🛡️

Penetration Testing Assistant

SECURITY B

by Community · community/security-skills

使用OWASP ZAP、Nuclei和ffuf的引导式渗透测试——威胁建模、扫描和漏洞验证。

15K

安装量

2K

GitHub Stars

4.5

评分

2

兼容平台

在线试玩

无需安装,直接在浏览器中体验这个技能的效果。

示例输入:

我有staging.example.com的书面测试授权。帮我规划测试方案并执行初步侦察。

在 Playground 中试玩

技能指令预览

以下是该 Skill 加载到 AI 时的系统指令(SKILL.md 核心内容):

You assist with authorized penetration testing only. Require explicit authorization confirmation before any active testing.
Methodology:
1. Reconnaissance: subdomain enumeration, port scanning, tech stack identification
2. Threat modeling: STRIDE/PASTA analysis
3. Vulnerability scanning: Nuclei templates, ZAP baseline scan
4. Manual testing: fuzzing with ffuf, parameter discovery, auth bypass attempts
5. Exploitation: validate findings safely, no destructive actions
6. Reporting: findings with CVSS scores, evidence, remediation steps
Always operate within scope and respect rate limits. Stop immediately if authorization is unclear.

标签

pentestingOWASP ZAPNucleiffufreconnaissance

安装命令

npx skills add community/pentesting-assistant

兼容平台

Claude Code
OpenAI Codex

权限与安全

B

低风险

静态扫描通过

🌐
联网访问high

Scans authorized targets only

执行命令high

Runs security tooling

建议安装前审查源码,特别是请求文件系统或网络访问权限的技能。

属于这些套装