Framework · agent-security-skillsactivedual-usehigh-risk
Pentest AI Agents
A set of Claude Code subagents, each a domain-specific system prompt for penetration testing, installed as agent files or a plugin, offering an advisory mode and a scope-gated mode that composes and runs tools.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
High risk of account lockouts, WAF bans, and terms-of-service violations. Requires explicit authorization and small, targeted inputs.
More frameworks & agents
- Agentic Malware Analysisagent-security-skillsKali-based Docker environment with 50+ RE tools, an MCP-connected Binary Ninja or Ghidra backend, and an orchestrator skill that lets Claude Code or Codex CLI turn a binary into a case directory of ranked evidence and hypotheses.
- Anthropic Cybersecurity Skillsagent-security-skillsApache-2.0 library of 818 agentskills.io-format cybersecurity skills in 34 domains, mapped to MITRE ATT&CK, NIST CSF 2.0, ATLAS, D3FEND, NIST AI RMF and F3, for loading into Claude Code, Codex CLI, Cursor and similar agents.
- AppSec (florianbuetow)agent-security-skillsMIT Claude Code plugin bundling 62 slash-command skills across OWASP, STRIDE, PASTA, LINDDUN, MITRE ATT&CK and CWE Top 25, plus six red-team persona agents, for reviewing a codebase and generating fixes.
- Awesome Claude Securityagent-security-skillsClaude Code plugin marketplace of 45 installable plugins (110 skills) covering pentest, threat modeling, detection engineering, DFIR, GRC and LLM/agentic-AI security, with role bundles such as pentester that auto-install their parts.
- Claude Code RE Toolkitagent-security-skillsClaude Code skill pack wrapping Ghidra, YARA, CAPA, Frida, FakeNet and an 18-service threat-intel client behind Docker and VMware isolation, for static, dynamic and web-forensic malware analysis on Windows.
- Claude Security (plugin)agent-security-skillsClaude Code plugin that runs a team of agents to scan a repository or diff for vulnerabilities, independently verifies each finding, and writes Markdown, JSONL and SARIF reports plus optional patch files left for review.