Topic · Security
Best penetration testing skills, page 3
Penetration testing skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 97 | Detects and exploits Server-Side Template Injection (SSTI) vulnerabilities across Jinja2, Twig, Freemarker, and other template engines to achieve remote code execution. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 98 | Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 99 | Simulates ARP spoofing/cache-poisoning attacks in authorized lab or pentest environments using arpspoof, Ettercap, and Scapy to demonstrate man-in-the-middle risk and validate Dynamic ARP… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 100 | Performs comprehensive iOS application security assessments using Frida for dynamic instrumentation, Objection for runtime exploration, SSL pinning bypass for traffic interception, keychain… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 101 | Bypasses Web Application Firewall protections using encoding tricks, HTTP method manipulation, parameter pollution, and payload obfuscation to smuggle SQL injection, XSS, and other exploit payloads… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 102 | Hardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 103 | Manually identifies flaws in application business logic - price manipulation, multi-step workflow bypass, and privilege escalation - by intercepting and modifying requests with Burp Suite, going… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 104 | Triages and prioritizes vulnerabilities with CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree, weighing exploitation status (via the CISA KEV catalog and FIRST EPSS… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 105 | A skill your agent uses when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. | alirezarezvani/ | 28k | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 106 | 106.Nmap Parse Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills. | SpecterOps/ | 702 | — | ~738 | Automated safety check: Pass | Apache-2.0 | 14 days ago |
| 107 | Cracks password hashes with Hashcat, covering hash-type identification, dictionary/brute-force/rule-based attack modes, custom rule creation, GPU benchmarking, and password-strength/compliance… | mukul975/ | 34k | — | ~893 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 108 | Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains | NeoTheCapt/ | 140 | — | ~608 | Automated safety check: Pass | No licence | 2 mo ago |
| 109 | A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before… | hypnguyen1209/ | 386 | — | ~660 | Automated safety check: Pass | MIT | 9 days ago |
| 110 | Application security defense knowledge for builders. An agent skill from telagod/code-abyss. | telagod/ | 244 | — | ~777 | Automated safety check: Pass | MIT | 2 mo ago |
| 111 | Analyzes malware C2 communication over HTTP, HTTPS, DNS, and custom protocols to reverse-engineer beacon patterns, command structures, data encoding, and infrastructure (primary servers, fallback… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 112 | Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 113 | Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 114 | Conducts authorized wireless network penetration tests to assess the security of WiFi infrastructure by testing for weak encryption protocols, captive portal bypasses, evil twin attacks, WPA2/WPA3… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 115 | Detect network reconnaissance and port scanning using Suricata and Snort IDS signatures, threshold-based detection rules, and traffic anomaly analysis to identify Nmap, Masscan, and custom scanning… | mukul975/ | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 116 | Use Certipy to enumerate AD CS certificate authorities and templates over LDAP/RPC, then exploit ESC1-ESC16 misconfigurations - SAN abuse, NTLM relay to web enrollment (ESC8), Shadow Credentials… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 117 | Detects and exploits HTTP request smuggling caused by Content-Length/Transfer-Encoding parsing discrepancies between front-end and back-end servers, using Burp Suite Repeater (auto Content-Length… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 118 | Identifies and exploits SQL injection vulnerabilities in web applications during authorized penetration tests using manual techniques and automated tools like sqlmap. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 119 | Detecting and exploiting SQL injection vulnerabilities using sqlmap to extract database contents during authorized penetration tests. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 120 | Performs advanced network recon using Nmap's Scripting Engine (NSE), timing controls, firewall/IDS evasion, and structured output parsing to discover hosts, enumerate service versions, detect… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 121 | Audit SillyTavern rolecard JSON, embedded HTML, regex replacements, Tavern Helper scripts, loaders, and related source for injection, dynamic execution, remote-code, wildcard messaging… | LiarMTTT/ | 148 | — | ~993 | Automated safety check: Pass | Unknown | 3 days ago |
