safety check: Pass | MIT | yesterday |
| 15 | 15.Myrqen Run an authorized, local-first application security assessment on the current project using this agent's own reasoning. | stijnswapped/ | 137 | — | ~2.1k | Automated safety check: Pass | Unknown | 1 mo ago |
| 16 | Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn. | Encod3d-Sec/ | 329 | 1 repo | ~1.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 17 | GitHub Actions security review for workflow exploitation vulnerabilities. | getsentry/ | 1k | 3 repos | ~2.2k | Automated safety check: Notes | Apache-2.0 | 4 days ago |
| 18 | 18.Burp Scan Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs. | six2dez/ | 1.5k | — | ~6.4k | Automated safety check: Warn | MIT | 1 mo ago |
| 19 | Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged… | samugit83/ | 2.9k | — | ~1.4k | Automated safety check: Pass | MIT | yesterday |
| 20 | Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation. | ptn1411/ | 219 | — | ~917 | Automated safety check: Pass | No licence | 15 days ago |
| 21 | Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan. | usestrix/ | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | today |
| 22 | Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses. | Encod3d-Sec/ | 329 | 1 repo | ~1.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 23 | Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets. | Tencent/ | 6.8k | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | today |
| 24 | Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must… | samugit83/ | 2.9k | — | ~2.2k | Automated safety check: Pass | MIT | yesterday |
| 25 | Automate low-impact web vulnerability verification through Burp MCP. | langbyyi/ | 133 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 10 days ago |
| 26 | Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry. | samugit83/ | 2.9k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
| 27 | Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding… | ADScanPro/ | 209 | — | ~2.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 28 | Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology. | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Interacting with BurpSuite over the reburp extension that exposes the full Montoya API as a local REST API. | forefy/ | 116 | — | ~883 | Automated safety check: Pass | MIT | 2 days ago |
| 30 | 30.Idor Testing This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"… | zebbern/ | 4.6k | 7 repos | ~3.1k | Automated safety check: Pass | MIT | today |
| 31 | Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling. | hardw00t/ | 104 | — | ~2.2k | Automated safety check: Pass | No licence | 5 mo ago |
| 32 | 32.Kantor Agent Jalankan "Kantor Agent" — kantor 3D (three.js) tanpa konfigurasi di http://127.0.0.1:8788/kerja yang menampilkan apa yang sedang dikerjakan Claude di project ini. | humaedihume/ | 100 | — | ~1k | Automated safety check: Pass | MIT | 8 days ago |
| 33 | Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token. | samugit83/ | 2.9k | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 34 | A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code… | ProgrammerAnthony/ | 235 | — | ~1.6k | Automated safety check: Pass | MIT | 4 mo ago |
| 35 | 35.Nmap Professional network reconnaissance and port scanning using nmap. | BrownFineSecurity/ | 858 | 1 repo | ~3.8k | Automated safety check: Notes | MIT | 4 mo ago |
| 36 | 36.Cloud Audit Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images | CommonHuman-Lab/ | 156 | — | ~1.1k | Automated safety check: Pass | Unknown | today |
| 37 | This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through… | zebbern/ | 4.6k | 4 repos | ~2.9k | Automated safety check: Pass | MIT | today |
| 38 | Spawning and hardening scan containers from the recon orchestrator: the security flags that look correct and break the container, and the sibling bind-mount path handling. | samugit83/ | 2.9k | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 39 | 39.Ssti Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or… | PentesterFlow/ | 1.4k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | 40.Auth Bypass Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses | NeoTheCapt/ | 140 | — | ~1.3k | Automated safety check: Pass | No licence | 2 mo ago |
| 41 | A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. | AratKruglik/ | 155 | 1 repo | ~1.1k | Automated safety check: Notes | No licence | 5 mo ago |
| 42 | 42.Iom Opsec IoM Operational Security (OPSEC) advisor. An agent skill from chainreactors/malice-network. | chainreactors/ | 500 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 43 | Detects input validation failures and arithmetic vulnerabilities in smart contracts. | quillai-network/ | 129 | — | ~3.1k | Automated safety check: Pass | MIT | 6 mo ago |
| 44 | A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every… | mtarcure/ | 162 | — | ~3.6k | Automated safety check: Pass | MIT | 16 days ago |
| 45 | Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only. | forefy/ | 152 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 46 | The Priority Board's three-layer score model (rules BASE, REVIEW by the built-in AI or an MCP agent, a person's DECISION) and who may write which layer. | samugit83/ | 2.9k | — | ~1.7k | Automated safety check: Pass | MIT | yesterday |
| 47 | 47.Adcs Attacks Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k). | ADScanPro/ | 209 | — | ~3.6k | Automated safety check: Pass | MIT | 1 mo ago |
| 48 | Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws | NeoTheCapt/ | 140 | — | ~2.8k | Automated safety check: Pass | No licence | 2 mo ago |
Questions, answered from the data.
What is the best penetration testing skill?
Strix Code Vulnerability Scan from usestrix/strix ranks first of the 183 penetration testing skills listed here, with the highest score: its repository has 67k GitHub stars, its SKILL.md loads about 1.1k tokens and it passes the automated safety check with no findings. Next come Code Audit and Fix Strix Security Findings.
Which penetration testing skills are official?
3 of the 183 penetration testing skills are official, published by the vendor's own GitHub organization: Burp Suite Project Parser, Gha Security Review and Remediating With AWS Security Agent.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34