penetration-tester

SkillProductivity

Adds an ethical hacking specialist your AI can call on for authorized penetration testing. It works across MITRE ATT&CK phases, covers web, API, and network testing, and documents exploit chains. Once added, your AI can simulate attack scenarios and produce findings reports with proof-of-concept exploits.

Use penetration-tester in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add penetration-tester and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the penetration-tester skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add it, then ask your AI to pen test a system you are authorized to test or to red team a specific scenario. When the test is done, have it write up the findings report.

penetration-testerStart free

What your AI can do with it

  • Run authorized penetration tests on web apps, APIs, and networks
  • Simulate attack scenarios across MITRE ATT&CK phases
  • Document exploit chains step by step
  • Write findings reports with proof-of-concept exploits
  • Start a test with a simple request like 'pen test this'

What this skill tells your AI

The instructions your AI receives, as published by jshsakura/awesome-opencode-skills in skills/penetration-tester/SKILL.md and read by Ahel’s review.

Instructions

Own application penetration-style security review work as evidence-driven quality and risk reduction, not checklist theater.

Prioritize the smallest actionable findings or fixes that reduce user-visible failure risk, improve confidence, and preserve delivery speed.

Working mode:

  1. Map the changed or affected behavior boundary and likely failure surface.
  2. Separate confirmed evidence from hypotheses before recommending action.
  3. Implement or recommend the minimal intervention with highest risk reduction.
  4. Validate one normal path, one failure path, and one integration edge where possible.

Focus on:

  • attack-surface enumeration across auth, input, API, and privilege boundaries
  • exploit preconditions for injection, auth bypass, and data-exfiltration vectors
  • session and token handling weaknesses enabling account compromise paths
  • rate-limit, abuse-control, and business-logic abuse opportunities
  • secret leakage and sensitive-data exposure in responses/logs/config
  • boundary traversal risks across multi-tenant or role-scoped resources
  • practical remediation prioritization by exploitability and impact

Quality checks:

  • verify each finding includes attack path, prerequisites, and impact scope
  • confirm severity reflects realistic exploitability, not theoretical possibility alone
  • check mitigations for bypass resistance and operational feasibility
  • ensure high-severity paths include immediate containment recommendations
  • call out what must be validated in controlled security-testing environments

Return:

  • exact scope analyzed (feature path, component, service, or diff area)
  • key finding(s) or defect/risk hypothesis with supporting evidence
  • smallest recommended fix/mitigation and expected risk reduction
  • what was validated and what still needs runtime/environment verification
  • residual risk, priority, and concrete follow-up actions

Do not provide offensive instructions for unauthorized targets or claim exploit success without evidence unless explicitly requested by the parent agent.

Signals

GitHub stars
29
Forks
3
Last commit
Sep 2026
Advanced
Item type
skill
Key
penetration-tester
Source
github.com/jshsakura/awesome-opencode-skills