.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/crazymarky/pentest-skills
home/skills/crazymarky/pentest-skills
crazymarky avatar

crazymarky/pentest-skills

11 skills · 414 total installs

View on GitHub
$npx skills add crazymarky/pentest-skills
SkillInstalls
recon-port-scanPort scanning and service identification using nmap, masscan, and rustscan.48recon-subdomainSubdomain enumeration and DNS reconnaissance using subfinder, amass, dnsx, and other tools.44exploit-sqliSQL injection detection and exploitation using sqlmap, manual techniques, and custom payloads.43exploit-xssCross-site scripting (XSS) vulnerability detection and exploitation. Supports reflected XSS, stored XSS, DOM-based XSS, and blind XSS testing.43exploit-file-download任意文件下载与本地文件包含 (LFI) 漏洞检测和利用工具。使用 curl、ffuf、wget 等工具测试文件下载漏洞,支持路径遍历、伪协议利用、敏感文件读取。当用户需要测试文件下载功能、检测 LFI 漏洞、读取服务器敏感文件时使用此技能。41exploit-lfi本地文件包含 (LFI) 漏洞检测和利用工具。使用 curl、ffuf 等工具测试 LFI 漏洞,支持路径遍历、PHP 伪协议利用、日志投毒 RCE、敏感文件读取。当用户需要检测 LFI 漏洞、利用文件包含漏洞读取服务器文件时使用此技能。40pentest-report按照标准格式生成渗透测试报告,包含项目信息表、漏洞发现清单、漏洞详情(含属性表、描述、复现步骤、证据截图、修复建议)、附录(风险等级定义、CVSS说明、词汇表)。当用户要求生成渗透测试报告、安全测试报告、漏洞报告时使用此技能。严格遵循项目模板目录中的标准格式。40recon-dir-scanDirectory and file enumeration using ffuf, gobuster, dirsearch, and feroxbuster.39recon-fingerprintWeb fingerprinting and WAF detection using wafw00f, whatweb, nuclei, and httpx.39results-storageSQLite-based persistent storage and reporting system for penetration testing results.37scriptsArbitrary file download vulnerability detection and exploitation using path traversal techniques, bypass methods, and sensitive file discovery.—