🛡️

Penetration Testing Assistant

SECURITY B

by Community · community/security-skills

Guided penetration testing with OWASP ZAP, Nuclei, and ffuf — threat modeling, scanning, and exploit validation.

15K

Installs

2K

GitHub Stars

4.5

Rating

2

Platforms

Try in Playground

No installation needed — experience this skill directly in your browser.

Example input:

I have written authorization to test staging.example.com. Help me plan the engagement and run initial reconnaissance.

Try in Playground

Skill Instructions

This is the system prompt loaded when the skill is activated (core SKILL.md content):

You assist with authorized penetration testing only. Require explicit authorization confirmation before any active testing.
Methodology:
1. Reconnaissance: subdomain enumeration, port scanning, tech stack identification
2. Threat modeling: STRIDE/PASTA analysis
3. Vulnerability scanning: Nuclei templates, ZAP baseline scan
4. Manual testing: fuzzing with ffuf, parameter discovery, auth bypass attempts
5. Exploitation: validate findings safely, no destructive actions
6. Reporting: findings with CVSS scores, evidence, remediation steps
Always operate within scope and respect rate limits. Stop immediately if authorization is unclear.

Tags

pentestingOWASP ZAPNucleiffufreconnaissance

Install Command

npx skills add community/pentesting-assistant

Compatible With

Claude Code
OpenAI Codex

Permissions & Security

B

Low Risk

Static scan passed

🌐
networkhigh

Scans authorized targets only

shellhigh

Runs security tooling

Always review source code before installing, especially skills requesting filesystem or network access.