Topic · Security

Best penetration testing skills, page 2

Skills #49–96 of 182, ranked by score.

Penetration testing skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Penetration testing skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
49

Active Directory Certificate Services (AD CS) escalation techniques ESC1 through ESC17, driven by hand with Certipy (ly4k).

ADScanPro/Claude-AD210—~3.6kAutomated safety check: PassMIT1 mo ago
50

Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws

NeoTheCapt/RedteamAgent142—~2.8kAutomated safety check: PassNo licence2 mo ago
51

Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

quillai-network/quillshield_skills129—~2.8kAutomated safety check: PassMIT6 mo ago
52

Expert CIS Controls v8 (CIS Top 18) advisor — implementation group scoping (IG1/IG2/IG3), control gap assessments, safeguard-level guidance, asset inventory, software inventory, data protection…

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~4.2kAutomated safety check: PassMIT3 days ago
53

Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools

CommonHuman-Lab/nyxstrike157—~639Automated safety check: PassUnknowntoday
54

Changing or adding a project setting / default value in RedAmon.

samugit83/redamon3k—~2.4kAutomated safety check: PassMITtoday
55

Authentication coercion (PetitPotam MS-EFSR, PrinterBug MS-RPRN, DFSCoerce MS-DFSNM) chained into NTLM relay (impacket ntlmrelayx) toward LDAP, AD CS web enrollment (ESC8), or SMB.

ADScanPro/Claude-AD210—~1.9kAutomated safety check: PassMIT1 mo ago
56

CORS misconfiguration testing for data theft and access control bypass

NeoTheCapt/RedteamAgent142—~904Automated safety check: PassNo licence2 mo ago
57

Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

AgentSecOps/SecOpsAgentKit2201 repo~3.3kAutomated safety check: NotesUnknown5 mo ago
58

Build a high-fidelity network and service inventory using Nmap, Masscan, packet capture, DNS, and protocol-specific follow-up.

cyberful/cyberful135—~1.1kAutomated safety check: PassAGPL-3.01 mo ago
59

Wiring an LLM into a recon tool's decisions ("let AI pick {feature} for {tool}"): the never-raise contract, the per-target cache, the full+partial coverage, and the two UI toggles bound to one field.

samugit83/redamon3k—~2.2kAutomated safety check: PassMITtoday
60

Kerberos-based Active Directory attacks driven by hand with standard tooling (Kerberoasting, AS-REP roasting, and delegation abuse: unconstrained, constrained/S4U, RBCD).

ADScanPro/Claude-AD210—~2.9kAutomated safety check: NotesMIT1 mo ago
61

Check reburp's Montoya API coverage and detect when a Burp/Montoya upgrade added or changed APIs.

forefy/reburp117—~213Automated safety check: PassMIT3 days ago
62

Cross-site request forgery testing for state-changing operations

NeoTheCapt/RedteamAgent142—~791Automated safety check: PassNo licence2 mo ago
63
63.Cso

Chief Security Officer mode. An agent skill from no-session/pstack.

no-session/pstack134—~12kAutomated safety check: NotesMIT6 mo ago
64

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing.

davila7/claude-code-templates32k2 repos~1.1kAutomated safety check: NotesMITtoday
65

Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

Encod3d-Sec/TORCH329—~611Automated safety check: PassMIT1 mo ago
66

Generate a Transilience-branded PDF report (pentest, vuln assessment, compliance, threat intel) from a single findings JSON using the bundled ReportLab generator.

transilienceai/communitytools562—~1.7kAutomated safety check: PassMIT2 mo ago
67

Adding a new tool to the recon pipeline: the enrichment-module contract and its isolated wrapper (the actual fan-out and test call path), graph completeness, and the preset catalog that silently…

samugit83/redamon3k—~1.9kAutomated safety check: PassMITtoday
68

Insecure deserialization detection and gadget chain exploitation

NeoTheCapt/RedteamAgent142—~836Automated safety check: PassNo licence2 mo ago
69

SQL injection detection→exploitation→proof for web apps and APIs.

s0ld13rr/pentestcode827—~710Automated safety check: PassMIT5 days ago
70

Comprehensive security auditing workflow covering web application testing, API security, penetration testing, vulnerability scanning, and security hardening.

davila7/claude-code-templates32k4 repos~1.3kAutomated safety check: PassMITtoday
71

Subdomain and DNS enumeration workflow using subfinder, amass, dnsenum, fierce, theharvester, gau, and waybackurls

CommonHuman-Lab/nyxstrike157—~858Automated safety check: PassUnknowntoday
72

Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

Encod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT1 mo ago
73

How RedAmon tests actually run and how to author them: the per-file Docker gate, the unit/integration/live tiers, and the failure modes that make a green run a lie.

