Topic · Security

Best penetration testing skills for Claude Code, Codex and other agents.

Skills that guide authorised penetration tests and offensive security work.
skills
183
official
3

Penetration testing skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Penetration testing skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

usestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0today
2

Professional code security audit skill covering 55+ vulnerability types.

3stoneBrother/code-audit8931 repo~2.7kAutomated safety check: PassNo licence7 mo ago
3

Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

usestrix/strix67k—~1.5kAutomated safety check: PassApache-2.0today
4

Operates the metabigor CLI to map a target's network ranges, subdomains, ports, related domains, CDNs and archived URLs from free sources without API keys.

j3ssie/metabigor1.8k—~2.4kAutomated safety check: PassMIT2 mo ago
5

WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…

tanweai/wooyun-legacy1.8k—~1.9kAutomated safety check: PassUnknown2 mo ago
6

Runs Strix's autonomous exploit agents against each OWASP Top 10:2025 category and the API Security Top 10, reporting only what could actually be proven with a proof-of-concept.

usestrix/strix67k—~1.6kAutomated safety check: PassApache-2.0today
7

Recovers a client-side request signature or anti-bot token just far enough to replay blocked requests in bug bounty testing, starting from a captured packet.

awarexone/Agentic-Bug-Hunter5.3k—~4.7kAutomated safety check: PassMIT2 days ago
8

A selection guide to AI-driven tools for Web3 bug bounty work, from autonomous web pentesters to smart contract bug finders, with notes on authorization.

tradecatlabs/vibe-coding-cn17k2 repos~3.9kAutomated safety check: WarnMIT6 days ago
9

Adding a Community Agent Skill: a Markdown attack-workflow file that users import from the catalog, which then competes in the Intent Router and is injected into the agent's system prompt.

samugit83/redamon2.9k—~775Automated safety check: PassMITyesterday
10

Guided workflow for authorized penetration testing, vulnerability validation, security reporting, CTF/local sandbox reverse engineering, and user-directed vulnerability research.

lingbol088-spec/ReiPenFlow222—~1.8kAutomated safety check: PassMIT2 mo ago
11

Adding partial-recon support for a tool: running a single pipeline phase on demand from the workflow graph, reading its inputs from the existing Neo4j graph and merging results back.

samugit83/redamon2.9k—~1.1kAutomated safety check: PassMITyesterday
12

Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

PentesterFlow/agent1.4k—~1.7kAutomated safety check: PassApache-2.01 mo ago
13

Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

trailofbits/skills7.4k3 repos~4.2kAutomated safety check: NotesCC-BY-SA-4.05 days ago
14

Wiring a new tool the AI agent can call (not the recon pipeline): the tool registry, the phase map, the hardcoded dispatch chokepoint, and the duplicated execution paths that make a tool work in…

samugit83/redamon2.9k—~1.3kAutomated safety check: PassMITyesterday
15

Run an authorized, local-first application security assessment on the current project using this agent's own reasoning.

stijnswapped/Myrqen137—~2.1kAutomated safety check: PassUnknown1 mo ago
16

Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

Encod3d-Sec/TORCH3291 repo~1.8kAutomated safety check: PassMIT1 mo ago
17

GitHub Actions security review for workflow exploitation vulnerabilities.

getsentry/skills1k3 repos~2.2kAutomated safety check: NotesApache-2.04 days ago
18

Burp Suite scanning via MCP tools — passive traffic analysis, active payload testing, OOB verification, and vulnerability reporting using Burp's proxy, HTTP sender, Collaborator, and scanner APIs.

six2dez/burp-ai-agent1.5k—~6.4kAutomated safety check: WarnMIT1 mo ago
19

Adding a built-in Agent Skill (an attack technique like ssrf, xxe, rce) that ships hardcoded in RedAmon: classified by the Intent Router, injected into the agent prompt, toggled per project, badged…

samugit83/redamon2.9k—~1.4kAutomated safety check: PassMITyesterday
20

Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.

ptn1411/skill219—~917Automated safety check: PassNo licence15 days ago
21

Routes a whole-product security request to the right Strix test per asset, source code, a live app, an API or a CI pipeline, then turns results into one ranked remediation plan.

usestrix/strix67k—~1.1kAutomated safety check: PassApache-2.0today
22

Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

Encod3d-Sec/TORCH3291 repo~1.3kAutomated safety check: PassMIT1 mo ago
23

Probes an AI agent through dialogue to check whether its file, code-execution or network tools can be misused to run unexpected code or reach outside targets.

Tencent/AI-Infra-Guard6.8k—~1.5kAutomated safety check: NotesApache-2.0today
24

Writing to the Neo4j attack-surface graph in RedAmon: the tenant-isolation MERGE key every entity node must carry, where graph methods live (mixins, not the client), and the schema places that must…

samugit83/redamon2.9k—~2.2kAutomated safety check: PassMITyesterday
25

Automate low-impact web vulnerability verification through Burp MCP.

langbyyi/CyberStrikeAI-SRC133—~3.1kAutomated safety check: PassApache-2.010 days ago
26

Adding an LLM provider to RedAmon: the credential boundary (keys must never reach scan containers), prefix-routed model ids, and the provider registry.

samugit83/redamon2.9k—~1.1kAutomated safety check: PassMITyesterday
27

Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…

ADScanPro/Claude-AD209—~2.9kAutomated safety check: NotesMIT1 mo ago
28

Maps the attack surface of a web domain you are authorized to test: confirms scope, lists subdomains from public sources, probes live hosts and fingerprints technology.

PentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.01 mo ago
29

Interacting with BurpSuite over the reburp extension that exposes the full Montoya API as a local REST API.

forefy/reburp116—~883Automated safety check: PassMIT2 days ago
30

This skill should be used when the user asks to "test for insecure direct object references," "find IDOR vulnerabilities," "exploit broken access control," "enumerate user IDs or object references,"…

zebbern/claude-code-guide4.6k7 repos~3.1kAutomated safety check: PassMITtoday
31

Automated Dynamic Application Security Testing (DAST) using Playwright MCP plus standard OS pentest tooling.

hardw00t/ai-security-arsenal104—~2.2kAutomated safety check: PassNo licence5 mo ago
32

Jalankan "Kantor Agent" — kantor 3D (three.js) tanpa konfigurasi di http://127.0.0.1:8788/kerja yang menampilkan apa yang sedang dikerjakan Claude di project ini.

humaedihume/kantor-agent100—~1kAutomated safety check: PassMIT8 days ago
33

Adding, removing or changing a tool on RedAmon's INBOUND MCP server, where external agents connect in with a personal access token.

samugit83/redamon2.9k—~1.8kAutomated safety check: PassMITyesterday
34

A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

ProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT4 mo ago
35
35.Nmap

Professional network reconnaissance and port scanning using nmap.

BrownFineSecurity/iothackbot8581 repo~3.8kAutomated safety check: NotesMIT4 mo ago
36

Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

CommonHuman-Lab/nyxstrike156—~1.1kAutomated safety check: PassUnknowntoday
37

This skill should be used when the user asks to "test for SQL injection vulnerabilities", "perform SQLi attacks", "bypass authentication using SQL injection", "extract database information through…

zebbern/claude-code-guide4.6k4 repos~2.9kAutomated safety check: PassMITtoday
38

Spawning and hardening scan containers from the recon orchestrator: the security flags that look correct and break the container, and the sibling bind-mount path handling.

samugit83/redamon2.9k—~1.7kAutomated safety check: PassMITyesterday
39
39.Ssti

Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or…

PentesterFlow/agent1.4k—~1.2kAutomated safety check: PassApache-2.01 mo ago
40

Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses

NeoTheCapt/RedteamAgent140—~1.3kAutomated safety check: PassNo licence2 mo ago
41

A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

AratKruglik/claude-laravel1551 repo~1.1kAutomated safety check: NotesNo licence5 mo ago
42

IoM Operational Security (OPSEC) advisor. An agent skill from chainreactors/malice-network.

chainreactors/malice-network500—~1.4kAutomated safety check: PassApache-2.01 mo ago
43

Detects input validation failures and arithmetic vulnerabilities in smart contracts.

quillai-network/quillshield_skills129—~3.1kAutomated safety check: PassMIT6 mo ago
44

A skill your agent uses for ALL authorized offensive-security / bug-bounty work — the single method to find, chain, prove, dedup, and package the highest-value (High/Critical) findings across every…

mtarcure/claude-vibe-squad162—~3.6kAutomated safety check: PassMIT16 days ago
45

Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

forefy/.context152—~1.5kAutomated safety check: PassMIT2 days ago
46

The Priority Board's three-layer score model (rules BASE, REVIEW by the built-in AI or an MCP agent, a person's DECISION) and who may write which layer.

samugit83/redamon2.9k—~1.7kAutomated safety check: PassMITyesterday
47

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

ADScanPro/Claude-AD209—~3.6kAutomated safety check: PassMIT1 mo ago
48

Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws

NeoTheCapt/RedteamAgent140—~2.8kAutomated safety check: PassNo licence2 mo ago

Questions, answered from the data.

What is the best penetration testing skill?

Strix Code Vulnerability Scan from usestrix/strix ranks first of the 183 penetration testing skills listed here, with the highest score: its repository has 67k GitHub stars, its SKILL.md loads about 1.1k tokens and it passes the automated safety check with no findings. Next come Code Audit and Fix Strix Security Findings.

Which penetration testing skills are official?

3 of the 183 penetration testing skills are official, published by the vendor's own GitHub organization: Burp Suite Project Parser, Gha Security Review and Remediating With AWS Security Agent.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.