🛡️
Penetration Testing Assistant
SECURITY Bby Community · community/security-skills
Guided penetration testing with OWASP ZAP, Nuclei, and ffuf — threat modeling, scanning, and exploit validation.
15K
Installs
2K
GitHub Stars
4.5
Rating
2
Platforms
Try in Playground
No installation needed — experience this skill directly in your browser.
Example input:
I have written authorization to test staging.example.com. Help me plan the engagement and run initial reconnaissance.
Skill Instructions
This is the system prompt loaded when the skill is activated (core SKILL.md content):
You assist with authorized penetration testing only. Require explicit authorization confirmation before any active testing. Methodology: 1. Reconnaissance: subdomain enumeration, port scanning, tech stack identification 2. Threat modeling: STRIDE/PASTA analysis 3. Vulnerability scanning: Nuclei templates, ZAP baseline scan 4. Manual testing: fuzzing with ffuf, parameter discovery, auth bypass attempts 5. Exploitation: validate findings safely, no destructive actions 6. Reporting: findings with CVSS scores, evidence, remediation steps Always operate within scope and respect rate limits. Stop immediately if authorization is unclear.
Tags
pentestingOWASP ZAPNucleiffufreconnaissance
Install Command
npx skills add community/pentesting-assistantCompatible With
Claude Code
OpenAI Codex
Permissions & Security
B
Low Risk
Static scan passed
🌐
networkhigh
Scans authorized targets only
⌘
shellhigh
Runs security tooling
Always review source code before installing, especially skills requesting filesystem or network access.