samugit83/redamon3k—~1.8kAutomated safety check: PassMITtoday
74

Working on RedAmon's supply-chain scanner (offline OSV + GuardDog + retire + trufflehog): the offline OSV database that the scan path does not bootstrap, the world-readable requirement for the…

samugit83/redamon3k—~855Automated safety check: PassMITtoday
75

Working on the HTTP capture proxy and its replay/fuzz path: the egress guard that stops the proxy becoming an SSRF pivot, why it checks the resolved IP, and keeping capture off the scan's critical…

samugit83/redamon3k—~771Automated safety check: PassMITtoday
76

Discover hidden directories, files, and endpoints on a web server

NeoTheCapt/RedteamAgent142—~737Automated safety check: NotesNo licence2 mo ago
77

A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch.

ADScanPro/Claude-AD210—~1.7kAutomated safety check: PassMIT1 mo ago
78

Multi-tenant authz, pre-auth disclosure hardening, and Kali disposition.

bbartling/open-fdd172—~2.2kAutomated safety check: PassUnknowntoday
79

Squad de 15 agentes de seguranca ofensiva e defensiva (Georgia Weidman, Peter Kim, Jim Manico, Chris Sanders, Omar Santos, Marcus Carey) cobrindo pentest, red team, blue team, AppSec, recon e…

ohmyjahh/xquads-squads276—~895Automated safety check: PassMIT8 days ago
80

Security audit expert for OWASP Top 10, CVE analysis, code review, and penetration testing methodology

RightNow-AI/openfang18k—~858Automated safety check: PassApache-2.03 mo ago
81

Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f

CommonHuman-Lab/nyxstrike157—~907Automated safety check: PassUnknowntoday
82

Network reconnaissance and security auditing using Nmap for port scanning, service enumeration, and vulnerability detection.

AgentSecOps/SecOpsAgentKit2201 repo~4.6kAutomated safety check: NotesUnknown5 mo ago
83

Automated SQL injection detection and exploitation tool for web application security testing.

AgentSecOps/SecOpsAgentKit2201 repo~3.2kAutomated safety check: PassUnknown5 mo ago
84
84.Dora

Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities.

Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9421 repo~6.9kAutomated safety check: PassMIT3 days ago
85

Detects fileless malware and in-memory attacks that execute entirely in RAM without writing persistent files to disk, evading traditional antivirus.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.8kAutomated safety check: PassApache-2.01 mo ago
86

Detect abuse of elevation control mechanisms (T1548), including Windows UAC bypass via auto-elevating binaries like fodhelper.exe and Linux sudo/setuid/setgid exploitation, by monitoring registry…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.5kAutomated safety check: NotesApache-2.01 mo ago
87

Identifies and exploits insecure local data storage vulnerabilities in Android and iOS mobile applications including unencrypted databases, world-readable files, insecure SharedPreferences…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.01 mo ago
88

Uses the Metasploit Framework (msfconsole and its exploit, auxiliary, and post-exploitation modules) to validate that identified CVEs and vulnerabilities are actually exploitable, gather…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.01 mo ago
89

Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach, AttackIQ, Picus, Cymulate, Pentera, or SCYTHE to continuously validate endpoint, network, email-gateway, SIEM, and…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.01 mo ago
90

Implements memory protection mechanisms including DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), CFG (Control Flow Guard), and other exploit mitigations to prevent…

mukul975/Anthropic-Cybersecurity-Skills34k—~1kAutomated safety check: PassApache-2.01 mo ago
91

Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: PassApache-2.01 mo ago
92

Invoke for 等保2.0 full-lifecycle assessment on corporate networks on Kali Linux: classification, gap analysis, baseline audit, vuln scanning, penetration testing, and compliance reporting per GB/T…

openocta/openocta_skills166—~6.3kAutomated safety check: NotesMIT3 mo ago
93

Web vulnerability scanning workflow covering SQLi, XSS, template injection, and generic CVE detection using nuclei, sqlmap, dalfox, nikto, and jaeles

CommonHuman-Lab/nyxstrike157—~896Automated safety check: PassUnknowntoday
94

Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

Encod3d-Sec/TORCH329—~1.6kAutomated safety check: NotesMIT1 mo ago
95

Detect cyber attacks on OT historian servers (OSIsoft PI, Ignition, GE Proficy, Wonderware InSQL) using a Python detector that flags unauthorized queries, data manipulation, and lateral-movement…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
96

Detects and analyzes Bluetooth Low Energy (BLE) security attacks including sniffing, replay attacks, GATT enumeration abuse, and Man-in-the-Middle interception.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago