Automated web application vulnerability scanner and exploit generator starting from domains or URLs. Tests for SQLi, XSS, SSRF, IDOR, SSTI, authentication bypass, file upload bypass, and race conditions. Generates working PoC for each finding. Use when user asks to "find vulnerabilities", "scan web app", "test for XSS/SQLi/SSRF", "hunt bugs", "bug bounty scan", or provides a domain for web security testing. For authorized testing only.
$npx -y skills add orizon-eu/claude-code-pentest --skill webapp-exploit-hunterInstalls into the current project.
Run `npx skills use "https://github.com/orizon-eu/claude-code-pentest" --skill "orizon-eu/claude-code-pentest/webapp-exploit-hunter"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/orizon-eu/claude-code-pentest" that are relevant to the current task. Run `npx skills add "https://github.com/orizon-eu/claude-code-pentest"` and select the relevant skills, then follow their instructions.