Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
zhaoxuya520 avatar

Pentest Tools

  • 179 installs
  • 18.1k repo stars
  • Updated August 4, 2026
  • zhaoxuya520/reverse-skill

Organize and prioritize custom pentest payloads so your agent tries proven SQLi, XSS, SSRF, and auth-bypass tests before generic SecLists dictionaries.

About

Pentest Tools is an agent skill for solo builders and small teams who run authorized security testing on their own apps or lab targets. It defines how to maintain a personal payload library—organized by attack class—and instructs the agent to prefer those proven strings before falling back to SecLists subsets, with automatic SecLists bootstrap when empty. The README also catalogs modern LLM-driven pentest agents and MCP security stacks you can pair with the skill for recon through verification. It does not replace formal penetration tests or legal scope paperwork; it standardizes repeatable, agent-guided testing hygiene during Ship. Expect advanced familiarity with web vulnerabilities and explicit permission to test each environment.

  • Custom payload directory layout for SQLi, XSS, SSRF, LFI/RFI, auth bypass, and command injection
  • Agent rule: try local payloads first, then SecLists; bootstrap downloads SecLists if missing
  • Feedback loop to write newly effective payloads back into categorized files
  • References external AI pentest frameworks (PentestGPT, pentest-ai MCP, PentestAgent) as supplementary sources
  • Descriptive filenames required—no generic test.txt clutter

Pentest Tools by the numbers

  • 179 all-time installs (skills.sh)
  • +32 installs in the week ending Jul 28, 2026 (Skillselion tracking)
  • Ranked #817 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/zhaoxuya520/reverse-skill --skill pentest-tools

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs179
repo stars18.1k
Last updatedAugust 4, 2026
Repositoryzhaoxuya520/reverse-skill

What it does

Organize and prioritize custom pentest payloads so your agent tries proven SQLi, XSS, SSRF, and auth-bypass tests before generic SecLists dictionaries.

Files

SKILL.mdMarkdownGitHub ↗

渗透测试工具链 (Pentest Tools)

适用范围

当任务属于以下场景时使用本 skill:

  • 目标信息收集(端口扫描、子域名枚举、服务识别)
  • 漏洞扫描(Web 漏洞、CVE 检测、配置错误)
  • Web 渗透(SQL 注入、XSS、SSRF、目录爆破)
  • 密码破解(哈希破解、字典攻击)
  • 网络渗透(服务利用、横向移动辅助)

与其他 skill 的分工

场景用什么
主动扫描/攻击(Nmap/Nuclei/SQLMap)本 skill
逆向分析二进制ida-reverse/radare2/
前端 JS 签名逆向js-reverse/
浏览器/桌面自动化操作browser-automation/
CTF 竞赛(综合)CTF-Sandbox-Orchestrator/

简单判断:

  • 需要"扫描目标、发现漏洞、利用漏洞" → 本 skill
  • 需要"分析程序内部逻辑" → 逆向类 skill
  • 需要"操作浏览器/桌面" → browser-automation

---

工具矩阵

信息收集

工具用途典型命令
Nmap端口扫描、服务识别、OS 检测nmap -sV -sC -O target
Masscan大规模快速端口扫描masscan -p1-65535 target --rate=1000
Subfinder子域名枚举subfinder -d target.com
httpxHTTP 探测、存活检测httpx -l urls.txt -status-code

漏洞扫描

工具用途典型命令
Nuclei模板化漏洞扫描(CVE/配置/暴露)nuclei -u target -t cves/
ZAPWeb 应用安全扫描通过 API 或 MCP 调用
NiktoWeb 服务器漏洞扫描nikto -h target

Web 渗透

工具用途典型命令
SQLMapSQL 注入自动化sqlmap -u "url?id=1" --batch --dbs
FFUF目录/参数爆破ffuf -u target/FUZZ -w wordlist.txt
Gobuster目录/子域名爆破gobuster dir -u target -w wordlist
XSStrikeXSS 检测xsstrike -u "url?param=test"

密码破解

工具用途典型命令
HashcatGPU 哈希破解hashcat -m 0 hash.txt wordlist.txt
John the RipperCPU 哈希破解john --wordlist=rockyou.txt hash.txt
Hydra在线暴力破解hydra -l admin -P pass.txt target ssh

利用框架

工具用途说明
Metasploit漏洞利用框架需要单独安装,体量大
ImpacketWindows 协议利用(SMB/WMI/Kerberos)pip install impacket

---

MCP 后端选择

本 skill 支持两种 MCP 后端,选一个即可:

方案 A:pentestMCP(推荐,Docker 一键)

  • 项目:https://github.com/ramkansal/pentestmcp
  • 特点:20+ 工具打包成单个 Docker 容器,MCP server 直接暴露
  • 工具:Nmap、Nuclei、ZAP、SQLMap、FFUF、Nikto、Gobuster、Subfinder、httpx 等
  • 安装
# 拉取并运行
docker pull ramkansal/pentestmcp
docker run -d -p 8080:8080 ramkansal/pentestmcp

# 或本地构建
git clone https://github.com/ramkansal/pentestmcp.git
cd pentestmcp
docker build -t pentestmcp .
docker run -d -p 8080:8080 pentestmcp
  • MCP 注册
{
  "mcpServers": {
    "pentest": {
      "url": "http://localhost:8080/mcp"
    }
  }
}

方案 B:mcp-security-hub(模块化)

  • 项目:https://github.com/FuzzingLabs/mcp-security-hub
  • 特点:每个工具独立 MCP server,按需启用
  • 工具:Nmap、Ghidra、Nuclei、SQLMap、Hashcat
  • 安装:按各子模块 README 操作

方案 C:单工具 MCP(最轻量)

如果只需要某一个工具:

工具MCP 项目安装
Nmapnmap-mcp-servernpm
Nucleinuclei-mcpnpm
SQLMapmcp-security-hub 子模块pip

---

工作流

标准渗透流程

重要:执行渗透测试时,必须按 references/pentest-loop.md 的自主循环框架运行。
该框架定义了完整的风险门控、记录规范、上下文压缩和完成检查机制。
1. 信息收集
   - Nmap 端口扫描 → 确认开放服务
   - Subfinder 子域名枚举 → 扩大攻击面
   - httpx 存活检测 → 过滤有效目标

2. 漏洞扫描
   - Nuclei 模板扫描 → 快速发现已知漏洞
   - ZAP/Nikto → Web 应用深度扫描

3. 漏洞利用
   - SQLMap → SQL 注入
   - FFUF → 发现隐藏路径/参数
   - 手动验证 → 确认可利用性

4. 后渗透(如果授权范围内)
   - 权限提升
   - 横向移动
   - 数据提取

5. 报告
   - 调用 docs-generator skill 生成渗透测试报告

快速扫描流程(5 分钟出结果)

1. nmap -sV -sC target → 端口+服务
2. nuclei -u target -severity critical,high → 高危漏洞
3. 有 Web 服务 → ffuf -u target/FUZZ -w common.txt → 目录
4. 汇总发现 → 决定下一步

---

注意事项

  • 必须有授权 — 所有扫描/攻击操作必须在授权范围内
  • 控制扫描速率 — 避免触发 WAF/IDS 或打崩目标
  • 先被动后主动 — 先信息收集,再漏洞扫描,最后利用
  • 记录所有操作 — 每个命令和结果都要记录,用于报告
  • 不要盲目自动化 — AI 应该在每个关键步骤等待确认

---

按需自举(On-Demand Bootstrap)

自动化能力边界

工具可自动安装安装方式说明
Nmapwinget (Insecure.Nmap)Windows 版
Nucleigo install 或 GitHub Release需要 Go 或直接下载二进制
SQLMappip install sqlmap 或 git clonePython
FFUFGitHub ReleaseGo 二进制
SecListsGitHub Release ZIP字典大全(FFUF/Gobuster 必备)
Hashcat手动下载需要 GPU 驱动
Metasploit手动安装体量大,建议用 Kali
pentestMCP (Docker)需要 Dockerdocker run ramkansal/pentestmcp
Impacketpip install impacketPython
ProxyCatpip install proxycat代理池中间件(批量扫描防封)
BurpSuite MCPBurpSuite 扩展市场安装需要 BurpSuite Pro/Community

自举策略

1. 如果用户有 Docker → 推荐 pentestMCP(一键全家桶) 2. 如果没有 Docker → 按需单独安装各工具 3. 优先安装 Nmap + Nuclei + SQLMap(覆盖 80% 场景)

手动安装引导

⚠️ **渗透工具未安装**

**推荐方案(需要 Docker)**:
docker pull ramkansal/pentestmcp
docker run -d -p 8080:8080 ramkansal/pentestmcp

**轻量方案(逐个安装)**:
- Nmap: winget install Insecure.Nmap
- Nuclei: go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest
- SQLMap: pip install sqlmap
- FFUF: 从 https://github.com/ffuf/ffuf/releases 下载

**安装后告诉我,我继续当前任务。**

---

参考资源

本 skill 内参考文档

  • references/pentest-loop.md核心循环框架(风险门控 + 记录规范 + 上下文压缩)
  • references/burpsuite-mcp-guide.mdBurpSuite MCP 完整指南(63 工具 + 7 大使用场景 + AI Prompt 模板)
  • references/automation-loop-pattern.md — 自动化循环测试模式(轻量版)
  • references/awesome-pentest-digest.md — 渗透工具精华速查
  • references/pentest-ai-agents-matrix.md — 35 agent 覆盖矩阵
  • payloads/ — 自定义 payload 目录(AI 优先使用)
  • templates/ — 渗透测试必需文件模板(scope/rules/plan/findings/progress)

src-hunter 漏洞挖掘知识库

src-hunter/ 目录包含完整的 SRC/Bug Bounty 漏洞挖掘方法论:

  • 19 类攻击 playbook(IDOR、RCE、XSS、SQLi、SSRF、OAuth、文件上传等)
  • 305 个结构化 payload + 263 个 WAF/EDR 绕过步骤
  • 2887 份 HackerOne 已披露 High/Critical 报告
  • 88,636 条 WooYun 历史案例统计
  • 国产组件指纹和默认凭据
  • CVSS 4.0 报告模板

使用方式:AI 在 hunt 阶段自动读取对应 playbook,按其流程测试。

详见 src-hunter/SKILL.mdsrc-hunter/references/

---

路由上下文

上游入口: skills/SKILL.md(总控)、routing.md 触发条件: 需要主动扫描/攻击目标(端口扫描、漏洞检测、注入测试等) 下游出口:

  • 发现 Web 漏洞需要进一步分析 → js-reverse/
  • 发现二进制漏洞需要逆向 → ida-reverse/radare2/
  • 需要操作浏览器验证漏洞 → browser-automation/
  • 完成后生成报告 → docs-generator/

同级关联模块: CTF-Sandbox-Orchestrator/(CTF 中的 Web/Pwn 题会用到这些工具)

Related skills

Securityappsecaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.