Topic · Security

Best penetration testing skills, page 4

Skills #145–183 of 183, ranked by score.

Penetration testing skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Penetration testing skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
145

Attack and enumerate Azure AD / Entra ID tenants — initial recon with AADInternals and ROADtools, password spraying, token theft (PRT, CAE, refresh tokens), application and service principal abuse…

trilwu/secskills156—~4.3kAutomated safety check: PassMIT1 mo ago
146

Prioritize and drive remediation of a vulnerability backlog by real risk, not raw CVSS — combining severity with exploitation signals (EPSS, CISA KEV), asset exposure and business context, using…

trilwu/secskills156—~2.2kAutomated safety check: PassMIT1 mo ago
147

Write security findings and assessment reports — severity scoring with CVSS and business impact, reproducible proof of concept, remediation guidance, executive summaries, and coordinated disclosure.

trilwu/secskills156—~3.4kAutomated safety check: PassMIT1 mo ago
148

Pentest Android and iOS mobile applications including APK analysis, dynamic analysis, SSL pinning bypass, root/jailbreak detection bypass, and mobile-specific vulnerabilities.

trilwu/secskills156—~2.8kAutomated safety check: PassMIT1 mo ago
149

Enumerates Active Directory trust relationships and exploits them for cross-domain and cross-forest privilege escalation.

blacklanternsecurity/red-run286—~4.5kAutomated safety check: NotesGPL-3.09 days ago
150
150.Hack

Entry P0 primary router and operating doctrine for HackSkills.

yaklang/hack-skills2.4k—~4.7kAutomated safety check: NotesMIT24 days ago
151

Coordinate a PCI DSS penetration-testing and CDE-scoping readiness assessment across methodology, scope, segmentation, execution evidence, remediation, and retesting.

cyberful/cyberful134—~895Automated safety check: PassAGPL-3.01 mo ago
152

Security architecture review, control validation, penetration testing guidance, and compliance verification for the CIA platform

Hack23/cia239—~1.9kAutomated safety check: PassApache-2.0today
153

HTTP request smuggling via CL.TE/TE.CL desync and cache poisoning

NeoTheCapt/RedteamAgent140—~982Automated safety check: PassNo licence2 mo ago
154

Frontend source code analysis for hidden routes, API endpoints, and secrets

NeoTheCapt/RedteamAgent140—~3kAutomated safety check: PassNo licence2 mo ago
155

Detect and exploit SQL injection vulnerabilities in web application parameters

NeoTheCapt/RedteamAgent140—~1.2kAutomated safety check: PassNo licence2 mo ago
156

Detect and exploit server-side request forgery to access internal resources and cloud metadata

NeoTheCapt/RedteamAgent140—~768Automated safety check: PassNo licence2 mo ago
157

Subdomain discovery via subfinder, DNS brute-force, and passive sources

NeoTheCapt/RedteamAgent140—~1.7kAutomated safety check: NotesNo licence2 mo ago
158

Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference

NeoTheCapt/RedteamAgent140—~2.9kAutomated safety check: PassNo licence2 mo ago
159

Enumerate web technologies, headers, endpoints, and metadata from a target

NeoTheCapt/RedteamAgent140—~770Automated safety check: PassNo licence2 mo ago
160

Detect and exploit cross-site scripting vulnerabilities in web applications

NeoTheCapt/RedteamAgent140—~1.4kAutomated safety check: PassNo licence2 mo ago
161

XML external entity injection for file read, SSRF, and DoS. An agent skill from NeoTheCapt/RedteamAgent.

NeoTheCapt/RedteamAgent140—~1kAutomated safety check: PassNo licence2 mo ago
162

Build or challenge an application threat model from architecture, dataflows, identities, trust boundaries, business invariants, dependencies, and deployment context.

cyberful/cyberful134—~1.2kAutomated safety check: PassAGPL-3.01 mo ago
163

Audit C, C++, unsafe Rust, native extensions, parsers, codecs, FFI boundaries, and systems code for memory corruption and low-level exploitation risk.

cyberful/cyberful134—~829Automated safety check: PassAGPL-3.01 mo ago
164

Operate Cyberful as an authorized application-security control room.

cyberful/cyberful134—~1.1kAutomated safety check: PassAGPL-3.0-only1 mo ago
165

Bypass antivirus and EDR detection for payload delivery during exploitation.

