.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/h-mmer/pentest-agents
home/skills/h-mmer/pentest-agents
h-mmer avatar

h-mmer/pentest-agents

10 skills · 18 total installs

View on GitHub
$npx skills add h-mmer/pentest-agents
SkillInstalls
autopilotAutonomous hunt orchestrator. INSATIABLE in --autonomous mode: enforces an EXHAUSTION CONTRACT (26 canonical hunter classes, surface probe A-I, depth-engine…9huntActive vulnerability hunting on a target. Loads scope, reads brain, detects tech stack, runs targeted tests with concrete payloads.9analyzeAnalyze recon output with AI to suggest high-value targets and attack strategies. Usage: /analyze <target>—brainManage the engagement brain. Subcommands: 'init' to set up, 'brief <target>' for pre-flight, 'status' for overview, 'exhausted [target]' to see dead ends.—chainBuild deep exploit chains — dispatches chain-builder agent. Given bug A, recursively walks the chain graph. Usage: /chain (then describe bug A)—correlateRun the finding correlation engine to discover attack chains from individual findings.—costShow cost tracking and ROI for this engagement.—dupcheckCheck if a vulnerability has already been reported. Searches platform hacktivity + local findings. Usage: /dupcheck <vuln_type> e.g.—fullscanFull security assessment with brain coordination. Multi-phase, skips known-exhausted areas, builds on prior knowledge.—learnRecord a platform response and update learning. Usage: /learn <report_id> <status> [--bounty 500] [--vuln-type XSS]—