| 122 | This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp ... | aiskillstore/ | 430 | 4 repos | ~2.7k | Automated safety check: Pass | No licence | today |
| 123 | 123.Secure By Design Run an enterprise security review of a system design or existing code before it ships. | ooiyeefei/ | 494 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 124 | Discover hidden parameters, test values, and identify input handling anomalies | NeoTheCapt/ | 140 | — | ~944 | Automated safety check: Pass | No licence | 2 mo ago |
| 125 | Detects and exploits MS17-010 (EternalBlue), a critical remote code execution flaw in Microsoft's SMBv1 implementation, using Nmap's ms-17-010 NSE script for detection and Metasploit's… | mukul975/ | 34k | — | ~963 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 126 | 126.File Inclusion Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution | NeoTheCapt/ | 140 | — | ~988 | Automated safety check: Warn | No licence | 2 mo ago |
| 127 | 127.Network Scanner Run authorized network reconnaissance with Nmap on Windows (or Linux). | ptn1411/ | 219 | — | ~1.4k | Automated safety check: Notes | No licence | 15 days ago |
| 128 | 128.Offensive Wifi Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. | SnailSploit/ | 7.3k | — | ~2.8k | Automated safety check: Notes | MIT | 17 days ago |
| 129 | 129.Screenshot Burp Capture a Burp Suite Repeater request/response as a PoC image (targets/<eng/poc/) by driving the Burp MCP + the Kali GUI. | Encod3d-Sec/ | 329 | — | ~1.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 130 | AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and… | modu-ai/ | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | today |
| 131 | A skill your agent uses when conducting a frontend security review — static analysis (risky HTML patterns, env var exposure), authentication/authorization audit (token storage, route guards… | mizchi/ | 356 | — | ~1.7k | Automated safety check: Notes | No licence | 5 days ago |
| 132 | 132.Port Scanning Discover open ports, running services, and their versions on a target | NeoTheCapt/ | 140 | — | ~634 | Automated safety check: Pass | No licence | 2 mo ago |
| 133 | Multi-source threat intelligence and vulnerability lookup. An agent skill from ptn1411/skill. | ptn1411/ | 219 | — | ~1.1k | Automated safety check: Pass | No licence | 15 days ago |
| 134 | Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 135 | 135.Securing Systems Security engineering router for penetration testing, code auditing, red/blue/purple team operations, threat intelligence, and vulnerability research. | telagod/ | 244 | — | ~581 | Automated safety check: Pass | MIT | 2 mo ago |
| 136 | CORS misconfiguration testing playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.4k | Automated safety check: Pass | MIT | 24 days ago |
| 137 | Subdomain takeover detection and exploitation playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.6k | Automated safety check: Pass | MIT | 24 days ago |
| 138 | Comprehensive API security testing methodology covering REST, gRPC, and WebSocket attack surfaces. | SnailSploit/ | 7.3k | — | ~5k | Automated safety check: Pass | MIT | 17 days ago |
| 139 | Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. | aws/ | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | today |
| 140 | 140.Hunt Burp Drive Burp Suite over its MCP server as an AI triage + attack layer - review proxy history for signals, replay via Repeater/send, OOB-gate blind bugs with Collaborator, fuzz via Intruder (RoE-safe)… | Encod3d-Sec/ | 329 | — | ~3.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 141 | 141.Metasploit Drive msfconsole across the workflow - DB-backed recon (dbnmap, auxiliary scanners), version-exploit search/check/run, multi/handler reverse shells (meterpreter-first, plain shellreversetcp backup… | Encod3d-Sec/ | 329 | — | ~1k | Automated safety check: Pass | MIT | 1 mo ago |
| 142 | 142.Security Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries… | telagod/ | 244 | — | ~907 | Automated safety check: Pass | MIT | 2 mo ago |
| 143 | 143.Cryptography Cryptanalysis techniques — lattice attacks, padding oracles, weak-RNG exploitation, signature forgery, secret-sharing recovery. | transilienceai/ | 559 | — | ~465 | Automated safety check: Pass | MIT | 2 mo ago |
| 144 | Run a third-party / vendor security review and assign a risk tier with required controls. | mohitagw15856/ | 1.4k | — | ~1.1k | Automated safety check: Pass | MIT | yesterday |
Explore related skills
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Cloud security90
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34