blacklanternsecurity/red-run286—~5.4kAutomated safety check: NotesGPL-3.09 days ago
166

Host discovery and port scanning using nmap — ICMP/ARP host discovery, SYN/TCP/UDP port scanning with scope enforcement and audit logging.

automateyournetwork/netclaw674—~1.3kAutomated safety check: PassApache-2.02 days ago
167

Custom nmap scans with arbitrary flags, plus scan history retrieval and management.

automateyournetwork/netclaw674—~1.2kAutomated safety check: PassApache-2.02 days ago
168

Service fingerprinting, OS detection, NSE script execution, and vulnerability scanning using nmap MCP.

automateyournetwork/netclaw674—~1.5kAutomated safety check: PassApache-2.02 days ago
169

Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.

ArabelaTso/Skills-4-SE253—~3.5kAutomated safety check: PassApache-2.01 mo ago
170

Assess AI-system risk from architecture, intended use, affected actors, model limitations, data lineage, autonomy, human oversight, monitoring, and failure consequences.

cyberful/cyberful134—~566Automated safety check: PassAGPL-3.01 mo ago
171

使用 naabu 进行高速端口扫描。当需要对目标主机/网段进行端口发现、存活检测时使用。naabu 是 ProjectDiscovery 出品的快速端口扫描器,支持 SYN/CONNECT/UDP 扫描,性能远超 nmap,支持批量目标、CDN 排除、nmap 集成。任何涉及端口扫描、端口发现、主机存活检测、网段探测的场景都应使用此技能。如果 naabu 结果不足再降级用 nmap

wgpsec/AboutSecurity1.8k—~812Automated safety check: NotesNo licence4 days ago
172

使用 nmap 进行端口扫描和服务识别。当需要对目标进行精细端口扫描、服务版本探测、操作系统指纹识别、NSE 脚本漏洞扫描时使用。nmap 是最经典的网络扫描器,支持 SYN/TCP/UDP/ACK 等多种扫描模式,内置 600+ NSE 脚本。任何涉及端口扫描、服务识别、漏洞脚本扫描、操作系统指纹的场景都应使用此技能。速度不如 naabu,但功能远超 naabu

wgpsec/AboutSecurity1.8k—~652Automated safety check: NotesNo licence4 days ago
173

Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts

NeoTheCapt/RedteamAgent140—~5.1kAutomated safety check: NotesNo licence2 mo ago
174

OS command injection detection, exploitation, and filter bypass

NeoTheCapt/RedteamAgent140—~754Automated safety check: PassNo licence2 mo ago
175

File upload vulnerability testing — webshells, bypass, path traversal

NeoTheCapt/RedteamAgent140—~1.6kAutomated safety check: PassNo licence2 mo ago
176

Insecure direct object reference testing for broken access control

NeoTheCapt/RedteamAgent140—~793Automated safety check: PassNo licence2 mo ago
177

Information disclosure detection — error messages, files, headers, debug endpoints

NeoTheCapt/RedteamAgent140—~1.1kAutomated safety check: NotesNo licence2 mo ago
178

Server-side template injection detection, engine identification, and RCE

NeoTheCapt/RedteamAgent140—~748Automated safety check: PassNo licence2 mo ago
179

Expert-level Nmap skill for network reconnaissance, port scanning, service detection, and security assessment.

theneoai/awesome-skills183—~4.4kAutomated safety check: PassMIT4 mo ago
180

Elite Security Engineer skill with deep expertise in application security, cloud security architecture, penetration testing, Zero Trust implementation, threat modeling (STRIDE), and compliance…

theneoai/awesome-skills183—~2.1kAutomated safety check: PassMIT4 mo ago
181

Security audit workflow - OWASP Top 10, input validation, auth, secret detection, vulnerability scan

vibeeval/vibecosystem531—~807Automated safety check: PassMIT1 mo ago
182

API security expertise covering OWASP API Security Top 10, API authentication and authorization patterns, API key management, rate limiting and throttling, JWT security best practices, OAuth 2.0…

FerroxLabs/wayland608—~3.1kAutomated safety check: PassApache-2.0yesterday
183

Becomes a senior DevOps engineer who designs and implements CI/CD pipelines, infrastructure as code, monitoring systems, and deployment strategies.

FerroxLabs/wayland608—~4.8kAutomated safety check: PassApache-2.0yesterday