By sabania
Conduct AI-orchestrated pentests on deployed web apps via CLI: run passive recon, discovery of APIs/secrets/cloud backends, scans for injections/auth/business logic/cloud misconfigs/WAFs, optional active exploits with consent, and generate PDF reports with severity-ranked findings and remediations.
npx claudepluginhub sabania/pentest-cli --plugin pentest-frameworkAdvanced attack specialist. Tests request smuggling, race conditions, cache poisoning, subdomain takeover.
Authentication and session tester. Analyzes JWT tokens, OAuth flows, session management, credential attacks.
Discovery specialist. Reverse engineers JS bundles, finds API endpoints, probes BaaS backends.
Injection tester. Tests SQLi, XSS, SSTI, SSRF, XXE, and other injection vectors.
Business logic analyst. Tests IDOR, privilege escalation, payment bypass, workflow manipulation, and authorization flaws.
Reconnaissance specialist. Maps attack surface: subdomains, ports, DNS, tech stack, OSINT.
Report generator. Aggregates all findings into a professional PDF security report.
Configuration scanner. Tests security headers, SSL/TLS, CORS, WAF, and web server hardening.
Business logic and authorization testing. IDOR, privilege escalation, workflow bypass, payment manipulation.
Show all available pentest-cli commands and how to use them.
Advanced attack testing. Request smuggling, race conditions, cache poisoning, subdomain takeover.
Authentication and session security testing. JWT, OAuth, sessions, brute force.
Cloud and infrastructure testing. Storage misconfig, WAF detection, email security.
Discovery scan. JS bundles, API endpoints, GraphQL, secrets, BaaS backends.
Complete security audit. Runs ALL passive + active tests and generates report.
Injection testing. SQLi, XSS, SSTI, SSRF, and more. Requires user consent for active testing.
Full reconnaissance scan on a deployed app. Subdomains, DNS, ports, tech stack, OSINT.
Generate PDF security report from findings.
Security configuration scan. Headers, SSL/TLS, CORS, SRI checks.
Install pentest-cli and verify the security testing environment. Run this first.
The AI pentest co-pilot that actually finds bugs. Phase-chained, evidence-gated offensive security skills for bug bounty and authorized pentesting.
Claude Code skills and agents for authorized security testing, bug bounty hunting, and pentesting workflows
Security testing toolkit with HTTP header analysis, dependency auditing, and static code scanning
Complete offensive security operator workspace: 27 specialist agents, 6 engagement commands, 5 reference skill libraries, scope-gated hooks, and evidence logging for professional penetration testing and red-team operations.
Editorial "Security Engineer" bundle for Claude Code from Antigravity Awesome Skills.
Uses power tools
Uses Bash, Write, or Edit tools
Share bugs, ideas, or general feedback.
Expert guidance for ffuf web fuzzing during authorized penetration testing, including authenticated fuzzing, auto-calibration, and result analysis
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim